Назад
Company hidden
4 дня назад

Senior Cyber Governance, Risk, Compliance Analyst (Cybersecurity)

112 300 - 202 500$
Формат работы
hybrid
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Senior Cyber Governance, Risk, Compliance Analyst (Cybersecurity): Managing enterprise cybersecurity governance, risk registers, security controls, audits, vulnerability remediation, and authorization activities with an accent on NIST RMF, AWS-based systems, GRC operations, and compliance frameworks. Focus on conducting risk assessments, developing treatment and remediation plans, maintaining SSPs and POA&Ms, and coordinating ATO and continuous monitoring processes.

Location: Rockville, MD, with a hybrid work environment and defined in-person presence requirements. The role may also be performed from listed hirify.global locations including Boston, Chicago, Denver, Jericho, Jersey City, Philadelphia, New York, Tysons, Washington, Woodbridge, Connecticut State, or Washington State.

Salary: $112,300–$202,500 for Rockville, MD. Other location-specific ranges apply.

Company

hirify.global is a securities regulator focused on investor protection and market integrity.

What you will do

  • Create and maintain cybersecurity policies, procedures, standards, hardening guidelines, and security baselines.
  • Maintain enterprise risk registers in GRC platforms and report risks to stakeholders and senior leadership.
  • Conduct cybersecurity risk assessments using threat modeling, vulnerability analysis, likelihood and impact evaluation, and NIST methodologies.
  • Develop risk treatment strategies, control implementation roadmaps, risk acceptance justifications, and prioritized remediation plans.
  • Develop and maintain System Security Plans, POA&M documentation, authorization packages, and continuous monitoring strategies.
  • Coordinate audits, regulatory examinations, vulnerability remediation, security control assessments, ATO processes, and reporting on control effectiveness.

Requirements

  • Bachelor’s degree in Computer Science, Computer Engineering, Cybersecurity, or a related technical field, or equivalent experience.
  • At least seven years of professional experience designing, operating, and monitoring IT systems with substantial cybersecurity experience.
  • At least three years of experience designing, operating, monitoring, and assessing security controls for AWS-based systems.
  • Hands-on experience applying the NIST Risk Management Framework across the full system lifecycle.
  • Experience building, operating, and maintaining an enterprise cyber risk register in a GRC platform from identification through closure.
  • Hybrid work with defined in-person presence requirements at an applicable US location is required.

Nice to have

  • Experience supporting internal and external audits, assessments, and regulatory examinations.
  • Experience with NIST, SOC, and PCI security frameworks.

Culture & Benefits

  • Collaboration is expected both in person and virtually in support of investor protection and market integrity.
  • Health, dental, vision, life, disability, legal, and long-term care insurance options.
  • 401(k) plan with company match and an additional hirify.global-funded retirement contribution.
  • Paid time off, personal and sick days, paid holidays, parental and family-related leave, and volunteer service days.
  • Tuition reimbursement, commuter benefits, wellness programs, adoption assistance, backup family care, and employee assistance.

Hiring process

  • Applications are accepted on an ongoing basis.
  • Candidates must submit an application through the hirify.global Careers site.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →