Jobs and Careers
AX

Cybersecurity Assurance Analyst

Axonius
Remote US, United StatesRemotefull_timeVerifiedPosted 20 Dec 2024
💰 $130,000/yr($115,000/yr$130,000/yr)

About the role

Location: EST or CST timezones only

About the Role

We are seeking a highly motivated and detail-oriented Cybersecurity Analyst to join our growing security team with a focus on Governance, Risk, and Compliance (GRC). This is a fully remote position within the US, but candidates must be located in the CST or EST time zones. In this role, you will play a key part in ensuring the security of our organization's information assets and compliance with relevant regulations by collaborating with stakeholders to identify and mitigate risks, ensure compliance, and develop and implement security policies and procedures. You will also be involved in vendor management, reporting and metrics, and cross-functional collaboration. The ideal candidate will have a strong understanding of cybersecurity principles, compliance requirements, and GRC frameworks, as well as experience conducting risk assessments and using GRC tools. 

The GRC team member will be responsible for assisting in the day-to-day tasks related to governance, risk management, and compliance. This includes

Governance, Risk, and Compliance (GRC)

  • Framework Implementation: Collaborate to develop, review, and update strategies, policies, and procedures related to cybersecurity and technology governance. Employ effective project management techniques to manage governance routines and meetings and to maintain compliance processes.
  • Risk Management: Employ strong project management skills to collaborate with stakeholders across the organization, identify and analyze cybersecurity risks, and develop and implement remediation plans within established timelines. Conduct risk assessments and internal reviews to proactively identify potential compliance issues. Maintain consistent follow-up with risk owners to ensure accountability and effective risk mitigation, driving the organization's risk management program toward its defined risk appetite
  • Compliance: Proactively manage compliance activities by ensuring timely responses to risk assessments, audits, and customer or prospect inquiries. This includes preparing for and supporting internal and external audits, promptly addressing audit findings and closing identified gaps, maintaining and improving internal control standards, and staying current on relevant regulations and industry standards (including NIST and GDPR).
  • Vendor Management: Assist with the vendor risk lifecycle, which requires collaborating with stakeholders across various teams, such as Corp IT, SecOps, Legal, and Procurement. This includes maintaining vendor security information, conducting security assessments, ensuring compliance with security requirements, and providing technical expertise to evaluate the security posture of SaaS systems, integrations, and add-ons.
  • Training & Awareness: Collaborate with stakeholders to develop and deliver effective security awareness and GRC training programs. Take ownership of tracking training compliance and identifying areas for program improvement.
  • Policy & Procedure Management: Collaborate with stakeholders to develop, maintain, and update security policies, procedures, and standards. Take ownership of tracking policy exceptions and ensuring proper approvals are obtained.
  • Reporting and Metrics: Assist with developing and maintaining comprehensive security metrics and reporting processes to track key performance indicators (KPIs), identify trends, and inform decision-making. Track KPIs such as the number of open risks, time to remediate risks, and compliance with key regulations. Continuously improve reporting accuracy, efficiency, and effectiveness to align with evolving organizational needs.
  • Cross-functional Collaboration: Foster strong partnerships with stakeholders across Legal, Technology, Sales, and Finance teams to ensure alignment on security objectives and initiatives. For example, partner with the Sales team to help address customer or prospect questions regarding our security program, which might also include completing the CAIQ or SigLite and posting it to our trust center.

Qualifications

  • Exceptional collaboration and communication skills, with a proven ability to build consensus and effectively communicate GRC activities to diverse audiences, including senior management.
  • A degree in a related field and 3+ years of experience in cybersecurity or IT, OR a minimum of 5 years of combined relevant education and experience in cybersecurity or IT.
  • Understanding of cybersecurity principles, compliance requirements, risk assessments, and GRC frameworks.
  • Understanding of relevant security regulations and frameworks (e.g., ISO 27001, SOC2, NIST CSF,

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Axonius

View company profile →