Cyber Risk Lead
PluralsightAbout the role
Job Description:
We are seeking an experienced security professional to join our Information Security team and be an integral part of developing our Information Security program. Reporting to the Director of IT GRC, Identity & Asset Management, this person will work closely with many parts of the business, including Engineering, Legal, IT, Support, People and Places, and Finance. Their primary focus will be on assessing and communicating business risk and threats. As a Cyber Risk Business Partner, you will also be involved in creating risk, business resilience and security strategy early in the design phase, building up and strengthening the Risk team, evangelizing cyber risk and security across teams, and be the business unit point of contact for security risk initiatives.
Who you’re committed to being:
You enjoy building processes from the ground up to streamline initiatives and other programs
You are an inquisitive, curious, critical thinker who is always looking for better ways to tackle cyber security problems
Persistent Problem-Solver- You know what it takes to protect the business and as the business changes, you find ways to manage information security in a practical way
You are an effective communicator within the information security community and within the business
You use data, empathy and good judgment to approach business problems
You enjoy researching, implementing, and teaching security and risk best practices
You are organized, can be flexible, leverage best practices, and most importantly, create solutions for any problem with a can-do attitude.
What you’ll do:
Support the Information Security office with the global IT risk management frameworks and legal entity regulatory requirements.
Lead the expansion of IT Risk Management Program including Vendor Risk Management, into a robust cybersecurity supply chain risk management business resilience program.
Conduct company-wide risk assessments, and develop and manage cybersecurity, data privacy, compliance, operational, product, and third party vendor risks management throughout vendor lifecycle
Implement risk assessment, including privacy related risk assessment strategies to qualify and/or quantify potential impact of risks utilizing known risk management frameworks to meet global legal, regulatory, and customer requirements.
Collaborate with IT, legal, Procurement and business partners, review agreements and contracts, monitor vendor performance, mitigate risks, and refine the risk management treatment program and maintain risk register.
Partner with vendors that align with the organization's needs and risk appetite, defining security and technical requirements. Overseeing technical builds, integrations, and implementations of new and existing tools ensuring full optimization of availability technology.
Test critical applications against adopted IT controls to ensure resilience and recovery objectives are met.
Create and manage continuous monitoring activities, execute updates to existing reporting and track, employing analytics features to protect against risk exposure. Identify, evaluate, and mitigate risks and vulnerabilities of third parties in the supply chain, and enforce security designs in any phase of product life cycle.
Assisting with the development of assessment programs, and questionnaires to aid in the mitigation of supplier security risks, and assist with existing and prospective customers.
Prepare internal and external communication plans and presentations, and develop risk-related policies, procedures and training that compliment global compliance, risk management frameworks, and best practices.
Experience you’ll bring:
Experience in information security risk assessment, business impact analysis, business resilience, auditing processes with a focus on SaaS and/or technical business.
Excellent organization skills, excellent interpersonal skills, problem solving and innovative thinking, attention to detail, ability to work well within a team and have a helpful and positive attitude.
Requirements:
Bachelors of Science in CIS/MIS/CS/CE, Engineering/Technology or related field or equivalent experience/training.
5+ years working in Risk, SaaS business, or technology industry.
Familiarity with security and privacy standards and regulations (e.g., NIST RFM, ISO 31000ERM, COSO ERM, GDPR, SOC 2, PCI, ISO 27001, COBIT, FAIR)
Applicable industry certifications (e.g., CIPP, CRISC, CISA, CISSP, CISM etc.)
Ability to travel up to 10%, includ
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s
Similar roles
Cloud Cybersecurity Engineer
General Dynamics Information Technology
$184,000/yr
Cyber SOC Incident Responder (Days) - TS/SCI with Polygraph
General Dynamics Information Technology
$184,000/yr
Senior Cybersecurity SIGINT SME (5339) (TS/SCI CI Poly) (Ft. Belvoir, VA )
smxtech