Cybersecurity Risk Analyst
Location: 100% Remote
Employment Type: Contract (W-2 only - No C2C
Position Overview
We are seeking a Cybersecurity Risk Analyst to support cybersecurity governance, risk management, and compliance activities within a large, complex organization. This individual will be responsible for evaluating cybersecurity risks, interpreting technical requirements in the context of established security policies and standards, and working with technical and business stakeholders to identify appropriate risk mitigation strategies.
The ideal candidate combines strong critical thinking and analytical skills with a solid understanding of cybersecurity principles. This role requires someone who can evaluate technical risks, clearly communicate their potential business impact, and make practical recommendations to reduce organizational exposure.
Key Responsibilities
- Perform cybersecurity risk assessments for applications, systems, technologies, processes, and business initiatives.
- Identify, analyze, document, and communicate cybersecurity risks and potential business impacts.
- Evaluate technical requirements, solutions, and controls against established cybersecurity policies, standards, and procedures.
- Translate technical security findings into understandable risk statements and actionable recommendations.
- Partner with technology, cybersecurity, and business teams to develop appropriate risk mitigation and remediation plans.
- Track identified risks and security issues through remediation and closure.
- Support the organization's cybersecurity issues, exceptions, and risk-acceptance management processes.
- Evaluate requests for exceptions to cybersecurity policies and standards and provide risk-based recommendations.
- Assist with the development, review, and maintenance of cybersecurity policies, standards, procedures, and supporting documentation.
- Identify gaps between current technical practices and established cybersecurity requirements.
- Provide guidance to stakeholders regarding cybersecurity requirements, controls, and risk mitigation options.
- Maintain accurate risk documentation and support reporting of cybersecurity risk to appropriate stakeholders.
- Collaborate across technical and non-technical teams to ensure cybersecurity risks are clearly understood and appropriately addressed.
Required Qualifications
- Professional experience in cybersecurity risk management, information security, GRC, IT risk, or a related discipline.
- Demonstrated experience performing cybersecurity or technology risk assessments.
- Strong understanding of cybersecurity concepts, controls, policies, standards, and risk management principles.
- Ability to evaluate technical information and determine its relationship to cybersecurity policies and requirements.
- Experience identifying security risks and developing practical mitigation recommendations.
- Strong critical-thinking, analytical, and problem-solving skills.
- Excellent written and verbal communication skills, including the ability to communicate technical risks to both technical and non-technical stakeholders.
- Ability to work independently and exercise sound judgment when evaluating cybersecurity risks.
- Strong organizational and documentation skills with the ability to manage multiple assessments, issues, and remediation activities simultaneously.
Preferred Qualifications
- Experience with cybersecurity governance, risk, and compliance (GRC) programs.
- Experience managing cybersecurity issues, policy exceptions, risk acceptances, or remediation plans.
- Familiarity with common cybersecurity frameworks and standards such as NIST Cybersecurity Framework (CSF), NIST 800-53, ISO 27001, CIS Controls, or similar frameworks.
- Experience working within a large enterprise or highly regulated environment.
- Experience with GRC or risk-management platforms such as ServiceNow GRC/IRM, Archer, OneTrust, or similar tools.
- Healthcare or other regulated-industry experience is a plus.
What We Are Looking For
The successful candidate will be someone who can look beyond a checklist and think critically about risk. You should be comfortable reviewing technical information, determining where cybersecurity concerns exist, connecting those concerns to organizational policies and standards, and recommending reasonable steps to mitigate the risk.
Just as importantly, you must be able to communicate effectively with engineers, cybersecurity professionals, business stakeholders, and leadership to help move identified risks toward resolution.