Назад
Company hidden
2 часа назад

Senior Cyber Risk Analyst (Cybersecurity)

150 000 - 170 000$
Формат работы
hybrid
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Senior Cyber Risk Analyst (Cybersecurity): Leading enterprise-wide cyber risk assessments and mitigation across cloud infrastructure, vulnerabilities, third parties, compliance, and emerging AI technologies with an accent on NIST, ISO, FAIR, and executive risk reporting. Focus on quantifying enterprise exposure, assessing cloud and vendor risks, building AI governance practices, and translating complex cybersecurity issues into strategic business recommendations.

Location: Newton, Massachusetts, USA; based in the Newton office with in-person work three days a week or more

Salary: $150,000–$170,000 per year, based on experience

Company

hirify.global provides data-driven technology information, intelligence, advertising, custom content, and intent and demand generation services for technology buyers and sellers.

What you will do

  • Lead enterprise-wide cybersecurity risk assessments across business operations, systems, infrastructure, and new technology initiatives.
  • Develop risk registers, treatment plans, mitigation strategies, dashboards, KRIs, and KPIs.
  • Assess cloud and hybrid infrastructure risks across AWS, Azure, and GCP, including migration projects and architecture designs.
  • Oversee vulnerability and threat risk prioritization and coordinate remediation with IT and security teams.
  • Conduct third-party and vendor security assessments and support vendor remediation and contract security requirements.
  • Prepare executive and board reporting and advise engineering, product, legal, compliance, privacy, and audit stakeholders.

Requirements

  • Bachelor’s degree in cybersecurity, information security, risk management, computer science, information technology, or a related field.
  • 5–8 years of progressive experience in cybersecurity risk management, information security, or IT risk.
  • Experience conducting enterprise-level cyber risk assessments, cloud security risk assessments, and third-party risk management.
  • Deep knowledge of cybersecurity principles, vulnerabilities, security controls, cloud security, network security, application security, and infrastructure security.
  • Experience with NIST, ISO 27001, ISO 27005, FAIR, SOC 2, SOX, NIST 800-53, vulnerability management, and GRC platforms.
  • At least one required certification: CRISC, CISSP, or CISM.

Nice to have

  • CISA, CGRC, CCSP, or additional cybersecurity and risk management certifications.
  • Master’s degree in cybersecurity, information security, risk management, or a related field.
  • Security operations or engineering experience, incident response, business continuity, secure design, privacy regulations, or AI/ML security.

Culture & Benefits

  • Collaborative international environment with colleagues and teams across global offices.
  • Open vacation, 10 national holidays, and the option to work from almost anywhere for up to four weeks per year.
  • 401(k) match, health, vision and dental insurance, parental leave, and employee share purchase plan.
  • Training, mentoring, LinkedIn Learning access, and support for internal career moves.
  • Volunteer days, wellbeing resources, employee assistance, mental health support, and recognition programs.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →