Cybersecurity Risk & Reporting Analyst
MarkelAbout the role
What part will you play? If you’re looking for a place where you can make a meaningful difference, you’ve found it.
The work we do at Markel gives people the confidence to move forward and seize opportunities, and you’ll find your fit amongst our global community of optimists and problem-solvers. We’re always pushing each other to go further because we believe that when we realize our potential, we can help others reach theirs. Join us and play your part in something special! The Cybersecurity Risk & Reporting Analyst has two critical functions. First, from a reporting perspective, this role leads the development, maintenance, and enhancement of cybersecurity dashboards and metrics to deliver clear, visually engaging, and actionable insights. The analyst turns technical data into meaningful visualizations that are consumed across the organization, including bysenior executives. Second, from a risk perspective, this role supports the cybersecurity program by contributing to the identification, assessment, and tracking of cybersecurity risks across the organization, including third-party/vendor risk. The analyst helps ensure that cybersecurity risks are
documented, communicated, and monitored effectively to support mitigation efforts and strategic decision-making.
Job Location: Hybrid work arrangement based in Richmond, VA
Job Responsibilities
Reporting: Contributes to the development, maintenance, and enhancement of cybersecurity dashboards and metrics to deliver clear, visually engaging, and actionable insights.
Compile and analyze cybersecurity data to produce dashboards and reports for stakeholders across the organization, including senior leadership.
Translate technical cybersecurity metrics into meaningful visualizations that support decision- making and risk mitigation.
Identify business requirements and create scalable technical specifications for reporting solutions.
Code, test, and deliver reporting outputs using tools such as Power BI, Excel, and other visualization platforms.
Analyze key metrics to identify trends, gaps, and opportunities for improvement; recommend changes or solutions as needed.
Troubleshoot reporting issues and perform ad-hoc data analysis to support cybersecurity initiatives.
Create and maintain documentation for reporting processes, data sources, and dashboard functionality according to department standards.
Cybersecurity Risk: Supports the cybersecurity program by contributing to the identification, assessment, and tracking of cyber risks across the organization.
Participate in internal cybersecurity risk assessments and third-party/vendor risk evaluations.
Document and communicate identified risks and assist in tracking mitigation efforts and control effectiveness.
Partner with stakeholders across IT, risk, and business units to ensure cybersecurity risks are understood and addressed appropriately.
Contribute to the development and refinement of cybersecurity KPIs and KRIs.
Maintain awareness of cybersecurity frameworks (e.g., NIST, ISO 27001) and apply them to risk assessment activities.
Support the continuous improvement of cybersecurity risk management processes and tools.
Assist in the financial quantification of cybersecurity risks, helping translate technical risk.
scenarios into potential business impact using models or frameworks that support risk-informed decision-making.
Education
College degree in Information Security, Cybersecurity, Computer Science, or related work experience/certification.
Certification
Certifications that are a plus:
Microsoft Certified: Power BI Data Analyst Associate
CompTIA Security+
(ISC)2 Certified in Cybersecurity (CC)
ISACA Cybersecurity Fundamentals Certificate
Certified in Risk and Information Systems Control (CRISC)
FAIR Fundamentals Certificate
Work Experience/Skill Set
Proficiency in Power BI or other reporting/visualization tools.
Proficiency with HTML, Web APIs, and scripting languages (e.g., Python, JavaScript).
Strong knowledge of Excel formulas, pivot tables, and graphing techniques.
Familiarity with cybersecurity risk management frameworks (e.g., NIST, ISO 27001).
Understanding of cloud computing environments (e.g., Azure, AWS, GCP).
Excellent customer service and stakeholder engagement skills.
Strong critical thinking, attention to detail, and problem-solving abiliti
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s