Senior Cyber Risk Management Engineer

White Cap Supply Holdings, LLC.

United States

Hybrid

USD 110,000 - 170,000

Full time

14 days+
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

White Cap Supply Holdings, LLC. is seeking a cybersecurity risk professional to implement and maintain risk frameworks (NIST CSF/RMF) and to assess security controls across the organization.

The role requires deep expertise in identifying gaps, leading risk mitigation, and communicating findings to senior IT leaders. Hybrid work arrangement and opportunities to influence security posture across critical infrastructure.

Qualifications

  • 5+ years of cybersecurity experience conducting risk assessments, identifying security gaps, and mitigation strategies.
  • Strong analytical and problem-solving skills, with the ability to communicate complex technical issues to senior IT leaders and non-technical stakeholders.
  • Experience with identity and access management (IAM), identity governance and administration (IGA), and Privileged Access Management (PAM).
  • Knowledge of access governance, least-privilege principles, privileged account lifecycle management, access reviews, RBAC, and security exception management.
  • Hands-on experience conducting information security assessments, SC1/SC2 control testing, remediation tracking.
  • In-depth knowledge of NIST CSF and RMF with ability to apply to organizational security practices.
  • Working knowledge of CIS Controls and CIS Benchmarks; experience documenting control gaps.
  • Experience administering risk and control self-assessments (RCSAs) and coordinating with risk/control owners.
  • Ability to collect, validate, reconcile, and analyze security data and develop key risk indicators.
  • Experience producing security dashboards and executive-level presentations for leadership reviews.
  • Certifications: CRISC, CGRC, CISSP or comparable.

Responsibilities

  • Conduct thorough and regular risk assessments to identify threats and vulnerabilities related to critical infrastructure.
  • Identify, track, and report on Cyber Key Risk Indicators.
  • Collaborate with cross-functional teams to integrate security measures into processes and systems.
  • Stay updated on emerging cyber threats and industry best practices; conduct threat intelligence monitoring.
  • Lead the implementation of comprehensive cyber risk management strategies and risk monitoring.
  • Perform annual assessments of operating system security baselines.

Skills

Cyber risk assessments
NIST CSF
RMF
Threat intelligence
Risk governance
IAM/IGA/PAM
Control testing
Executive communication
Security dashboards

Education

BS/BA in related field
MS/MA in related field

Job description

A position at White Cap isn’t your ordinary job. You’ll work in an exciting and diverse environment, meet interesting people, and have a variety of career opportunities.

The White Cap family is committed to Building Trust on Every Job. We do this by being deeply knowledgeable, fully capable, and always dependable, and our associates are the driving force behind this commitment.

Job Summary

Responsible for providing expertise in implementing and maintaining cybersecurity risk frameworks, including NIST CSF ( National Institute of Standards and Technology Cybersecurity Framework) and NIST RMF (National Institute of Standards and Technology Risk Management Framework). Assess, review, and help identify areas where security controls do not exist currently.

Major Tasks, Responsibilities and Key Accountabilities
  • Conduct thorough and regular risk assessments to identify and evaluate potential threats and vulnerabilities related to critical infrastructure. Develop and maintain cyber risk-based statements and scenarios to enhance risk register capabilities.

  • Identify, track, and report on Cyber Key Risk Indicators.

  • Collaborate with cross-functional teams to ensure the integration of security measures into organizational processes and systems.

  • Stay updated on emerging cyber threats and industry best practices to enhance risk mitigation strategies. Conduct threat intelligence monitoring and reporting as needed.

  • Lead the implementation of comprehensive cyber risk management strategies and risk monitoring.

  • Perform annual assessments of operating system security baselines.

Nature and Scope
  • Identifies key barriers/core problems and applies problem-solving skills in order to deal creatively with complex situations. Troubleshoots and resolves complex problems. Makes decisions under conditions of uncertainty, sometimes with incomplete information, that produce effective end results.

  • Independently performs assignments with instruction limited to the expected results. Determines and develops an approach to solutions. Receives technical guidance only on unusual or complex problems or issues.

  • May oversee the completion of projects and assignments, including planning, assigning, monitoring and reviewing progress and accuracy of work, evaluating results, etc. Contributes to employees' professional development but does not have hiring or firing authority.

Work Environment
  • Located in a comfortable indoor area. Any unpleasant conditions would be infrequent and not objectionable.

  • Most of the time is spent sitting in a comfortable position and there is frequent opportunity to move about. On rare occasions, there may be a need to move or lift light articles.

  • Typically requires overnight travel less than 10% of the time.

Education and Experience
  • Typically requires BS/BA in a related discipline. Generally 5-8 years of experience in a related field OR MS/MA and generally 3-5 years of experience in a related field. Certification is required in some areas.
Preferred Qualifications
  • REQUIRED: 5+ years of cybersecurity experience conducting risk assessments, identifying security gaps, and recommending mitigation strategies.

  • REQUIRED: Strong analytical and problem-solving skills, with the ability to communicate complex technical issues to senior IT leaders and non-technical stakeholders.

  • Experience with identity and access management (IAM), identity governance and administration (IGA), and Privileged Access Management (PAM) processes and platforms.

  • Knowledge of access governance, least-privilege principles, privileged account lifecycle management, access reviews, role-based access control, and security exception management.

  • Hands-on experience conducting information security assessments, application control self-assessments (SC1/SC2), control testing, and remediation tracking.

  • In-depth knowledge of NIST Cybersecurity Framework (CSF) and Risk Management Framework (RMF), with a strong ability to apply these frameworks to organizational security practices.

  • In-depth knowledge of operating systems and security baselines, including CIS Controls and CIS Benchmarks, with experience assessing technology configurations and documenting control gaps.

  • Experience administering Risk and Control Self-Assessments (RCSAs), maintaining risk and control documentation, validating evidence, and coordinating with risk and control owners.

  • Ability to collect, validate, reconcile, and analyze security data; develop key risk indicators and operational metrics; and investigate missing, incomplete, or inconsistent information.

  • Experience producing security dashboards, program reporting, trend analysis, and concise executive-level presentations for monthly leadership reviews.

  • Strong written, verbal, and stakeholder-management skills, with the ability to communicate control issues clearly to business, technology, security, and leadership audiences.

  • Preferred certifications: CRISC (ISACA), CGRC ((ISC)²), CISSP ((ISC)²), or comparable governance, risk, access management, or information security certifications.

If you’re looking to play a role in building America, consider one of our open opportunities. We can’t wait to meet you.

Functional Area

Information Technology

Work Type

Hybrid

Req ID

WCJR-035046

White Cap is an Equal Opportunity Minority/Female/Individuals with Disabilities/Protected Veteran and White Cap considers for employment and hires qualified candidates without regard to age, race, religion, color, sex, sexual orientation, gender, gender identity, national origin, ancestry, citizenship, protected veteran or disability status or any factor prohibited by law.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Cyber Risk Management Engineer
Senior Cyber Risk Management Engineer

White Cap Supply Holdings, LLC. • Northern (KY)

Hybrid
USD 90,000 - 130,000
Senior Cyber Risk Management Engineer
Senior Cyber Risk Management Engineer

White Cap • Atlanta (GA)

On-site
USD 120,000 - 160,000
Director, Information Security
Director, Information Security

The Security Executive Council • Doraville (GA)

On-site
USD 100,000 - 130,000
Senior Cyber Risk Engineer — NIST CSF/RMF
Senior Cyber Risk Engineer — NIST CSF/RMF

White Cap Supply Holdings, LLC. • Northern (KY)

Hybrid
USD 90,000 - 130,000
Senior Cyber Risk Engineer | NIST CSF/RMF Lead
Senior Cyber Risk Engineer | NIST CSF/RMF Lead

White Cap Supply Holdings, LLC. • United States

Hybrid
USD 110,000 - 170,000
Senior Cyber Risk Architect — NIST CSF/RMF Expert
Senior Cyber Risk Architect — NIST CSF/RMF Expert

White Cap • Atlanta (GA)

On-site
USD 120,000 - 160,000
Senior Cyber Risk Manager
Senior Cyber Risk Manager

Avantdigitalnow • San Francisco (CA)

On-site
USD 120,000 - 150,000
Senior Cyber Security Analyst
Senior Cyber Security Analyst

Ampcus Inc • Washington

On-site
USD 90,000 - 120,000
Risk Manager
Risk Manager

Management Solutions • Washington

On-site
USD 130,000 - 160,000
Medical, Rx, Dental, and Vision Insurance
401(k) plan with up to a 5% match
Paid holidays and PTO
Risk Manager
Risk Manager

Management Solutions LLC • Washington

On-site
USD 120,000 - 140,000
Medical, Rx, Dental, and Vision Insurance
401k plan with up to 5% match and immediate vesting
Flexible Spending Accounts
+1