- Company Name
- CoreWeave
- Job Title
- Security Risk Management Analyst
- Job Description
-
**Job title:** Security Risk Management Analyst
**Role Summary:**
Responsible for identifying, documenting, and tracking internal and external security risks; supporting risk assessment processes; driving corrective actions; and collaborating with cross‑functional teams to maintain the organization’s risk register and compliance with industry frameworks.
**Expectations:**
• Deliver timely, actionable risk insights to Risk Owners and executives.
• Maintain stakeholder relationships to enhance risk visibility.
• Apply advanced risk quantification, automation, and AI‑assisted workflows.
• Ensure compliance with SOX, SOC 2, ISO 27001/27701, NIST, FedRAMP, GDPR, HIPAA, and related regulations.
**Key Responsibilities:**
- Identify, document, and track risks across security, IT, cloud, engineering, legal, and privacy domains.
- Collaborate with cross‑functional teams to capture risk scope, impact, and mitigation plans.
- Build and maintain repeatable documentation, tracking, and prioritization systems for the risk register and enterprise risk assessments.
- Utilize cyber risk quantification methods (e.g., FAIR, Cyber V‑a‑Risk), telemetry‑based risk signals, and LLM‑assisted workflows to define loss scenarios, assess impact, and streamline reporting.
- Monitor regulatory and organizational changes; assess impacts on security and privacy obligations.
- Conduct periodic control and risk assessments aligned with SOX, SOC 2, ISO 27001:2022, FedRAMP, GDPR, NIST, ISO 27701, and HIPAA.
- Support broader GRC functions: audit readiness, customer security questionnaires, program health metrics.
- Assist in the creation, enforcement, and implementation of security policies, procedures, standards, and controls.
**Required Skills:**
- Risk management, IT security, compliance, or audit experience (5+ years).
- Proficient in the NIST Cybersecurity Framework and risk quantification methodologies (FAIR, Cyber V‑a‑Risk).
- Knowledge of regulatory frameworks: SOX, SOC 2, ISO 27001/27701, ISO 27701, NIST 800‑53/CSF, FedRAMP, GDPR, HIPAA.
- Broad security domain expertise: cloud computing, Kubernetes, physical security, third‑party risk, IAM, data security, vulnerability & patch management, malware defenses.
- Ability to translate technical vulnerabilities into clear business‑impact statements for non‑technical stakeholders.
- Strong planning, organizational, project management, and analytical skills.
- Experience building cross‑functional relationships and resolving complex, ambiguous issues independently.
**Required Education & Certifications:**
- Bachelor’s degree in Information Security, Computer Science, or related field (or equivalent practical experience).
- Certification preferred: CISSP, CISM, CRISC, or equivalent.
(Word count: ~260)
Livingston, United states
On site
Mid level
09-09-2025