Technology & Cybersecurity Risk Analyst
Core
Conduct risk intake, assessments, and triage sessions to identify, document, and mitigate technology and cybersecurity risks using NIST, COBIT, and ISO 27001 frameworks.
Role type
Technology & Cybersecurity Risk Analyst
Builds
Risk registers, control effectiveness evaluations, executive-ready risk reports, and dashboards
Domain
Cybersecurity and Enterprise Risk Management
Deliverable
dashboards & analysis
Required skills
Risk assessment, control design evaluation, risk mitigation, stakeholder coordination, analytical thinking, project coordination, documentation, report preparation
Preferred skills
Familiarity with ServiceNow, Microsoft Copilot, governance, risk, and compliance tools
Responsibilities
Conduct risk intake, assessments, and triage sessions; Identify and document inherent, residual, and emerging technology risks; Review security controls and evaluate their effectiveness; Map risks to controls, policies, and framework requirements; Facilitate control walkthroughs and risk discussions; Document risk statements, controls, and assessment results; Recommend risk treatment and mitigation measures; Track remediation activities and action items; Escalate overdue actions and significant concerns; Prepare executive-ready risk reports and presentations; Coordinate risk activities across stakeholders; Identify opportunities to improve risk management processes