- Company Name
- Semperis
- Job Title
- Cyber Risk Analyst
- Job Description
-
**Job title**
Cyber Risk Analyst
**Role summary**
Analyses and controls cyber risk exposure of technology assets, applications, infrastructure, and third‑party vendors. Supports governance, risk, and compliance (GRC) initiatives through assessment, documentation, monitoring, and remediation, ensuring alignment with policy and industry standards.
**Expectations**
- Conduct comprehensive risk assessments for internal systems and external vendors.
- Translate technical findings into business‑ready risk statements and recommendations.
- Maintain auditable documentation and drive resolution of risk exceptions.
- Leverage GRC tools to automate workflows, track risk mitigation, and report status to stakeholders.
- Collaborate across security, product, legal, and business units to ensure timely remediation and compliance.
**Key responsibilities**
- Perform risk identification, assessment, and residual risk rating (High/Medium/Low).
- Validate and document risk exception requests, including review dates and resolution plans.
- Collect, model, and analyze data to forecast risk scenarios and business impact.
- Monitor risk plan milestones, lead issue management, and verify control effectiveness.
- Develop and recommend mitigation strategies (policy, controls, process changes).
- Execute third‑party due diligence: review SOC 2, ISO 27001, security questionnaires, and other attestations.
- Produce risk reports, summaries, and presentations for management and stakeholders.
- Utilize and enhance the corporate GRC platform; automate manual GRC tasks.
- Respond to customer, partner, and regulator inquiries on security posture; support evidence collection for audits.
**Required skills**
- Strong knowledge of GRC concepts and modern risk‑management tools.
- Experience in technology risk assessment, third‑party vendor risk, and compliance frameworks (NIST, ISO 27001, etc.).
- Analytical capability to model risk scenarios and translate findings into business risk terms.
- Documentation, reporting, and stakeholder communication skills.
- Ability to automate workflows and improve process efficiency.
**Required education & certifications**
- Bachelor’s degree in Computer Science, Information Security, Risk Management, or related field.
- Professional certifications preferred: CISSP, CRISC, CGEIT, or equivalent.
---