Enable job alerts via email!

Sr. Analyst, Cybersecurity Risk Management & Controls Assurance

General Motors

Austin (TX)

Hybrid

USD 100,000 - 130,000

Full time

7 days ago
Be an early applicant

Generate a tailored resume in minutes

Land an interview and earn more. Learn more

Start fresh or import an existing resume

Job summary

A leading automotive company seeks a Cybersecurity Risk Management and Controls Assurance Sr. Analyst in Austin, Texas. This role plays a key part in enhancing the company's cybersecurity posture by managing and mitigating risks, developing GRC frameworks, and driving continuous improvement in cybersecurity practices. Suitable candidates will demonstrate strong analytical skills and experience in risk management frameworks.

Qualifications

  • Experience with cybersecurity frameworks like NIST CSF.
  • Strong analytical and risk assessment skills.
  • Ability to communicate technical concepts to business stakeholders.

Responsibilities

  • Identify and mitigate cybersecurity risks impacting GM.
  • Develop and maintain a comprehensive GRC framework.
  • Collaborate with cybersecurity teams to improve controls.

Skills

Cybersecurity Risk Management
Data Management
GRC Processes
Stakeholder Communication

Education

Bachelor's degree in Computer Science, Cybersecurity, or related field

Tools

ServiceNow IRM

Job description

Location:

Hybrid: This role is categorized as hybrid. This means the successful candidate is expected to report onsite at the Warren-MI, Austin-TX, Roswell GA location at least three times per week minimum or other frequency dictated by the business. This job is not eligible for relocation benefits. Any relocation costs would be the responsibility of the selected candidate

The Role

The Cybersecurity Risk Management and Controls Assurance Sr. Analyst plays a pivotal role in strengthening GM’s cybersecurity posture. This position is responsible for identifying, assessing, and mitigating cybersecurity risks impacting GM’s people, platforms, products, productions, and partners. The Sr. Analyst ensures security controls are enforced, frameworks align with industry standards, and risk-related data is optimized to enhance resilience. This role drives collaboration with stakeholders to improve cybersecurity governance while managing GRC platforms, developing key cybersecurity metrics, and leveraging data visualizations for informed risk insights and decision-making. Additionally, the Sr. Analyst proactively evaluates and enhances the design and operating effectiveness of cybersecurity controls, identifying weaknesses and implementing continuous control monitoring and automation to minimize risk and reinforce security.

Risk Management:

  • Implement a comprehensive risk management program, including a quantifiable means to calculate both inherent and residual risks, and GM’s overall risk posture.
  • Conduct regular risk assessments of cybersecurity threats, vulnerabilities, and environmental factors affecting the business.
  • Analyze and prioritize identified risks based on their impact and likelihood.
  • Execute risk mitigation strategies, including potential control implementation and enhanced monitoring mechanisms, aligned to industry best practices.
  • Monitor and track mitigation results, assess impacts to residual risks, and recommend adjustments to the unified controls framework.
  • Report and present risk management progress to stakeholders.
  • Utilize quantitative and qualitative risk assessment methods to support informed decision-making and improve GM's overall cybersecurity risk posture.
  • Provide guidance and expertise to junior analysts and cross-functional teams on cybersecurity risk management best practices.

Controls Assurance:

  • Perform regular evaluations to assess the adequacy of the design and operating effectiveness of existing cybersecurity controls.
  • Identify control gaps and weaknesses, recommending solutions for improvement.
  • Conduct validations to ensure root causes of identified deficiencies are properly addressed.
  • Monitor and track progress on control remediation efforts to closure.
  • Support business continuity and risk resilience efforts, ensuring cybersecurity controls effectively mitigate potential threats and disruptions.

Unified Controls Framework:

  • Assist in the development and maintenance of a comprehensive GRC framework, tailored for GM’s Cybersecurity program, aligning with industry standards (e.g., NIST CSF, CIS), regulations, and organizational goals.
  • Ensure clear control ownership and alignment across all Cybersecurity functions.
  • Maintain essential GRC documentation, including processes, procedures, and risk registers.
  • Integrate GRC processes with enterprise-wide cybersecurity initiatives, processes, and reporting requirements.

Reporting and Communication:

  • Develop clear and concise reports on risk assessments and control effectiveness status for senior management and relevant stakeholders.
  • Collaborate between cybersecurity and other departments on risk and cybersecurity control-related matters.
  • Communicate effectively with cross-functional teams to build understanding and support for risk and controls-related initiatives.
  • Work closely with leadership to develop and refine cybersecurity risk strategies that align with GM’s business objectives.
  • Effectively communicate cybersecurity risk insights to stakeholders, translating technical findings into actionable business strategies.

Data & Automation:

  • Manage and maintain Cybersecurity’s GRC platform, analytics, and reporting (i.e., ServiceNow IRM).
  • Assist in the migration to and configuration of the ServiceNow IRM modules.
  • Support and maintain the Risk & Controls Dashboard.
  • Collaborate with federated Cybersecurity teams to populate risk-related data.
  • Assist in driving the organization to a continuous controls monitoring and reporting environment.
  • Design, develop, and implement GRC workflows to streamline risk initiatives.
  • Design and implement data integration strategies to consolidate information from multiple sources into a unified system.

Continuous Improvement:

  • Identify opportunities to improve the effectiveness and efficiency of our GRC program.
  • Implement initiatives to enhance the overall cybersecurity posture of the organization.
  • Stay informed about evolving cybersecurity threats, regulations, and best practices.
  • Maintain awareness of evolving cyber threats, industry trends, and regulatory developments to proactively strengthen GM’s cybersecurity framework.
  • Research and evaluate emerging threats, technologies, and security trends to enhance GM’s cybersecurity risk posture.
Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.