Conduct end-to-end cybersecurity risk assessments across systems, networks, applications, and business units
Identify and evaluate potential threats, vulnerabilities, and risks impacting the confidentiality, integrity, and availability of information assets
Recommend risk mitigation strategies and controls to reduce exposure
Support compliance efforts related to standards such as ISO 27001, NIST, CIS, PCI-DSS, GDPR, etc.
Perform third-party/vendor risk assessments and advise on remediation
Develop and maintain risk registers and risk treatment plans
Collaborate with system owners and technical teams to integrate security into system design (e.g., secure architecture reviews)
CANDIDATE PROFILE
Bachelor’s degree in Cybersecurity, Information Systems, Computer Science, or related field
3–7 years of experience in cybersecurity risk assessment, information security, or IT audit
Preferred certification in CISA, CISSP, CRISC, and ISO 27001
Strong understanding of cybersecurity frameworks and methodologies
Familiarity with tools such as risk management platforms (e.g., Archer, MetricStream, RiskLens), vulnerability scanners (e.g., Qualys, Nessus), and SIEM systems
Experience conducting both technical and business-level risk assessments
Strong communication skills with the ability to translate technical risks into business language