17 Aug
Sr Risk Analyst
Massachusetts, Newton , 02458 Newton USA

This role is based in our Newton, MA office.We are seeking an experienced and strategic Senior Cyber Risk Analyst to join our team. This role requires deep expertise in enterprise cybersecurity risk management, with responsibility for identifying, assessing, and mitigating cyber risks across the organization. You will lead enterprise risk assessments, partner with engineering and security teams on strategic initiatives, and provide executive-level reporting on the organization's cyber risk posture. This position also includes emerging responsibilities in AI governance and technology risk as part of a comprehensive enterprise risk management approach.Key ResponsibilitiesEnterprise Risk Assessment & ManagementLead comprehensive enterprise-wide cyber risk assessments across all business operations, systems, and infrastructureIdentify, analyze, and evaluate cybersecurity risks including threats, vulnerabilities, and potential business impactsDevelop and maintain enterprise risk registers, ensuring all cyber risks are properly documented, prioritized, and monitoredCreate and implement risk treatment plans and mitigation strategies to reduce organizational exposureConduct risk assessments for new technologies, systems, and business initiatives in partnership with engineering and product teamsUtilize risk management frameworks (NIST CSF, ISO 27005, FAIR) to quantify and communicate riskCloud Security & Infrastructure RiskAssess security risks associated with cloud environments (AWS, Azure, GCP) and hybrid infrastructureEvaluate cloud architecture designs and configurations for security and compliance risksPartner with cloud engineering teams to implement security controls and risk mitigation measuresReview and assess risks related to cloud migration projects and infrastructure changesVulnerability & Threat ManagementOversee vulnerability management program effectiveness and risk prioritizationAnalyze vulnerability scan results and penetration test findings to assess enterprise risk exposureWork with IT and security teams to ensure timely remediation of critical vulnerabilitiesMonitor threat intelligence and assess potential impact to the organizationEvaluate the effectiveness of security controls in mitigating identified vulnerabilitiesThird-Party & Vendor Risk ManagementConduct cybersecurity risk assessments of third-party vendors, suppliers, and business partnersReview vendor security questionnaires, certifications, and audit reportsAssess risks associated with vendor access to systems and dataMonitor ongoing third-party risk and ensure compliance with security requirementsSupport vendor risk remediation efforts and contract security requirementsGovernance, Compliance & PolicyEnsure compliance with relevant cybersecurity regulations, standards, and frameworks (SOC 2, ISO 27001, NIST, Sox, etc.)Support the development and maintenance of cybersecurity policies, standards, and proceduresParticipate in internal and external audits related to cybersecurity and risk managementMonitor regulatory changes and assess impact on organizational risk postureContribute to the organization's cybersecurity governance structure and risk committee activitiesExecutive Reporting & MetricsPrepare comprehensive cyber risk reports and presentations for executive leadership, board of directors, and key stakeholdersDevelop and maintain cyber risk dashboards with Key Risk Indicators (KRIs) and Key Performance Indicators (KPIs)Communicate complex cybersecurity risks in business terms to non-technical executive audiencesProvide regular updates on risk trends, threat landscape, and mitigation progressPresent risk-based recommendations to support strategic business decisionsStrategic Partnership & AdvisoryPartner with engineering, IT, security, and product teams on new initiatives and technology implementationsProvide expert cybersecurity risk guidance during project planning and system design phasesAdvise business units on cyber risk implications of strategic decisions and initiativesCollaborate with cross-functional teams including legal, compliance, privacy, and internal auditEmerging Technology & AI GovernanceAssess cybersecurity and privacy risks associated with AI/ML systems and emerging technologiesSupport the development of AI governance frameworks and responsible AI practicesEvaluate risks related to AI implementation including data privacy, model security, and ethical considerationsStay current with emerging technology risks and evolving regulatory requirementsRequired QualificationsEducation & ExperienceBachelor's degree in Cybersecurity, Information Security, Risk Management, Computer Science, Information Technology, or related field5-8 years of progressive experience in cybersecurity risk management, information security, or IT riskProven track record of conducting enterprise-level cyber risk assessments in complex technology environmentsExperience with cloud security risk assessment and cloud platforms (AWS, Azure, GCP)Demonstrated experience in third-party risk management and vendor security assessmentsProfessional CertificationsRequired (at least one):CRISC (Certified in Risk and Information Systems Control)CISSP (Certified Information Systems Security Professional)CISM (Certified Information Security Manager)Preferred:CISA (Certified Information Systems Auditor)CGRC (Certified in Governance, Risk and Compliance)CCSP (Certified Cloud Security Professional)Additional relevant cybersecurity or risk management certificationsCybersecurity & Technical SkillsDeep understanding of cybersecurity principles, threats, vulnerabilities, and attack vectorsStrong knowledge of risk management frameworks (NIST, ISO 27001, Soc2, Sox)Experience with vulnerability management tools and processesUnderstanding of cloud security architecture and controls (AWS, Azure, GCP)Knowledge of security controls, defense-in-depth strategies, and compensating controlsFamiliarity with compliance frameworks (SOC 2, ISO 27001, NIST 800-53)Experience with GRC (Governance, Risk, and Compliance) platformsUnderstanding of network security, application security, and infrastructure security


Related jobs

Report job