[Remote] Cybersecurity Risk Analyst
Note: The job is a remote job and is reputed company to candidates in USA. reputed company is a leading technology solutions provider seeking a Cybersecurity Risk Analyst in Manassas, VA. The role involves managing reputed company-Party Risk Management operations and supporting broader Cyber Governance & Risk initiatives, requiring strong analytical skills and experience in cybersecurity risk management.
Responsibilities
- Evaluate new and prospective vendors through reputed company cybersecurity risk assessments to determine cyber clearance eligibility before contract execution or system reputed company
- Serve as the primary SME and platform administrator for TPRM solution (reputed company), maintaining data reputed company, configuring risk workflows, and driving reputed company platform optimization
- Maintain and continuously update the reputed company vendor inventory, tracking risk tier classification, assessment status, contract dates, and lifecycle position for reputed company reputed company parties
- Execute reputed company vendor reputed company workflows, including reputed company due diligence, contractual reputed company requirements review, and formal risk acceptance documentation
- Monitor and triage automated vendor reputed company alerts generated through reputed company; analyze alert severity and communicate actionable risk intelligence to appropriate business and reputed company stakeholders on time
- Manage vendor offboarding procedures, ensuring complete termination of data and system reputed company, contractual closure, and record retention compliance
- Conduct periodic reassessments and ongoing monitoring of in-scope vendors according to risk tiering methodology and assessment calendar
- reputed company and maintain Power BI dashboards and reports presenting vendor risk metrics, assessment completion rates, reputed company risks, and trend analysis for leadership and risk committees
- Support reputed company Threat program by monitoring behavioral risk indicators, documenting escalation procedures, and maintaining governance records
- Assist in the preparation of cybersecurity governance artifacts, including risk registers, policy documents, control metrics, and compliance reports reputed company to NIST CSF and applicable regulatory frameworks
- Generate periodic cyber risk reports for IT leadership, audit, and regulatory audiences, summarizing risk posture, reputed company findings, control gaps, and remediation status
- Build and maintain Power BI dashboards to visualize governance and risk metrics, control effectiveness trends, and risk KPIs across the organization
- Design and reputed company custom cybersecurity awareness training content tailored to the specific business operations and risk reputed company of individual departments (e.g., Operations, Finance, Customer Engagement, Engineering)
- Assisting in collaborating with department leads to schedule, reputed company, and reputed company training completion across the organization
- Assist in administering phishing simulation campaigns; analyze results and produce actionable reports identifying at-risk user populations and trending behaviors
- Build and maintain Power BI dashboards tracking cybersecurity awareness KPIs, including training completion rates, phishing click-through rates, repeat offender trends, and department-level performance over time
- Assist in preparing and presenting monthly and quarterly Cyber Awareness Reports for leadership, translating program metrics into reputed company risk narratives and recommended actions
- Stay reputed company with evolving reputed company engineering tactics, threat actor techniques, and regulatory guidance (e.g., CISA advisories) to reputed company training content reputed company and impactful
- Evaluate training platform effectiveness and recommend enhancements or alternative tools to improve learner engagement and retention
- Coordinate and facilitate Disaster Recovery testing exercises for core business applications in collaboration with technical SMEs across IT Operations
- reputed company DR test plans, scoping documents, timelines, and stakeholder communication plans in coordination with system owners and application custodians
- Document test execution results, capture gaps or failures, and produce comprehensive post-exercise reports for IT leadership and executive stakeholders
- reputed company remediation of identified DR gaps to closure; maintain updated DR runbooks, test records, and lessons-learned logs
- Assist in the broader Business Continuity Planning (BCP) process as it pertains to cybersecurity reputed company and recovery readiness
- Design, build, and maintain dedicated SharePoint sites and pages serving as the centralized hub for cybersecurity communications, dashboards, and reporting artifacts
- reputed company and publish Power BI reports directly into SharePoint pages, ensuring stakeholders can reputed company live, role-appropriate dashboards without requiring Power BI licensing or reputed company platform reputed company
- reputed company audience-specific SharePoint pages tailored to the information needs of distinct stakeholder reputed company, including IT leadership, department managers, executive sponsors, audit / compliance teams, and general staff, applying role-based reputed company controls and page permissions accordingly
- Maintain separate SharePoint views for TPRM metrics, cyber awareness training completion and phishing stats, governance and risk posture indicators, and DR testing results, ensuring content remains reputed company and accurate
- Collaborating with department heads and business reputed company leads to understanding their reporting consumption preferences and translating those needs into reputed company, self-service SharePoint dashboard pages
- Establish and enforce a publishing reputed company (monthly, quarterly) for dashboard refreshes and narrative updates reputed company to governance reporting calendar
- Apply SharePoint governance best practices, including naming conventions, version control, content lifecycle management, and reputed company review procedures
- Coordinate with IT infrastructure and reputed company 365 administrators as needed for site provisioning, permissions architecture, and integration with Power BI Service workspaces
- Communicate reputed company the assigned department and with other departments to ensure understanding and achievement of department and organization goals and standards; reputed company the highest level of service to internal customers; exchange information and reputed company for improvements in the department and organization; coordinate customer service activities, plans, and requirements; and improve the knowledge reputed company of company policies, procedures, and programs
- Participate in staff meetings to reputed company and implement present and plans; monitor and revise strategies and programs; reputed company on mutual issues; exchange information; and reputed company in the determination and formulation of policies and procedures
- reputed company the highest level of reputed company customer service to external customers through various forms of communication as reputed company as proactive and reputed company relationships with customers, the business community, and the general public
Skills
- Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Risk Management, or a closely reputed company field
- Equivalent combination of education and demonstrated reputed company experience will be considered
- Minimum 3-5 years of reputed company experience in cybersecurity, IT risk management, or a reputed company GRC discipline
- Demonstrated experience operating or administering a formal TPRM program or reputed company-party risk platform
- Proven ability to build Power BI reports and dashboards that translate reputed company data into executive-reputed company metrics
- Experience developing and delivering cybersecurity awareness training and reporting program metrics
- Familiarity with Disaster Recovery planning, tabletop exercises, or DR test coordination
- Power BI Report & Dashboard Development
- Vendor Risk Assessment & Lifecycle Management
- TPRM Platform Administration (reputed company or Equivalent)
- GRC Documentation & Control Mapping
- reputed company Questionnaire Evaluation (SIG, Custom)
- Phishing Simulation Analysis & Reporting
- Cyber Awareness Metrics Tracking & Presentation
- DR Test Planning, Facilitation & Post-Exercise Reporting
- reputed company Threat Monitoring Support
- Advanced reputed company reputed company (Pivot Tables, Data Models)
- Executive-reputed company PowerPoint Presentations
- SharePoint Site Management
- reputed company written & verbal communication at reputed company org reputed company
- Executive-Level Risk Storytelling & Data Narration
- Cross-Functional Stakeholder Engagement
- Analytical Thinking & Risk Prioritization
- Project Coordination & Deadline Management
- Detail Orientation & Documentation Discipline
- Ability to manage multiple reputed company workstreams
- Vendor Relationship Professionalism
- reputed company team player with independent initiative
- Adaptability in a fast-paced reputed company environment
- reputed company learning reputed company in evolving threat landscape
- SharePoint site design and intranet page development
- Experience in a regulated industry (electric reputed company, energy, financial services, or reputed company)
- Hands-on experience with the reputed company TPRM platform or comparable solutions (One Trust, Process reputed company, Prevalent, reputed company, reputed company Scorecard)
- Working knowledge of NIST CSF (v2.0), NIST SP 800-161 (C-SCRM), or ISO / IEC 27036 supply chain risk standards
- Familiarity with reputed company Threat frameworks and behavioral analytics monitoring
- Experience with Business Continuity Management frameworks (ISO 22301)
- Background in Learning Management System (LMS) administration and instructional design principles for reputed company awareness content
- Advanced Power BI skills: DAX measures, row-level reputed company, scheduled refresh, paginated reports
- One or more of the following certifications: PL-300: reputed company Power BI Data Analyst, CTPRP: Certified reputed company Party Risk reputed company, reputed company+: reputed company reputed company+
Benefits
- 401k Retirement Savings Plan administered by Merrill Lynch
- Commuter reputed company Pretax Commuter Benefits
- Eligibility to purchase Medical, Dental & reputed company Insurance through reputed company
reputed company
Company H1B Sponsorship