openqareer

Cyber Risk Analyst

Forman Technology Group · Round Rock, TX 78664

# Cyber Risk Analyst **Forman Technology Group** · Round Rock, TX 78664 · `On-site` 🕒 **Статус:** *Опубликовано: 4 дня назад* · *Источник: Indeed* --- ### About the Role About the Job We are looking for a Cyber Risk Analyst to support and strengthen our organization's cybersecurity risk management and governance initiatives. This role will focus on identifying, evaluating, documenting, and monitoring cybersecurity and technology risks while helping improve the effectiveness of security controls, risk assessment procedures, and compliance practices across the organization. The individual will work within a collaborative environment involving information security, IT operations, risk management, compliance, internal audit, business operations, and technology teams. The role will involve reviewing security controls, analyzing risk assessment results, supporting audit and regulatory requirements, and coordinating with system owners and other stakeholders to address identified gaps and reduce potential risk exposure. The Cyber Risk Analyst will also contribute to developing risk reports, tracking remediation activities, maintaining governance documentation, and improving risk monitoring processes. This position offers an opportunity to work across technical and business functions, translating complex cybersecurity findings into practical insights that support informed decision-making and continuous improvement. Responsibilities - Conduct cybersecurity and technology risk assessments to identify potential threats, control weaknesses, vulnerabilities, and areas of risk exposure across business applications, infrastructure, systems, and operational processes. - Evaluate the design and effectiveness of security controls against established policies, industry standards, and risk management frameworks, identifying gaps and opportunities for improvement. - Analyze cybersecurity findings, control deficiencies, risk assessment results, and security-related data to determine potential business impact, prioritize risks, and support risk-based decision-making. - Develop and maintain risk assessment documentation, control evaluation records, risk registers, issue logs, and supporting evidence to ensure accuracy, consistency, and audit readiness. - Coordinate with IT, cybersecurity, business process owners, and other stakeholders to track remediation plans, validate corrective actions, monitor outstanding issues, and support timely risk resolution. - Review cybersecurity policies, standards, procedures, and technology risk exceptions, evaluating potential exposure, compensating controls, and mitigation measures. - Support internal and external audits, compliance reviews, and regulatory assessments by gathering evidence, coordinating responses, documenting control activities, and tracking findings through closure. - Assist in assessing third-party and vendor cybersecurity risks by reviewing security questionnaires, SOC 1 and SOC 2 reports, information security policies, business continuity documentation, and other relevant security evidence. - Prepare risk dashboards, metrics, management reports, and presentations to communicate risk trends, control performance, remediation progress, and emerging concerns to relevant stakeholders. - Support the development and continuous improvement of cybersecurity governance procedures, control testing approaches, risk assessment methodologies, and issue management workflows. - Monitor changes in cybersecurity threats, technology environments, industry practices, and applicable compliance requirements to help identify emerging risks and recommend appropriate responses. - Participate in cross-functional risk management initiatives, process improvement activities, and security governance meetings as needed. Qualifications - Bachelor's or Master's degree in Cybersecurity, Information Technology, Computer Science, Information Systems, Risk Management, or a related field, or an equivalent combination of education and relevant experience. - 2+ years of experience in cybersecurity, information security, IT risk management, governance, risk and compliance (GRC), internal audit, technology controls, or a related discipline. - Working knowledge of cybersecurity risk management principles, information security controls, risk assessment methodologies, and governance practices. - Familiarity with established cybersecurity and risk management frameworks such as NIST Cybersecurity Framework (CSF), NIST SP 800-53, ISO 27001, COBIT, CIS Controls, or similar standards. - Understanding of core information security concepts, including identity and access management, network security, vulnerability management, incident response, data protection, business continuity, and security monitoring. - Experience reviewing technical documentation, evaluating control evidence, identifying process gaps, and documenting risk findings or remediation activities. - Proficiency in Microsoft Excel, Word, and PowerPoint, with the ability to organize data, maintain documentation, and prepare clear reports. - Strong analytical and problem-solving skills, with the ability to interpret complex information, recognize patterns, assess potential business impacts, and support practical risk mitigation decisions. - Excellent written and verbal communication skills, including the ability to explain cybersecurity risks and control findings to both technical and non-technical stakeholders. - Strong organizational skills and the ability to manage multiple assignments, coordinate with different teams, and meet deadlines while maintaining attention to detail. - Ability to handle confidential information responsibly, exercise sound judgment, and work both independently and collaboratively. Preferred Qualifications - Experience working with governance, risk, and compliance platforms, audit management systems, or issue-tracking tools such as ServiceNow, Archer, or similar applications. - Familiarity with third-party risk management, vendor due diligence, security questionnaires, and independent assurance reports such as SOC 1 and SOC 2. - Experience developing dashboards, risk metrics, or analytical reports using Power BI, SQL, or similar reporting and data analysis tools. - Exposure to control testing, cybersecurity maturity assessments, policy exception reviews, and risk remediation tracking. - Familiarity with cloud security concepts, enterprise IT infrastructure, application security, and emerging cybersecurity risks. - Relevant industry certifications such as CompTIA Security+, CISA, CRISC, CISSP, CISM, CGRC, or equivalent credentials are a plus. Work Environment This position involves regular collaboration with cybersecurity professionals, technology teams, business stakeholders, risk management personnel, and audit and compliance partners. The individual should be comfortable balancing analytical work, documentation, stakeholder communication, and multiple ongoing risk management activities in a professional and evolving technology environment. Pay: $80,900.00 - $97,600.00 per year Work Location: Hybrid remote in Round Rock, TX 78664

Наблюдалась 2026-10-07, впервые 2026-10-02, источник — Indeed.

Открыть у работодателя