GRC Cybersecurity Analyst

Fractional CISO

Sevenig (Our)

Hybrid

EUR 95.000 - 147.000

Vollzeit

14 Tage+

Erhalte mehr Antworten von Arbeitgebern

Versende in nur wenigen Minuten einen passgenauen Lebenslauf.

Zusammenfassung

Fractional CISO seeks a GRC Cybersecurity Analyst to secure client infrastructure, data and software, and help society by advancing cybersecurity best practices.

You will work with a VCISO to deliver governance, risk, and compliance leadership across diverse industries, developing key program components and guidance for clients.

Qualifikationen

  • 2+ years of experience in security roles (SOC, audit, or related).
  • Strong written and verbal communication skills.
  • Experience managing internal projects or initiatives.

Aufgaben

  • Lead internal cybersecurity audits to ensure client environments stay compliant and secure.
  • Plan and run tabletop exercises to train client teams for incidents.
  • Perform quantitative risk assessments to guide smart cybersecurity investments.
  • Respond to security questionnaires from clients to support business growth.
  • Write cybersecurity policy documents to build robust client programs.
  • Assist with evidence collection for external audits and compliance.

Kenntnisse

GRC governance
Policy writing
Risk assessment
Security frameworks
SOC experience
Clear communication

Ausbildung

Cybersecurity degree

Tools

SIEM
Vulnerability scanners

Jobbeschreibung

As a GRC Cybersecurity Analyst (CA), you will play a pivotal role securing our clients’ infrastructure, data and software. Beyond helping our clients, you will also make a huge impact and help society as a whole by contributing to our fast moving, passionate efforts to smartly improve and promote cybersecurity best practices.

Fractional CISO is not a typical cybersecurity consulting firm. Instead of technical support, we focus on delivering the best possible cybersecurity advice to our client’s leadership teams. Our typical clients are medium sized tech firms with significant cybersecurity needs, but they’re not quite large enough yet to hire a full-time “C-level” senior security leader, like a Chief Information Security Officer (CISO). We fill that gap with our “fractional” CISO consulting services and help guide our clients on their cybersecurity improvement programs.

In This Position, You Will Work As a Team With a VCISO To Provide Cybersecurity Leadership In Governance, Risk, And Compliance (GRC) Directly To Our Clients. You Will Work With a Wide Range Of Companies Across Many Industries To Develop And Deliver The Components Of a Good Cybersecurity Management Program, Including

  • Leading Internal Cybersecurity Audits to ensure our clients’ operational environments stay compliant and secure.
  • Planning and running tabletop training exercises to help our clients’ employees practice how they will respond to a cybersecurity incident.
  • Performing quantitative Risk Assessments for clients so they can understand where to make smart investments in their cybersecurity.
  • Responding to security questionnaires from our clients’ customers so they can grow their businesses.
  • Writing cybersecurity policy documents to build up our clients’ cybersecurity programs.
  • Assisting with evidence collection to help our clients prepare for external compliance audits.
  • Providing advice and guidance to clients on a wide range of cybersecurity topics.
  • Project managing client accounts to keep them on track
  • Contributing to service development program to improve our client deliverables

The right candidate for this position will possess all of these traits:

  • 2 or more years of experience as a SOC analyst, developer, incident response remediator, technical auditor, IT administrator with security responsibilities or similar technical role
  • A passion about solving clients’ security challenges
  • High personal and professional ethical standards
  • Experience managing internal projects and initiatives
  • Well-developed technical writing skills

In addition, highly qualified candidates will likely possess technical experience in one of these areas:

  • Security Operations (SOC)
  • Security Compliance (SOC 2, ISO 27001, PCI-DSS, HIPAA, etc.)
  • Secure Software Development Lifecycle (S-SDLC) practices
  • System Administration (Windows, Linux)
  • Cloud Administration (AWS, Azure, Google Cloud)
  • Network or firewall administration
And Have One Or More Of These Experiences
  • Knowledge of security operations tools, systems, and practices (SIEM, WAF, vulnerability scanning, penetration testing, system hardening, MFA, SSO, etc.)
  • Able to explain at a high level how the Internet and websites function
  • Familiar with core networking concepts, protocols, and common services
  • Understanding of encryption concepts and SSL/TLS certificates
  • General scripting or coding experience
  • Cybersecurity certifications (SSCP, CompTIA Security+, etc.)
  • Experience with any security frameworks (NIST CSF, CIS, COBIT, etc.)
  • A degree in Cybersecurity or a related field.

While we value candidates with operational experience, this role is not the same as a Security Operations Center (SOC) analyst! This job does not focus on routine security tasks like monitoring logs, responding to security alerts, patching systems, or running vulnerability scans. If you have experience as a SOC analyst but are looking for a new challenge that will advance your career towards thoughtful cybersecurity leadership, this may be a great position for you!

We are committed to providing guidance and support to the right GRC Cybersecurity Analyst candidate so they can accelerate their cybersecurity career. What we ask in return is that the candidate bring a passion for cybersecurity, a strong work ethic, and demonstrated excellence in their prior positions and coursework. We value diversity and believe that qualified candidates are just as likely to come from non-traditional work or educational backgrounds.

Note: We genuinely appreciate it when candidates take the time to write a brief cover letter that explains their interest in the position and what attracted them to Fractional CISO!

About Fractional CISO Fractional CISO enables client sales, reduces its risk and helps them comply with cybersecurity standards by providing expert cybersecurity advice. Our CISO as a Service offering delivers flexible cybersecurity leadership tailored to the needs of each client organization.

Please check out our Fractional CISO Fundamentals program to see if Fractional CISO would be a good cultural fit for you.

Our employees follow the standard Code of Ethics as defined by the (ISC)2.

Our office is conveniently located next door to the Riverside T stop on the Green Line in Newton, MA. We have easy highway access to I-90 and I-95.

Our office is conveniently located next door to the Riverside T stop on the Green Line in Newton, MA. It is near the I-95 / I-90 exchange.

This is a hybrid position with at least 3 days in our Newton office.

Hol dir deinen kostenlosen, vertraulichen Lebenslauf-Check.
oder ziehe deine Datei hierhin.
Similar jobs

Ähnliche Jobs, die dir auch gefallen könnten

Security GRC Analyst
Security GRC Analyst

Jobtailor • Deutschland

Remote
EUR 42.000 - 64.000
Executive Partner -CISO SRM (Healthcare)
Executive Partner -CISO SRM (Healthcare)

Gartner • Deutschland

Hybrid
EUR 180.000 - 240.000
Cyber Security GRC Consultant
Cyber Security GRC Consultant

MeJuvante GmbH • Frankfurt

Vor Ort
EUR 65.000 - 95.000
Information Security Assessor
Information Security Assessor

FRSecure • Deutschland

Hybrid
EUR 73.000 - 82.000
Medical insurance
Dental insurance
Vision insurance
+8
Sr. Director, Analyst - Cybersecurity & Emerging Technologies for CIO & AI Leaders (Remote US)
Sr. Director, Analyst - Cybersecurity & Emerging Technologies for CIO & AI Leaders (Remote US)

Gartner • Deutschland

Hybrid
EUR 148.000 - 174.000
Hybrid work environment
Competitive compensation
Generous PTO
Senior Cybersecurity Solutions Engineer - Remote
Senior Cybersecurity Solutions Engineer - Remote

Center for Internet Security • Deutschland

Hybrid
EUR 80.000 - 141.000
Senior Product Manager - CISO Advantage (m/f/d)
Senior Product Manager - CISO Advantage (m/f/d)

Sophos • Deutschland

Vor Ort
USD 75.000 - 95.000
Remote-first working model
Diversity and inclusion initiatives
Global wellbeing days
PPS Solutions Sr. Consultant (Remote, GBR)
PPS Solutions Sr. Consultant (Remote, GBR)

CrowdStrike • Deutschland

Hybrid
EUR 90.000 - 140.000
Equity awards
Wellness programs
Paid parental leave
+4
Cyber security consulting services expert (all gernders)
Cyber security consulting services expert (all gernders)

Merck Gruppe • Darmstadt

Vor Ort
USD 70.000 - 117.000
Security Engineer
Security Engineer

JR Recruiting • Geilenkirchen

Hybrid
EUR 82.000 - 116.000