Job Description
Senior Cybersecurity Risk Analyst
Bring your cybersecurity expertise to an environment where collaboration, innovation, and continuous improvement drive success. Play a key role in security assessments, risk oversight, and strategic initiatives that help strengthen organizational security and resilience.
What is in it for you:
• Salaried: $77-87.90 per hour.
• Incorporated Business Rate: $90-100.40 per hour.
• 12-month contract with the potential for permanent employment.
• Day schedule, 37.50 hours per week.
• Hybrid model: 3 days per week on-site, subject to change.
Responsibilities:
• Review and, when required, conduct Information Security Risk Assessments (ISRAs) and Third-Party Information Security Assessments (TPISAs).
• Manage and mitigate cybersecurity risks and provide cybersecurity consulting services to technology and business teams.
• Provide oversight on assessments, risk identification, risk management processes, and risk reporting tools.
• Continuously improve the quality of cybersecurity risk management services.
• Identify gaps in existing processes and technologies and develop remediation plans to address risks.
• Support the development and enhancement of cybersecurity risk reporting and Key Risk Indicators (KRIs).
• Ensure identified cybersecurity risks are effectively communicated and managed according to risk-prioritized timelines.
• Provide senior management and executives with information on security trends, identified risks, and the effectiveness of security activities.
• Increase visibility of cybersecurity risks when action plan target dates are not met.
• Manage penetration testing and business impact assessment programs.
• Prepare for Internal Risks and Control Assessments.
• Collaborate with security and IT teams to implement security solutions that strengthen the overall security posture.
• Contribute to improving team processes, efficiency, and quality standards.
What you will need to succeed:
Required qualifications
• Post-secondary education in Computer Science, Computer Engineering, IT Security, Risk Management, or comparable professional training.
• 10+ years of progressive experience in cybersecurity risk assessments, vendor assessments, and continuous risk management.
• Experience conducting or reviewing Information Security Risk Assessments (ISRAs) and Third-Party Information Security Assessments (TPISAs).
• Strong understanding of cybersecurity industry standards, principles, practices, and risk concepts.
• Knowledge of cybersecurity controls and concepts.
• Knowledge of Ariba, Archer, or other GRC management platforms.
Preferred qualifications
• Professional cybersecurity or IT risk certification such as CISSP, CISA, CISM, CCSP, CCSK, or GIAC.
• Understanding of application security design and architecture.
Soft skills
• Resourceful.
• Forward-thinking.
• Collaborative.
• Comfortable working in a fast-paced environment.
• Strong communication skills.
• Leadership skills.
• Ability to communicate complex issues clearly and concisely to a wide range of audiences and stakeholders.
• Ability to navigate ambiguity and guide teams through change.
• Ability to understand complex processes and make sound judgment calls.
• Ability to negotiate and influence others to achieve optimal results.
Why Recruit Action?
Recruit Action (agency permit: AP-2504511) provides recruitment services through quality support and a personalized approach. As part of the screening process, some applications may be reviewed using artificial intelligence tools. Only candidates who meet the hiring criteria will be contacted.
Requirements
—