Senior Cybersecurity Analyst
Core
Conduct independent, risk-based reviews of system, network, application, cloud, and third-party architectures to identify cyber risks and confirm alignment with policies and secure-by-design practices.
Role type
Senior Cybersecurity Governance Analyst (Second-line oversight)
Builds
Cybersecurity risk management program, governance oversight for network segmentation and identity management, and enterprise risk reporting.
Domain
Financial services / Cybersecurity Governance
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Cybersecurity risk assessment, vulnerability management, secure design principles, audit support, regulatory compliance, threat intelligence analysis, control effectiveness evaluation, remediation tracking, policy development, executive reporting
Preferred skills
Financial services experience, board-level reporting, MITRE ATT&CK frameworks, CISSP/CRISC/CISM certifications, cloud security architecture
Technologies
Cloud, Network Security, NIST CSF, NIST SP 800-53, FFIEC ACET, CIS Controls, MITRE ATT&CK, CVSS, EPSS
Responsibilities
Conduct independent risk-based reviews of system, network, application, cloud, and third-party architectures; provide governance oversight for network segmentation, identity management, cloud security, and infrastructure security; participate in project governance and the system development lifecycle; carry out cybersecurity risk assessments for technology initiatives and third-party services; support risk acceptance, exception handling, and remediation tracking; contribute to enterprise and operational risk management through analysis and reporting; monitor threat intelligence and industry activity; oversee the vulnerability management program; coordinate and oversee penetration testing and red team exercises; develop and maintain cybersecurity metrics, dashboards, risk reports, policies, and standards.
Seniority
Senior, hands-on IC with governance oversight
