Position: IT Security Risk Analyst
Location: Miami FL
Duration: 12Year Contract
Job Description:
A lot of these responsibilities can be taught but the hiring manager needs someone with strong experience in IT security risk assessments. The most important part is having experience with writing risk assessments reports and strong communication.
Summary:
Responsible for conducting Cyber Security risk assessments for thirdparty service providers. This person will be more focused on writing reports for high level executives. The hiring manager is looking for someone who has excellent written and verbal communication.
Must Haves:
- Experience conducting IT Security Risk Assessments
- Technical background to speak to vendors
- Strong verbal and written communication
Nice to Haves:
- Any GRC tool ServiceNow Archer etc
Principal Responsibilities:
- Perform cybersecurity risk assessments of Suppliers and ThirdParties (vendors) to identify & validate threats and remediate risks.
- Perform interviews with vendors and business units walkthrough vendor controls document assessments.
- Measure assessments against key controls and industry security standards i.e. PCIDSS HIPAA ISO27001:13 SSAE18SOC2 Type2 etc.
- Create professionally written assessments that include findings requirements and recommendations to mitigate risk and provide visibility into the adherence to policies and procedures
- Submit assessment findings requirements and recommendations to business partners.
- Develop trusted relationships with business partners Supply Chain Sourcing and other team members to gain consensus approvals on strategies recommendations findings and project plans.
Experience:
- Understanding of emerging technologies including but not limited to mobile and cloud technology (PaaS SaaS.)
- Analytical/critical thinking and problemsolving skills.
- Basic understanding of information technology network security encryption incident management.
- Ability to contribute to consistent improvement model of team workflow processes templates and tools.
- Knowledge of NIST Cybersecurity Framework and how NIST supports the management and reduction of cybersecurity risk.
- Ability to keep up with a complex high volume and fastpaced assessment environment.
- Understanding of vendor questionnaires and responses e.g. SIG CAIQ.
- Knowledge of technology industry best practices and standards e.g. NIST PCIDSS ISO CSA etc.
- Ability to simply articulate technical concepts in written and verbal form.
|