cybersecurity risk management

Brooklyn, NY, US • Posted 12 hours ago • Updated 12 hours ago
Full Time
No Travel Required
On-site
110000 - 115000/yr
Fitment

Dice Job Match Score™

🔢 Crunching numbers...

Job Details

Skills

  • Risk

Summary

Position: Cyber Risk Analyst
Location: Brooklyn, NY
Client: State Client

Certification: CISA, CRISC, CGEIT, CISSP, CompTIA Security+, CCSK, CAP/ISC2 CGRC

 

Drive enterprise cybersecurity risk management by transforming compliance into a strategic advantage. Quantify risks, assess control effectiveness, and ensure alignment with NIST 800-53 and FISMA frameworks. Collaborate with Cybersecurity Engineers and Business Analysts to define compliance guardrails, prioritize remediation, and track key cyber risks. Conduct enterprise-wide risk assessments, audits, and user awareness programs to reduce risk and continuously improve the organization’s security posture.
Key Requirements
• Expertise in GRC methodologies, third-party risk management (TPRM), and federal compliance (NIST SP 800-53, 800-37). Skilled in Risk Register tracking and maintenance, performing Security Impact Analyses, managing the POA&M lifecycle, and developing security awareness content to mitigate human-centric risks.
• Risk Identification & Quantification: Lead enterprise-wide risk assessments using GRC methodologies to identify, evaluate, and prioritize risks, translating technical vulnerabilities into business impact for stakeholders.
17
• Regulatory & Framework Alignment: Ensure ongoing compliance with federal frameworks, including NIST SP 800-53 and 800-37 (RMF), through periodic audits and Security Impact Analyses for new and existing system interconnections.
• Strategic POA&M & Risk Register Oversight: Maintain and manage the enterprise Risk Register, tracking key cyber risks and overseeing the full lifecycle of Plans of Action and Milestones (POA&M), ensuring findings are documented, validated, and remediated within defined SLAs.
• Key Cyber Risk Tracking: Continuously monitor and report critical cyber risks, using risk dashboards and metrics to provide actionable insights to leadership and maintain enterprise risk posture.
• Human-Centric Risk & Awareness: Design and implement security awareness programs and phishing simulations (e.g., KnowBe4, Proofpoint) to reduce social engineering risks and strengthen organizational security culture.
• Technical Remediation Partnership: Collaborate with Cybersecurity Engineers and Business Analysts to define compliance guardrails and prioritize remediation activities based on risk impact.
• Advanced Risk Analytics & Visualization: Leverage GRC platforms (Archer, ServiceNow) and tools like Power BI and Excel to generate automated risk metrics, heat maps, and executive-level security posture reports.
Experience: 3+ years
Certifications: CISA, CRISC, CGEIT, CISSP, Security+, CCSK, or CGRC.
Technologies: GRC Platforms (Archer/ServiceNow), TPRM Tools (OneTrust/Prevalent), Awareness Platforms (KnowBe4/Proofpoint), MS Power BI, Excel (Advanced), and JIRA

Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.
  • Dice Id: compqtx
  • Position Id: 9109388
  • Posted 12 hours ago
Contact the job poster
Krishna Prasad

Krishna Prasad

Recruiter @ CompQsoft,Inc .
Create job alert
Never miss an opportunity! Create an alert based on the job you applied for.

Similar Jobs

New York, New York

•

25d ago

Full-time

USD 165,000.00 - 225,000.00 per year

Brooklyn, New York

•

Today

Easy Apply

Full-time

100000 - 110000

New York, New York

•

Today

Full-time

New York, New York

•

4d ago

Full-time

USD 101,100.00 - 206,700.00 per year

Search all similar jobs