Quick Overview
Job Description
Core Responsibilities
• Conduct risk intake, assessments, triage sessions, and stakeholder risk discussions.
• Assess technology and cybersecurity risks using NIST, COBIT, and ISO frameworks.
• Identify, document, and evaluate inherent, residual, and emerging technology risks.
• Review controls and evaluate their effectiveness in mitigating identified risks.
• Map risks to controls and applicable framework and policy requirements.
• Facilitate control walkthroughs and risk discussions with control owners and stakeholders.
• Document risk statements, controls, evidence, and assessment results in governance tools and Word/Excel/PPT.
• Develop risk treatment recommendations and track remediation activities through closure.
• Escalate overdue actions, unresolved risks, and significant control or compliance concerns.
• Prepare executive-ready risk reports, dashboards, and governance presentation materials.
Required Knowledge and Skills
• Technology and Cybersecurity Fundamentals: Demonstrates a solid understanding of security controls, threats, and risk concepts. NIST, COBIT, and ISO 27001 framework knowledge.
• Risk Assessment & Analysis: Ability to identify, assess, and document technology and cybersecurity risks and control gaps. Understanding of control design, control effectiveness, and risk mitigation concepts.
• Project Management: Effectively plans, tracks, and executes work across multiple concurrent initiatives.
• Process Improvement: Identifies opportunities to streamline workflows and improve operational efficiency.
• Stakeholder Collaboration: Works effectively with crossfunctional teams and external partners.
• Communication: Clearly communicates technical risk information to both technical and nontechnical audiences.
• Attention to Detail: Produces accurate, welldocumented assessments and maintains reliable risk records.
• Tool proficiency: Microsoft Word, Excel, PowerPoint, and CoPilot. ServiceNow.
Requirements• Bachelor’s degree in Information Technology, Cybersecurity, Computer Science, Business, or a related field (or equivalent experience).
• 1–3 years of experience in cybersecurity or technology risk management, IT risk, cybersecurity, compliance, or related discipline.
• Foundational understanding of cybersecurity principles, risk assessment methodologies, and common security control frameworks.
• Experience supporting projects or initiatives that require coordination across multiple stakeholders.
• Strong written and verbal communication skills, with the ability to clearly document risks and recommendations.
Key Success Factors
• Comfortable navigating conversations with Control Owners and stakeholders.
• Clear and structured articulation of technology risks and controls.
• Strong attention to detail and documentation quality.
• Willingness to learn and grow within a Technology & Cybersecurity Risk Management function.
• Collaborative mindset across technical and non-technical teams.
Similar jobs
- IL
Sr. Site Reliability Engineer
Illumio
Sunnyvale🇺🇸On-site3 months agoDockerMicroservicesAWS+11Technology - HH
Staff Software Engineer, GI
NewHinge Health
San Francisco-HQ🇺🇸Hybrid4 hours agoNode.jsAWSComputer Vision+8Technology - HA
Senior Software Engineer, Coding
NewHandshake
San Francisco🇺🇸On-site41 minutes agoJavaScriptLLMMental Health+2Technology - SA
TS Cleared - Linux Systems Administrator
NewStaffRight Associates, LLC
McLean, VA🇺🇸$90k - $205k/yrOn-site17 hours agoDockerFiberBash+4Technology - SA
TS/SCI Cleared - Sr. Network Engineer
NewStaffRight Associates, LLC
McLean, VA🇺🇸$115k - $205k/yrOn-site17 hours agoTCP/IPBashPythonTechnology - HE
Data Analyst
NewHeartflow
Rohnert Park🇺🇸Hybrid50 minutes agoSQLSalesforceTableau+11Technology