Jobs and Careers
DI

Principal Cybersecurity Analyst ( Cybersecurity Risk and Control )

Discover
Riverwoods, IL, United Statesfull_timeVerifiedPosted 22 Oct 2024
💰 $174,200/yr($103,000/yr$174,200/yr)

About the role

Discover. A brighter future.

With us, you’ll do meaningful work from Day 1. Our collaborative culture is built on three core behaviors: We Play to Win, We Get Better Every Day & We Succeed Together. And we mean it — we want you to grow and make a difference at one of the world's leading digital banking and payments companies. We value what makes you unique so that you have an opportunity to shine.

Come build your future, while being the reason millions of people find a brighter financial future with Discover.

Job Description:

What You’ll Do
 

  • We are seeking a highly skilled and experienced Cybersecurity Risk and Control Self-Assessment Expert to join our team. The ideal candidate will be responsible for conducting comprehensive risk assessments, evaluating the effectiveness of security controls, and implementing strategies to mitigate identified risks. This role requires a deep understanding of cybersecurity principles, risk management frameworks, and control assessment methodologies.
  • Optimizes cybersecurity program processes and output. Contributes to the broader program roadmap. Drives reporting accuracy and demand excellence in department deliverables.
  • Actively manages and escalates risk and customer-impacting issues within the day-to-day role to management.


 

How You’ll Do It
 

  • Conduct thorough cybersecurity risk assessments to identify potential threats and vulnerabilities within the organization’s infrastructure, and application.
  • Develop and implement risk management strategies to mitigate identified risks and ensure the security of information assets.
  • Perform control self-assessments to evaluate the effectiveness of existing security controls and identify areas for improvement.
  • Develop new risks and controls to address the security gaps.
  • Collaborate with various departments to ensure that cybersecurity risks are identified, assessed, and managed in accordance with organizational policies and industry best practices.
  • Develop and maintain risk assessment and control self-assessment documentation, including reports, policies, and procedures.
  • Assess the effectiveness of security controls and create control effectiveness rationale.
  • Provide guidance and training to staff on cybersecurity risk management and control assessment practices.
  • Stay up-to-date with the latest cybersecurity trends, threats, and technologies to ensure the organization’s security posture remains robust.
  • Assist in the implementation of cybersecurity policies, standards, and guidelines.
  • Map the organization's cybersecurity standards to the industry frameworks and its applicable controls.
  • Manages and executes cybersecurity risk assessments using qualitative and quantitative methodologies to support the organization's overall security posture.
  • Maintains an awareness of emerging cybersecurity threats by analyzing and reporting on cybersecurity risk against various Cybersecurity Frameworks (NIST CSF, NIST 800-53, PCI-DSS).
  • Performs in-depth analysis of security issues and vulnerabilities using tools including WhiteHat, Veracode, and Qualys to ensure compliance with audit, regulatory and legal requirements.
  • Designs metrics and develops advanced capabilities to ensure confidentiality, integrity, availability, authentication, and non-repudiation to communicate elevated risk in a business-friendly manner to Cybersecurity Leadership and 2nd line partners. Proactively identifies and reports control deficiencies as issues within action plans.
  • Conduct strategic and operational effectiveness assessments as required for cyber events, and regulatory and audit reviews
  • Partner with Product Owners to evaluate current security posture and drive future security control implementations based on gaps found during the cybersecurity risk assessment.
  • Utilizes ServiceNow and Cyber Risk System for risk management and risk remediation, processing potential security exceptions and/or risk acceptances against established security policies and standards.
  • Documents risk assessments in Archer enterprise governance, risk and compliance tool for review by external regulators and auditors. Prepares department, committee, and board-level reports and presentation materials.
  • Gathers and challenges data, evidence, or statuses for accuracy to achieve initiative and risk mitigation completion.


Qualifications You’ll Need
The Basics
 

  • Bachelor’s degree in information security, Information Technology, Analytics, Business Administration and Management or Project Management
  • 6+ years of expe

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Discover

View company profile →