Job Title: Cybersecurity Risk Analyst
Location: Rancho Cucamonga, California (Hybrid)
LONG TERM Contract
Position Summary
The Cybersecurity Risk Analyst serves as a key contributor within Governance, Risk, and Compliance (GRC), responsible for assessing, strengthening, and advancing the organization’s cybersecurity posture. This role provides technical expertise, risk advisory, and program leadership to ensure enterprise security controls effectively safeguard digital assets.
Key Responsibilities
Lead and manage the enterprise cybersecurity compliance program, ensuring alignment with regulatory and industry standards (e.g., NIST, ISO 27001, HIPAA).
Conduct comprehensive risk assessments across systems, applications, and third-party vendors; identify gaps and recommend remediation strategies.
Evaluate and validate security controls, ensuring proper design and operational effectiveness.
Develop, implement, and maintain cybersecurity policies, standards, and procedures.
Analyze risks within the technology stack and supply chain; partner with stakeholders to manage and mitigate risks.
Build and maintain cybersecurity metrics, dashboards, and reporting for leadership visibility and decision-making.
Support incident response, threat management, and continuous improvement initiatives.
Perform access and privilege reviews for user and system accounts.
Provide input into disaster recovery, business continuity, and data protection strategies.
Conduct security reviews of tools, platforms, and enterprise solutions to identify vulnerabilities and control gaps.
Drive cybersecurity awareness and training programs across the organization.
Maintain documentation for security controls, risk assessments, and compliance activities.
Required Qualifications
Bachelor’s degree in Information Security, Computer Science, or related technical field.
Minimum of 5 years of experience in cybersecurity, with a focus on governance, risk, and compliance (GRC).
Strong knowledge of cybersecurity frameworks and standards (e.g., NIST CSF, ISO 27001, HITRUST, HIPAA).
Hands-on experience with risk assessments, control testing, and audit support.
Ability to translate technical risks into business impact for stakeholders.
Preferred Qualifications
Certifications such as CISSP, CISM, or CISA.
Experience in healthcare or regulated industries.
Familiarity with third-party/vendor risk management.
Experience building cybersecurity metrics and reporting frameworks