Назад
Company hidden
8 дней назад

Senior IT Security Risk Analyst

Формат работы
hybrid
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Senior IT Security Risk Analyst (Cybersecurity Governance, Risk & Compliance): Leading cybersecurity governance, risk, and compliance initiatives for an insurance company with an accent on third-party assessments, regulatory alignment, risk registers, and control effectiveness. Focus on mapping regulations to controls, analyzing threat intelligence, supporting audits and vulnerability management, and translating cyber risk into business impact.

Location: Farmington Hills, Michigan, United States; 3-day hybrid onsite schedule required

Company

hirify.global is a property and casualty insurance company serving mid-sized commercial enterprises in construction, manufacturing, and healthcare.

What you will do

  • Lead cybersecurity governance, risk, and compliance initiatives aligned with business objectives and regulatory requirements.
  • Conduct IT and third-party security risk assessments, including reviews of AI systems and mobile applications.
  • Maintain the IT risk register and develop risk, compliance, and management metrics.
  • Review and update cybersecurity policies, standards, and procedures against NIST CSF, NYDFS, NIS2, PCI DSS, and other frameworks.
  • Perform control testing and validation, support IT audits and Model Audit Rule controls, and review SOC 2 reports.
  • Monitor threat intelligence and support vulnerability management, security operations, identity tasks, and leadership risk decisions.

Requirements

  • Bachelor’s degree or equivalent combination of education and experience.
  • At least 5 years of cybersecurity experience, including 2 years performing IT security control testing.
  • Advanced cybersecurity risk certification required, such as CISSP, CISM, CRISC, CCSP, or AWS Certified Security.
  • Expertise in third-party cyber risk assessments, NIST security frameworks, and control effectiveness analysis.
  • Experience with SOC 2 Type 1 and Type 2 reports and LogicGate or another GRC tool.
  • Ability to communicate risk clearly to technical and non-technical stakeholders and collaborate with IT, developers, and business leaders.

Nice to have

  • Experience using AI-driven tools to improve automation and operational efficiency.
  • Experience mentoring and developing security team members.

Culture & Benefits

  • Hybrid work arrangements designed to support work-life balance.
  • Competitive base pay and performance-based incentive pay.
  • Health and welfare benefits, a 401(k) savings plan with profit sharing, and paid time off.
  • Collaborative workplace focused on professional growth.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →