Senior Analyst, Security Risk in United States Embassy at Jobgether
Explore Related Opportunities
Job Description
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Senior Analyst, Security Risk based in United States.
This role offers an exciting opportunity to strengthen enterprise security risk management within a highly collaborative, remote-first environment. You will help identify, assess, and mitigate cybersecurity risks while partnering with engineering, product, and business teams to enhance organizational resilience. The position combines strategic thinking with hands-on execution, leveraging industry frameworks, automation, and data-driven insights to improve risk operations. You will contribute to the evolution of mature governance and compliance practices while supporting informed decision-making across the business. This is an ideal opportunity for an experienced risk professional who thrives in dynamic environments and enjoys driving continuous improvement through innovation and cross-functional collaboration.
The Senior Analyst, Security Risk will play a key role in advancing enterprise security risk management by supporting risk identification, assessment, reporting, and mitigation initiatives. Working closely with technical and business stakeholders, this role helps ensure risk processes remain effective, scalable, and aligned with regulatory requirements and industry best practices.
- Execute and continuously improve security risk management processes and day-to-day program operations.
- Maintain and enhance enterprise risk registers, key risk indicators (KRIs), and risk tracking activities.
- Partner with Product, Engineering, Security, Compliance, and business teams to identify, evaluate, and communicate cyber risks.
- Assess the effectiveness of risk treatment plans and recommend mitigation strategies where appropriate.
- Prepare dashboards, reports, presentations, and executive-level updates highlighting key risks, trends, and remediation progress.
- Analyze qualitative and quantitative risk data to support informed business decisions and predictive risk modeling.
- Translate technical vulnerabilities, control gaps, and operational issues into clear business risk statements.
- Support compliance initiatives and coordinate with internal and external auditors during assessments.
- Leverage automation, AI, and governance tools to improve the efficiency and scalability of risk operations.
- Contribute to the ongoing maturity of enterprise risk frameworks and security governance practices.
The ideal candidate brings extensive experience in cybersecurity risk management and enterprise governance, along with strong analytical, communication, and stakeholder management skills. They are comfortable navigating ambiguity, collaborating across technical and business teams, and driving measurable improvements to security risk programs.
- 5+ years of experience in security risk management, governance, compliance, or related cybersecurity disciplines.
- Hands-on experience with recognized risk management frameworks such as NIST RMF, ISO 31000, COSO, or similar methodologies.
- Strong background performing qualitative and quantitative cyber risk assessments.
- Experience managing enterprise risk registers, compliance initiatives, and large-scale cross-functional risk programs.
- Ability to translate technical security issues into actionable business risk recommendations.
- Experience working closely with engineering, IT, and security teams to implement effective risk controls.
- Familiarity with AI-powered solutions, automation, and governance, risk, and compliance (GRC) platforms.
- Excellent written, verbal, and presentation skills with the ability to communicate effectively at all organizational levels.
- Strong analytical, problem-solving, and organizational skills with the ability to manage multiple priorities.
- Bachelor's degree in Risk Management, Business, Cybersecurity, Finance, or a related field preferred.
- Professional certifications such as CRISC, CISSP, CISA, FRM, or equivalent are considered an asset.
- Fully remote position within the United States (location restrictions may apply).
- Competitive salary based on experience and geographic location.
- Eligibility for performance bonus and equity programs, where applicable.
- Comprehensive medical, dental, and vision healthcare coverage.
- 401(k) retirement savings plan.
- Generous paid time off, paid sick leave, and parental leave.
- Wellness programs and additional employee support benefits.
- Occasional travel opportunities for team collaboration and project meetings.
- Opportunity to contribute to a growing, innovative, and globally distributed organization.