Sr. Cybersecurity Risk Management Engineer
QuEST Global
Job Requirements
Qualification:
8+ years of experience in information security or cybersecurity, with at least 3 years in a risk management-focused role.Bachelor’s degree in Management Information Systems (MIS), Computer Science or related field; CISA, CISM, CRISC, CISSP or similar certifications preferredStrong understanding of cybersecurity principles, threat modeling, and enterprise risk management.Experience with industry standard risk assessment frameworks (e.g., NIST, ISO, FAIR, etc)Experience implementing and maintaining cybersecurity compliance programs (ISO 27001, SOC 2, NIST CSF, etc) Familiarity with GRC platforms (e.g., Navex, Archer, ServiceNow GRC, LogicGate, RiskLens).Experience thinking critically and defending solutions with solid communications skills in a cross-functional setting to influence decision makers across all levels of technical backgroundStrong analytical, communication, and project management skills.Demonstrated knowledge of underlying technologies (i.e. databases, operating systems, applications, networks, security and hardware)
Responsibilities:
Lead risk assessments for critical systems, applications, vendors, and business processes using industry frameworks (e.g., NIST, ISO, FAIR).Evaluate and enhance risk management strategies, processes, and tools.Identify and analyze threats, vulnerabilities, and risk exposures to organizational assets.Clearly communicate security concepts to both technical and non-technical stakeholdersCollaborate with system owners to recommend, implement, and validate appropriate risk mitigation controls.Ensure risk registers and mitigation plans are documented, tracked, and maintained.Support compliance related efforts (ISO 27001, SOC 2, SOX, etc)Review collected evidence and ensuring that it meets the security control objectives and requirements
Confirmar seu email: Enviar Email