Haystack
← Back to Jobs
Remote
Technology
MT

Cybersecurity Risk Analyst

MOURI TechUnited States🇺🇸United StatesPosted Oct 5, 2026

Quick Overview

Seniority
Mid Senior
Work mode
Remote
Location
United States
Posted
Yesterday
AWSEncryptionOWASPAzurePenetration Testing

Job Description

Role: Cybersecurity Risk Analyst
Location: Remote
Duration: 3+ Months with possibility extension

Position Summary:
The Cybersecurity Risk Analyst is responsible for identifying, assessing, and managing cybersecurity risks across the organization. This role partners with business, technology, application development, and security teams to evaluate threats, assess vulnerabilities, support compliance initiatives, and ensure appropriate security controls are implemented to protect company assets, systems, and data.
A key responsibility of this position is conducting application security reviews and risk assessments to identify security weaknesses, evaluate control effectiveness, and recommend remediation strategies throughout the application lifecycle.
Key Responsibilities

  • Perform cybersecurity risk assessments for applications, systems, infrastructure, and business initiatives.
  • Lead and conduct application security reviews, including evaluation of architecture, authentication, authorization, data protection, third-party integrations, and secure development practices.
  • Identify, document, and communicate cybersecurity risks and mitigation recommendations to technical and business stakeholders.
  • Review application assessment questionnaires and determine overall risk ratings and required security controls.
  • Ability to recommend system compensating controls and perform risk mapping to enterprise risk matrix.
  • Partner with application owners, developers, infrastructure teams, and project managers to ensure security requirements are addressed before implementation.
  • Assess compliance with cybersecurity policies, standards, and regulatory requirements.
  • Evaluate vulnerability assessment and penetration testing results and work with stakeholders to prioritize remediation activities.
  • Document identified risks through inputting into risk register/GRC tool.
  • Prepare reports and presentations for management regarding risk findings, trends, and remediation status.
  • Perform other related duties as assigned.


Required Qualifications

  • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Information Systems, or a related field, or equivalent work experience.
  • 3-5+ years of cybersecurity, information security, risk management, or GRC experience.
  • Must have hands-on experience performing application security reviews and risk assessments, including evaluating application architectures, security controls, data flows, authentication methods, third-party integrations, and compliance with organizational security requirements.
  • Demonstrated experience conducting application security reviews, application risk assessments, or secure architecture assessments.
  • Self-starter with a result-drive approach
  • Strong understanding of application security concepts, including:
  • Authentication and authorization
  • Identity and access management
  • Secure coding practices
  • API security
  • Encryption and key management
  • Data protection and privacy requirements
  • Cloud security controls
  • OWASP Top 10 risks
  • Experience identifying security requirements and evaluating applications against established security standards.
  • Knowledge of cybersecurity frameworks such as NIST CSF, NIST 800-171, IEC/IAS 62443, CIS Controls, ISO 27001, or similar frameworks.
  • Experience performing risk assessments and documenting risk treatment recommendations.
  • Strong analytical, verbal and written communications, and problem-solving skills.
  • Ability to communicate technical risks to both technical and non-technical audiences.
  • Preferred Qualifications
  • Experience with Governance, Risk, and Compliance (GRC) platforms.
  • Professional certifications such as CISSP, CISM, CRISC, Security+, CCSP, or CSSLP.
  • Experience supporting cloud environments such as Microsoft Azure or AWS.
  • Familiarity with secure software development lifecycle (SSDLC) methodologies.

Similar jobs