- Company Name
- CarMax
- Job Title
- Sr. Analyst, Cybersecurity (Information Risk)
- Job Description
-
Job Title: Sr. Analyst, Cybersecurity (Information Risk)
Role Summary:
Senior technology risk analyst responsible for designing, executing, and maintaining an enterprise-wide information risk management framework. Supports risk assessments, compliance, and policy development across technology, compliance, and cybersecurity teams. Drives risk identification, mitigation recommendations, and awareness programs, ensuring alignment with regulatory requirements and corporate risk appetite.
Expectations:
- Must be authorized to work in the United States full‑time; no sponsorship.
- Deliver actionable risk assessments on existing and emerging technology assets.
- Exhibit ownership and initiative, communicating clearly with technical and business stakeholders.
Key Responsibilities:
- Design and implement information risk management methodology and classification schemes.
- Conduct security risk assessments, analyze threats and vulnerabilities, and provide risk‑based business recommendations.
- Develop, maintain, and enforce policies, procedures, and controls for data confidentiality, integrity, and availability.
- Administer governance, risk, and compliance (GRC) systems, and develop automated risk tools.
- Prepare risk reports, recommendations, and management communications.
- Design and deliver training and awareness initiatives to reduce organizational risk exposure.
- Ensure compliance with applicable laws and regulations (e.g., SOX, GLBA, HIPAA, PCI, CFPB).
- Engage with cross‑functional teams to integrate risk considerations into business projects and technology implementations.
Required Skills:
- Strong knowledge of enterprise risk frameworks (e.g., NIST, ISO 27001, COBIT).
- Proficiency in identifying, assessing, and mitigating risks to IT assets, networks, and applications.
- Understanding of network controls, cloud security, identity and access management, and data protection.
- Ability to analyze and interpret quantitative and qualitative risk data.
- Excellent verbal and written communication, including presentation to senior management.
- Experience with GRC tools and automated risk assessment workflows.
- Familiarity with regulatory compliance requirements and cyber‑security standards.
Required Education & Certifications:
- Bachelor’s degree in Computer Science, Information Technology, Information Security, or related field.
- Certifying credentials such as CISSP, CISA, CRISC, or equivalent preferred.