Назад
Company hidden
1 час назад

Sr Risk Analyst (Cybersecurity)

150 000 - 170 000$
Формат работы
hybrid
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Sr Risk Analyst (Cybersecurity): Leading enterprise cyber risk assessments and mitigation across cloud environments, infrastructure, vendors, and emerging AI/ML systems with an accent on risk quantification, governance frameworks, and executive reporting. Focus on evaluating vulnerabilities and third-party exposure, developing AI governance practices, and translating complex cybersecurity risks into strategic business recommendations.

Location: Newton, MA, USA; in-person work three days a week or more, with flexibility to work from home on other days

Salary: $150,000–$170,000 per year, based on experience

Company

Informa TechTarget provides data-driven technology information, intelligence, advertising, content, and demand-generation services for technology buyers and sellers.

What you will do

  • Lead enterprise-wide cybersecurity risk assessments across business operations, systems, infrastructure, and new technology initiatives.
  • Assess cloud and hybrid infrastructure risks across AWS, Azure, and GCP, and partner with engineering teams on security controls and mitigation.
  • Oversee vulnerability and threat-risk prioritization, including analysis of scan results, penetration tests, threat intelligence, and remediation progress.
  • Manage third-party cybersecurity risk assessments, vendor security reviews, access risks, remediation, and contract security requirements.
  • Support cybersecurity governance, policies, compliance, audits, risk committees, and regulatory impact assessments.
  • Prepare executive and board-level risk reporting, dashboards, KRIs, KPIs, and risk-based recommendations while advising cross-functional teams.

Requirements

  • Bachelor’s degree in cybersecurity, information security, risk management, computer science, information technology, or a related field.
  • 5–8 years of progressive experience in cybersecurity risk management, information security, or IT risk.
  • Proven experience conducting enterprise-level cyber risk assessments in complex technology environments.
  • Experience with cloud security risk assessment, AWS, Azure, or GCP, plus third-party risk management and vendor security assessments.
  • At least one required certification: CRISC, CISSP, or CISM.
  • Strong knowledge of cybersecurity principles, risk frameworks, vulnerability management, security controls, GRC platforms, and executive risk communication.

Nice to have

  • Master’s degree or additional certifications such as CISA, CGRC, or CCSP.
  • Background in information security operations, security engineering, incident response, or business continuity planning.
  • Knowledge of AI/ML security risks, emerging technology governance, security architecture, secure design, and privacy regulations including GDPR, CCPA, or PIPEDA.

Culture & Benefits

  • Collaborative international environment with in-person and online social events and colleague networks.
  • Up to four paid volunteer days per year and access to training, mentoring, LinkedIn Learning, and internal career opportunities.
  • Open vacation, 10 national holidays, and the option to work from almost anywhere for up to four weeks per year.
  • Competitive benefits including 401(k) matching, health, vision and dental insurance, parental leave, and an employee share purchase plan.
  • Wellbeing support through an employee assistance program, mental health first aiders, and a wellness app.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →