CornerStone Technology Talent Services is seeking an experienced Senior Cybersecurity Risk Analyst to join their Governance, Risk & Compliance team. The role involves evaluating cybersecurity risks across various environments and collaborating with technical teams and executive leadership to strengthen security programs.
Responsibilities:
- Perform cybersecurity risk assessments for enterprise applications, infrastructure, and business initiatives
- Evaluate risks related to cloud environments, networks, endpoint security, and Identity & Access Management (IAM)
- Assess third-party vendors, software solutions, and emerging technologies, including AI-related initiatives
- Identify security risks and recommend practical mitigation strategies
- Support Governance, Risk & Compliance (GRC) initiatives and enterprise risk management activities
- Partner with IT, engineering, compliance, and business leaders to strengthen security programs
- Present cybersecurity findings and recommendations to both technical and non-technical stakeholders
- Improve cybersecurity risk assessment processes, reporting, and governance practices
- Stay current with evolving cybersecurity threats, industry standards, and regulatory requirements
Requirements:
- U.S. Citizenship (required)
- Authorized to work in the United States without current or future visa sponsorship
- 8+ years of enterprise cybersecurity experience
- Experience performing cybersecurity risk assessments
- Strong knowledge of: Cloud Security, Network Security, Endpoint Security, Identity & Access Management (IAM)
- Experience evaluating third-party/vendor cybersecurity risk
- Working knowledge of NIST cybersecurity frameworks and standards
- Current CompTIA Security+ certification (or equivalent)
- Excellent communication skills with the ability to explain technical risks to business leaders
- Ability to work independently in a collaborative environment
- Willingness to travel up to 25%
- CISSP, CySA+, or other advanced cybersecurity certifications
- Microsoft Azure
- Microsoft 365
- Microsoft Entra ID
- Azure Government (GCC High)
- Conditional Access
- Privileged Access Management (PAM)
- Governance, Risk & Compliance (GRC) program improvement
- Cybersecurity compliance frameworks such as: CMMC, NIST SP 800-171 / 800-172, DFARS, ISO 27001, UK Cyber Essentials, Essential Eight, UK GDPR, EU NIS2
- Experience supporting regulated, government, or defense-related environments
- Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or a related field (or equivalent experience)