Cyber Risk Management Analyst

CompQsoft Inc

New York (NY)

Hybrid

USD 120,000 - 160,000

Full time

31 hours ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

CompQsoft Inc. is seeking a senior role to drive enterprise cybersecurity risk management by translating compliance into strategic advantage.

You will quantify risks, assess control effectiveness, and align with NIST 800-53 and FISMA, partnering with Cybersecurity Engineers and Analysts to prioritize remediation and track top cyber risks. The role focuses on security governance, POA&M lifecycle, risk register oversight, and creating awareness programs to reduce human-centric risks while

Qualifications

  • Drive enterprise cybersecurity risk management by transforming compliance into a strategic advantage.
  • Quantify risks, assess control effectiveness, and align with NIST 800-53 and FISMA frameworks.
  • Collaborate with Cybersecurity Engineers and Business Analysts to define compliance guardrails, prioritize remediation, and track key cyber risks.
  • Conduct enterprise-wide risk assessments, audits, and user awareness programs to improve security posture.

Responsibilities

  • Lead enterprise-wide risk assessments using GRC methodologies to identify and prioritize risks.
  • Translate technical vulnerabilities into business impact for stakeholders.
  • Ensure ongoing compliance with federal frameworks through periodic audits and Security Impact Analyses.
  • Maintain and manage the enterprise POA&M lifecycle and the risk Register within SLAs.
  • Monitor and report critical cyber risks using dashboards and metrics for leadership.
  • Design and implement security awareness programs and phishing simulations to reduce risk.
  • Collaborate to define compliance guardrails and prioritize remediation by risk impact.
  • Use Archer and ServiceNow with Power BI and Excel to generate automated risk metrics.

Skills

GRC
TPRM
NIST 800-53
RMF
POA&M
Risk assessment
Analytics
Stakeholder comms

Tools

Archer
ServiceNow
Power BI
Excel
JIRA

Job description

Certifications: CISA, CRISC, CGEIT, CISSP, Security+, CCSK, or CGRC.

Requirements

Drive enterprise cybersecurity risk management by transforming compliance into a strategic advantage. Quantify risks, assess control effectiveness, and ensure alignment with NIST 800-53 and FISMA frameworks. Collaborate with Cybersecurity Engineers and Business Analysts to define compliance guardrails, prioritize remediation, and track key cyber risks. Conduct enterprise-wide risk assessments, audits, and user awareness programs to reduce risk and continuously improve the organization’s security posture.

Key Requirements
  • Expertise in GRC methodologies, third-party risk management (TPRM), and federal compliance (NIST SP 800-53, 800-37). Skilled in Risk Register tracking and maintenance, performing Security Impact Analyses, managing the POA&M lifecycle, and developing security awareness content to mitigate human-centric risks.
  • Risk Identification & Quantification: Lead enterprise-wide risk assessments using GRC methodologies to identify, evaluate, and prioritize risks, translating technical vulnerabilities into business impact for stakeholders.
  • Regulatory & Framework Alignment: Ensure ongoing compliance with federal frameworks, including NIST SP 800-53 and 800-37 (RMF), through periodic audits and Security Impact Analyses for new and existing system interconnections.
  • Strategic POA&M & Risk Register Oversight: Maintain and manage the enterprise Risk Register, tracking key cyber risks and overseeing the full lifecycle of Plans of Action and Milestones (POA&M), ensuring findings are documented, validated, and remediated within defined SLAs.
  • Key Cyber Risk Tracking: Continuously monitor and report critical cyber risks, using risk dashboards and metrics to provide actionable insights to leadership and maintain enterprise risk posture.
  • Human-Centric Risk & Awareness: Design and implement security awareness programs and phishing simulations (e.g., KnowBe4, Proofpoint) to reduce social engineering risks and strengthen organizational security culture.
  • Technical Remediation Partnership: Collaborate with Cybersecurity Engineers and Business Analysts to define compliance guardrails and prioritize remediation activities based on risk impact.
  • Advanced Risk Analytics & Visualization: Leverage GRC platforms (Archer, ServiceNow) and tools like Power BI and Excel to generate automated risk metrics, heat maps, and executive-level security posture reports.

Technologies: GRC Platforms (Archer/ServiceNow), TPRM Tools (OneTrust/Prevalent), Awareness Platforms (KnowBe4/Proofpoint), MS Power BI, Excel (Advanced), and JIRA.

CompQsoft provides equal opportunity in all aspects of employment and in the working environment to all employees and applicants. CompQsoft does not take any non-merit factors like race, color, religion, sex (gender), mental/physical disability, and age into account for purposes of recruitment, hiring and development.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Cybersecurity Assessor
Cybersecurity Assessor

CompQsoft Inc • New York (NY)

Hybrid
USD 120,000 - 160,000
Manager Security Compliance and Risk Management
Manager Security Compliance and Risk Management

LexisNexis • Raleigh (NC)

On-site
USD 118,000 - 220,000
Cybersecurity Risk Manager
Cybersecurity Risk Manager

Jobright.ai • Chicago (IL)

On-site
USD 120,000 - 180,000
Competitive benefits starting day one
Senior Cybersecurity Risk & Governance Analyst
Senior Cybersecurity Risk & Governance Analyst

mTrade • Oxford (MS)

On-site
USD 110,000 - 160,000
GRC Specialist (Governance, Risk & Compliance)
GRC Specialist (Governance, Risk & Compliance)

360CyberX • United States

On-site
USD 70,000 - 90,000
Cybersecurity Governance Analyst
Cybersecurity Governance Analyst

Veriipro • Fort Lauderdale (FL)

On-site
USD 90,000 - 130,000
GRC Analyst
GRC Analyst

The Emery Company, LLC • Houston (TX)

On-site
USD 85,000 - 110,000
Cybersecurity GRC Assessor - Risk & Compliance
Cybersecurity GRC Assessor - Risk & Compliance

CompQsoft Inc • New York (NY)

Hybrid
USD 120,000 - 160,000
Security Business Analyst
Security Business Analyst

CompQsoft Inc • New York (NY)

Hybrid
USD 110,000 - 150,000
Manager Security Compliance and Risk Management
Manager Security Compliance and Risk Management

RELX • Raleigh (NC)

On-site
USD 118,300 - 219,800
Annual incentive bonus