4 дня назад
Senior Cyber Governance, Risk, Compliance Analyst (Cybersecurity)
112 300 - 202 500$
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Senior Cyber Governance, Risk, Compliance Analyst (Cybersecurity): Managing enterprise cybersecurity governance, risk registers, security controls, audits, vulnerability remediation, and authorization activities with an accent on NIST RMF, AWS-based systems, GRC operations, and compliance frameworks. Focus on conducting risk assessments, developing treatment and remediation plans, maintaining SSPs and POA&Ms, and coordinating ATO and continuous monitoring processes.
Location: Rockville, MD, with a hybrid work environment and defined in-person presence requirements. The role may also be performed from listed locations including Boston, Chicago, Denver, Jericho, Jersey City, Philadelphia, New York, Tysons, Washington, Woodbridge, Connecticut State, or Washington State.
Salary: $112,300–$202,500 for Rockville, MD. Other location-specific ranges apply.
Company
is a securities regulator focused on investor protection and market integrity.
What you will do
- Create and maintain cybersecurity policies, procedures, standards, hardening guidelines, and security baselines.
- Maintain enterprise risk registers in GRC platforms and report risks to stakeholders and senior leadership.
- Conduct cybersecurity risk assessments using threat modeling, vulnerability analysis, likelihood and impact evaluation, and NIST methodologies.
- Develop risk treatment strategies, control implementation roadmaps, risk acceptance justifications, and prioritized remediation plans.
- Develop and maintain System Security Plans, POA&M documentation, authorization packages, and continuous monitoring strategies.
- Coordinate audits, regulatory examinations, vulnerability remediation, security control assessments, ATO processes, and reporting on control effectiveness.
Requirements
- Bachelor’s degree in Computer Science, Computer Engineering, Cybersecurity, or a related technical field, or equivalent experience.
- At least seven years of professional experience designing, operating, and monitoring IT systems with substantial cybersecurity experience.
- At least three years of experience designing, operating, monitoring, and assessing security controls for AWS-based systems.
- Hands-on experience applying the NIST Risk Management Framework across the full system lifecycle.
- Experience building, operating, and maintaining an enterprise cyber risk register in a GRC platform from identification through closure.
- Hybrid work with defined in-person presence requirements at an applicable US location is required.
Nice to have
- Experience supporting internal and external audits, assessments, and regulatory examinations.
- Experience with NIST, SOC, and PCI security frameworks.
Culture & Benefits
- Collaboration is expected both in person and virtually in support of investor protection and market integrity.
- Health, dental, vision, life, disability, legal, and long-term care insurance options.
- 401(k) plan with company match and an additional -funded retirement contribution.
- Paid time off, personal and sick days, paid holidays, parental and family-related leave, and volunteer service days.
- Tuition reimbursement, commuter benefits, wellness programs, adoption assistance, backup family care, and employee assistance.
Hiring process
- Applications are accepted on an ongoing basis.
- Candidates must submit an application through the Careers site.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
5 дней назад
Staff Security Analyst - GRC
150 000 - 164 000$
9 дней назад
Senior IT GRC Analyst
131 000$
5 дней назад
Senior Cyber Risk Analyst (Cybersecurity)
105 000 - 140 000$
4 дня назад
Information System Security Officer - Senior (Cybersecurity)
4 дня назад
IT & Security Governance Analyst (Cybersecurity)
82 000 - 92 000$
4 дня назад
Senior GRC Analyst (Healthcare)
155 000 - 185 000$