Senior Cyber Risk Management Engineer - Audit GRC

Request Technology

San Francisco (CA)

On-site

USD 80,000 - 120,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

An innovative firm is seeking a Senior Cyber Risk Management Capability Assessor to enhance their cyber risk management strategies. This role involves evaluating the effectiveness of current capabilities, conducting thorough risk assessments, and ensuring compliance with industry standards such as NIST 800-53 and SOC 2. You will work closely with various stakeholders to identify gaps and develop actionable plans to improve the organization's security posture. If you are passionate about cybersecurity and looking to make a significant impact in a dynamic environment, this opportunity is perfect for you.

Qualifications

  • 3-5 years of experience in cyber security and compliance.
  • Knowledge of NIST 800-53 and cloud-based cyber risk management.

Responsibilities

  • Conduct assessments of cyber risk management capabilities.
  • Develop reports on findings and remediation plans.
  • Support SOC 2 audits and regulatory compliance.

Skills

Cybersecurity
Risk Assessment
Compliance
Documentation
Stakeholder Collaboration

Education

Bachelor's degree in Cybersecurity
Certifications (CISSP, CISA, CISM, etc.)

Tools

NIST 800-53
Azure
Oracle Cloud Infrastructure

Job description

Get AI-powered advice on this job and more exclusive features.

Direct message the job poster from Request Technology

Executive Recruiter / Account Manager / Owner

NO SPONSORSHIP

RATE: Open

DURATION: ABOUT ONE YEAR

LOCATION: REMOTE

Job Description:

The Senior Cyber Risk Management Capability Assessor will evaluate the effectiveness and conduct risk assessments of cyber risk management capabilities, including policies, processes, and technical capabilities, leveraging enterprise cyber risk management requirement and control framework. This role involves significant work around issue management and Plan of Action and Milestones (POAM), supports SOC 1/2 Type 2 audits by external auditors, and prepares materials to support attestations for NAIC model laws and 23 NYCRR 500.

Responsibilities:

  • Cyber Risk Management Capability Assessments: Conduct thorough assessments of the effectiveness of cyber risk management capabilities within the organization.
  • Gap Analysis: Identify gaps in cyber risk management capability effectiveness and provide recommendations for enhancing the organization's cyber risk management posture.
  • Issue Management & POAM: Manage issues and develop Plan of Action and Milestones (POAM) to address identified gaps and vulnerabilities.
  • Documentation & Reporting: Develop detailed reports and documentation on assessment findings, remediation plans, and effectiveness metrics.
  • Stakeholder Collaboration: Work closely with cyber risk management, technology, and business partners to ensure that cyber risk management capabilities are effective.
  • Compliance, Standards, and Regulatory Alignment: Ensure adherence to regulatory and industry standard requirements such as NIST 800-53, SOC 2, 23 NYCRR 500, NAIC Model Law, and HIPAA. As regulations and standards are introduced and updated, assist in enhancing and extending the framework.
  • Audit Support: Support the performance of SOC 2 audits by external auditors and prepare materials to support attestations with NAIC model laws and NYDFS.

Education:

  • Bachelors degree in Cybersecurity, Information Security, Computer Science, or a related field.
  • Certifications (Preferred): CISSP, CISA, CISM, CRISC, CAP, Security+, or equivalent.

Experience:

  • Minimum 3-5 years of experience in cyber security, compliance, cyber risk assessment, or security auditing.

Technical Expertise:

  • Working knowledge of NIST 800-53.
  • Basic knowledge of cloud-based cyber risk management controls (Azure and/or Oracle Cloud Infrastructure).
  • Familiarity with technology management methodologies (DevOps, SAFe, ITIL).
  • Proficiency in multiple cyber risk management domains.
  • Understanding of cyber risk management oversight and administration processes, security architecture, technical security controls, and data protection strategies.
Seniority level
  • Not Applicable
Employment type
  • Contract
Job function
  • Information Technology
Industries
  • Insurance
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Cybersecurity Risk & Governance Analyst
Senior Cybersecurity Risk & Governance Analyst

Mortgage-Trade-Holding-Company,-LL • Oxford (MS)

On-site
USD 110,000 - 150,000
Senior Cybersecurity Risk & Governance Analyst
Senior Cybersecurity Risk & Governance Analyst

mTrade, LLC. • Oxford (MS)

On-site
USD 110,000 - 160,000
Senior Information Technology Audit Manager
Senior Information Technology Audit Manager

Smith Arnold Partners • Connecticut

On-site
USD 120,000 - 160,000
Cyber Security Engineer
Cyber Security Engineer

Trinity Global Consulting • Springfield (VA)

On-site
USD 90,000 - 110,000
Senior Cyber Risk Manager
Senior Cyber Risk Manager

Avantdigitalnow • San Francisco (CA)

On-site
USD 120,000 - 150,000
GRC Analyst
GRC Analyst

The Emery Company, LLC • Houston (TX)

On-site
USD 85,000 - 110,000
Senior Cybersecurity Risk & Governance Analyst
Senior Cybersecurity Risk & Governance Analyst

mTrade • Oxford (MS)

On-site
USD 110,000 - 160,000
Junior Cybersecurity GRC Analyst
Junior Cybersecurity GRC Analyst

Talanto • Northern (KY)

Hybrid
USD 5,500 - 12,000
Medical: Health plan options with HSA
Dental: PPO coverage
Vision: Annual exam allowance
+5
Sr. Audit Manager
Sr. Audit Manager

ConsultNet Technology Services and Solutions • New York (NY)

Hybrid
USD 165,000 - 185,000
Senior Cyber Risk Auditor & GRC Strategist (Remote)
Senior Cyber Risk Auditor & GRC Strategist (Remote)

Request Technology • San Francisco (CA)

On-site
USD 80,000 - 120,000