Назад
Company hidden
3 дня назад

Security Risk Analyst (Cybersecurity)

Формат работы
hybrid
Тип работы
fulltime
Английский
b2
Страна
Ireland
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Security Risk Analyst (Cybersecurity) (Third-Party Risk Management): Operating and enhancing McAfee’s third-party risk management program through vendor assessments, onboarding and offboarding controls, and continuous monitoring with an accent on security questionnaires, audit evidence, risk treatment, and compliance requirements. Focus on tracking remediation, evaluating SOC 2 and ISO 27001 controls, partnering with Legal, Privacy, and Procurement, and improving risk reporting and governance workflows.

Location: Hybrid in Dublin or Cork, Ireland; onsite attendance required as needed. Candidates must live within commuting distance, and relocation assistance is not offered.

Company

hirify.global develops consumer security solutions designed to protect people, families, and communities in an always-online world.

What you will do

  • Conduct end-to-end third-party risk assessments for new and existing vendors.
  • Support vendor onboarding and offboarding while verifying security and compliance requirements.
  • Evaluate vendor security posture using questionnaires, SOC 2 and ISO 27001 reports, and supporting evidence.
  • Document third-party risks, assign ownership, track treatment plans, and monitor remediation through closure.
  • Perform continuous third-party risk monitoring using security ratings, breach monitoring, and other external intelligence.
  • Partner with Legal, Privacy, Procurement, customers, and partners on risk decisions, contract requirements, due diligence, and assurance reporting.

Requirements

  • Experience in Third-Party Risk Management or cybersecurity risk.
  • Experience conducting vendor risk assessments and evaluating security questionnaires.
  • Knowledge of SOC 2, ISO 27001, and cybersecurity risk frameworks such as NIST.
  • Experience maintaining risk registers, tracking remediation, and monitoring vendor risk.
  • Understanding of security, compliance, and data privacy requirements, with strong analytical, problem-solving, stakeholder management, and communication skills.
  • Bachelor’s degree in Cybersecurity, Information Security, Computer Science, or a related field, or equivalent experience.

Nice to have

  • Experience with GRC or TPRM tools.
  • Certifications such as CISSP, CISM, CRISC, CISA, or Security+.

Culture & Benefits

  • Flexible work hours and family-friendly benefits.
  • Bonus program.
  • Pension and retirement plans.
  • Medical, dental, and vision coverage.
  • Paid time off and paid parental leave.
  • Support for community involvement and an inclusive workplace.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →