Information Security Risk Analyst
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
Information Security Risk Analyst (GRC): Managing the operational execution of the internal risk program with an accent on risk identification, assessment, and control mapping. Focus on transforming raw business signals into actionable risk decisions and maintaining the integrity of the enterprise risk register.
Location: Must be based in the U.S.
Salary: $84,000 — $165,000 USD
Company
is a leading global data platform provider, empowering organizations to innovate with a cloud-native, distributed database designed for the AI era.
What you will do
- Execute risk assessments including scoping, inherent risk scoring, and residual risk calculation.
- Manage the risk intake process, triaging submissions from Jira and maintaining the Risk Register.
- Identify and map controls to framework requirements like NIST SP 800-53, ISO 27001, and SOC 2.
- Assess control design adequacy and operating effectiveness through evidence collection.
- Draft cohesive Risk Assessment Memos that translate technical findings into business-relevant language.
- Monitor emerging risk signals, including AI-related threats, and support governance hygiene.
Requirements
- 3–5 years of experience in Information Security, GRC, or Enterprise Risk Management.
- Must hold at least one of the following certifications: CRISC, CISM, CISSP, or CISA.
- Strong working knowledge of NIST CSF, NIST SP 800-30/39/53, and ISO/IEC 27005.
- Advanced proficiency in Excel/Google Sheets and Jira (workflows, dashboards, JQL).
- Foundational understanding of cloud-native architectures and technical controls (IAM, encryption, logging).
- Bachelor's degree in Cybersecurity, Information Systems, or a related field.
Culture & Benefits
- Comprehensive health benefits and mental health counseling.
- 20 weeks of fully-paid gender-neutral parental leave.
- Equity participation and employee stock purchase program.
- Flexible paid time off and fertility/adoption assistance.
- Supportive culture with employee affinity groups and professional development focus.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →