- Company Name
- SoTalent
- Job Title
- Cybersecurity Risk Analyst
- Job Description
-
Job title: Cybersecurity Risk Analyst
Role Summary: Provide independent, second‑line oversight of technology and cyber risk for a financial services organization, advising stakeholders, conducting risk assessments, validating remediation, and ensuring alignment with regulatory and industry standards.
Expectations: 9+ years of cybersecurity risk management or related experience; senior-level understanding of regulatory expectations; proven ability to influence decision‑making, support governance committees, and drive risk remediation.
Key Responsibilities:
- Advise stakeholders on enterprise cyber and technology risk as a second‑line SME.
- Evaluate and monitor risks tied to new technologies, digital initiatives, and business changes.
- Assess third‑party technology providers, identifying security risks and required controls.
- Lead focused risk assessments to uncover gaps and validate remediation.
- Review and challenge first‑line risk activities (control testing, risk assessments, mitigation plans).
- Analyze cyber risk data to identify trends and produce actionable insights for leadership.
- Contribute to the development and enhancement of cybersecurity policies, standards, and governance frameworks.
- Monitor industry and regulatory developments, assessing impact on risk exposure.
- Support remediation of regulatory issues, tracking progress to closure.
- Prepare and present materials for governance committees; participate in risk discussions across key stakeholders.
- Escalate significant risks to senior leadership as appropriate.
Required Skills:
- Deep knowledge of cybersecurity frameworks (NIST, ISO 27001, FFIEC, etc.) and regulatory expectations.
- Expertise in security architecture, IAM, network & firewall management, vulnerability & patch management.
- Cloud security (AWS, Azure) proficiency, including containerization, encryption, tokenization, DLP.
- Experience with security monitoring, threat detection, incident response, and offensive security practices.
- Strong analytical, documentation, and communication skills.
- Ability to collaborate with cross‑functional teams and manage multiple priorities.
Required Education & Certifications:
- Bachelor’s degree in Information Security, Computer Science, Information Technology, or related field.
- Cybersecurity certifications required (e.g., CISSP, CISM, CRISC, or equivalent).
- Cloud security certifications (e.g., CCSP, AWS Security Specialty, Azure Security Engineer) preferred.