" Technology & Cybersecurity Risk Management Analyst"
Job Summary
Technology & Cybersecurity Risk Management Analyst
Division | Cybersecurity |
Location | Plano Texas |
Experience Required | 13 Years |
We are seeking a Technology & Cybersecurity Risk Management Analyst to support enterprise technology and cybersecurity risk management initiatives.
This role will focus on identifying assessing documenting and monitoring technology and cybersecurity risks while working closely with control owners and business stakeholders. The successful candidate will conduct risk assessments evaluate security controls support remediation activities and develop risk reporting and governance materials.
The ideal candidate has foundational experience in cybersecurity technology risk IT risk compliance or governance with knowledge of frameworks such as NIST COBIT and ISO 27001.
Conduct risk intake assessments triage sessions and stakeholder risk discussions.
Assess technology and cybersecurity risks using NIST COBIT and ISO 27001 frameworks.
Identify document and evaluate inherent residual and emerging technology risks.
Review security controls and assess their effectiveness in mitigating identified risks.
Map risks to controls policies and applicable framework requirements.
Facilitate control walkthroughs and risk discussions with control owners and stakeholders.
Document risk statements controls evidence and assessment results.
Develop risk treatment and mitigation recommendations.
Track remediation activities and action items through closure.
Escalate overdue actions unresolved risks and significant control or compliance concerns.
Maintain accurate and complete risk records within governance and risk management tools.
Develop executive-ready risk reports dashboards and governance presentations.
Communicate technology and cybersecurity risks to technical and non-technical stakeholders.
Coordinate risk activities across multiple stakeholders and concurrent initiatives.
Identify opportunities to improve and streamline risk management processes.
Bachelors degree in Information Technology Cybersecurity Computer Science Business or a related field or equivalent professional experience.
13 years of experience in cybersecurity technology risk management IT risk compliance governance or a related discipline.
Foundational understanding of cybersecurity principles security controls threats and risk assessment methodologies.
Knowledge of NIST COBIT and ISO 27001 frameworks.
Understanding of control design control effectiveness and risk mitigation concepts.
Experience supporting projects or initiatives involving multiple stakeholders.
Strong analytical organizational and project coordination skills.
Strong written and verbal communication skills.
Ability to clearly document risks controls findings and recommendations.
ServiceNow
Microsoft Excel
Microsoft PowerPoint
Microsoft Word
Microsoft Copilot
Governance Risk & Compliance (GRC) tools
NIST
COBIT
ISO 27001
The ideal candidate is a detail-oriented cybersecurity or technology risk professional who is comfortable working with control owners and stakeholders across technical and business teams. Strong candidates will be able to clearly articulate technology risks controls control gaps and remediation requirements while maintaining high-quality documentation and supporting multiple risk initiatives simultaneously.