Identify and translate inherent and residual risk through likelihood, impact, treatment plans, and ownership.
Define and track risk and awareness key metrics to measure program effectiveness and communicate to leadership and governance committees.
Conduct and manage enterprise information security risk assessment through recognized frameworks (including NIST 800-30) and maintain an information security risk register.
Lead third-party security risk assessments for vendors, partners, and service providers through analysis of assurance documentation, security testing summaries, and security questionnaires.
Maintain the information security risk register and third-party vendor risk inventory to track and monitor ongoing risks and approved exceptions.
Develop and lead enterprise security awareness training, including phishing simulations and targeted role-based training for security education and reporting.
Support internal and external security and compliance assessments through risk evidence and documentation.
Partner closely with organizational functions and key stakeholders to understand and address organizational risks across systems and processes, and ensure security risks are understood, prioritized, and treated in alignment with organizational risk appetite.
Requirements
4 – 6 Years of experience in information security, cybersecurity, risk management, or related field
Working experience managing enterprise/third-party risk assessments, risk registers, and security training programs.
Working experience supporting compliance audits and certifications, including NIST 800-53 (FedRAMP/GovRAMP), ISO 27001, PCI, and/or SOC 2
Certifications Security+, GSEC, or equivalent
Bachelor’s degree in Cybersecurity, Information Security, Information Systems, Risk Management, or a related field (preferred)