Назад
Company hidden
11 дней назад

GRC Risk Management Analyst (Cybersecurity)

98 800 - 196 000$
Формат работы
onsite
Тип работы
fulltime
Грейд
middle
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
GRC Risk Management Analyst (Cybersecurity): Managing security, privacy, and compliance risk registers and lifecycle processes with an accent on risk assessments, control effectiveness, mitigation strategies, and quantitative risk analysis. Focus on implementing FAIR-based risk models, conducting Privacy Impact Assessments, automating risk reviews, and producing KPIs and KRIs for enterprise decision-making.

Location: New York, United States; fully in-person schedule up to 5 days a week

Salary: $98,800–$196,000 annually, plus potential discretionary bonuses, incentives, and restricted stock units.

Company

hirify.global operates data privacy, cybersecurity, trust and safety, and national security programs to protect U.S. user data and the content ecosystem.

What you will do

  • Manage risk register and lifecycle activities, including risk identification, ownership assignment, assessments, control effectiveness reviews, and mitigation tracking.
  • Partner with cross-functional teams to reduce and mitigate security, privacy, and compliance risks.
  • Develop and document risk intake, analysis, operating procedures, and stakeholder engagement models.
  • Analyze internal and external data to identify risk trends, patterns, signals, and treatment priorities.
  • Support quantitative risk models such as FAIR, Privacy Impact Assessments, privacy risk analysis, and risk rating justifications.
  • Improve risk reporting, data collection, review automation, and KPI/KRI visibility for leadership.

Requirements

  • 3+ years of experience in IT, cybersecurity, or enterprise risk management in a fast-paced technology environment.
  • Hands-on experience with risk assessments, risk registers, and remediation plans.
  • Familiarity with FAIR, NIST RMF, ISO 31000, or COBIT frameworks.
  • Ability to explain technical risk concepts to non-technical stakeholders and influence without direct authority.
  • Experience reporting KRIs and KPIs in a global enterprise and supporting risk-informed decision-making.
  • Strong communication, collaboration, organization, time management, and problem-solving skills.

Nice to have

  • Practical experience implementing FAIR or similar quantitative risk models.
  • Working knowledge of DevSecOps, IAM, change management, or cloud security.
  • CRISC, FAIR, CISA, or CISSP certification.
  • Experience in highly regulated industries or global enterprise environments.

Culture & Benefits

  • Medical, dental, and vision insurance from day one.
  • 401(k) savings plan with company match.
  • Paid parental leave, disability coverage, life insurance, and wellbeing benefits.
  • 10 paid holidays, 10 paid sick days, and 17 days of paid personal time, with accrual increasing by tenure.
  • Inclusive workplace with reasonable accommodations available during recruitment.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →