Cyber Risk Management Analyst
Phia
Job highlights
Summary
Join phia, a Northern Virginia-based company, as a Cyber Risk Management Analyst working remotely within the United States. You will drive the development and implementation of third-party cyber risk management strategies, champion best practices, and conduct supply chain risk assessments. This role requires collaboration with cross-functional teams and utilizing various risk assessment platforms. U.S. citizenship and the ability to obtain Public Trust clearance are mandatory. The ideal candidate possesses strong communication, organizational, and technical writing skills, along with experience in managing diverse teams. phia offers a comprehensive benefits package including medical, dental, vision, disability, 401k, tuition assistance, and flexible spending accounts.
Requirements
- 3+ years of experience in the security aspects of multiple platforms, operating systems, software, communications, and network protocols
- Familiarity with third-party risk assessment platforms (e.g., Process Unity GRX) and risk management platforms (e.g., Diligent RSAM)
- Familiarity with cyber risk assessment and management frameworks, methodologies, and reporting. (e.g., SOC 2 Type II) and questionnaire responses
- Strong understanding and practical experience in adapting and implementing industry-standard cybersecurity frameworks and standards (e.g., ISO 27001, NIST CSF, NIST 800-53, NIST 800-171, CIS 18, Zero Trust Principles, FedRAMP)
- Excellent communication skills to effectively engage with cross-functional leadership and stakeholders, particularly in supply chain management regarding third-party risk management strategies and activities
- Experience in managing and instructing diverse teams with varying levels of subject matter expertise
- Strong organizational skills to manage competing priorities and ensure timely completion of projects
- Technical Writing Skills: Proficient in producing high-quality technical documentation and reports
- U.S. Citizenship required
- Ability to obtain Public Trust (or higher) government clearance
Responsibilities
- Drive the design, development, implementation, and continuous improvement of third-party cyber risk management strategies and practices across public and private sectors
- Champion and oversee Third Party Cyber Risk Management (TPCRM) best practices and policies
- Implement and adapt industry-standard cybersecurity frameworks (e.g., ISO 27001, NIST CSF, NIST 800-53, NIST 800-171, CIS 18, Zero Trust Principles, FedRAMP)
- Conduct supply chain risk assessments using recognized audit reports (e.g., SOC 2 Type II) and questionnaire responses
- Collaborate with cross-functional leadership and stakeholders, particularly in supply chain management, to communicate third-party risk management strategies, activities, and identified risks
- Utilize third-party risk assessment platforms (e.g., Process Unity GRX) and risk management platforms (e.g., Diligent RSAM)
- Review and make recommendations for policy and process updates, insuring alignment with organizational risk requirements
- Lead and mentor diverse teams with varying levels of subject matter expertise
- Prioritize and manage multiple concurrent projects to ensure timely completion
- Produce high-quality technical documentation and reports
- Engage in continuous learning to expand personal knowledge and upskill team members
Preferred Qualifications
- Bachelorβs degree in Computer Science, Information Technology or Information Security or other relevant disciplines
- Public and Private Sector Experience
- Familiarity with CyberGRX (now Process Unity GRX) and Diligent RSAM
- Proximity to customer locations in the DMV (DC, MD, or VA) Metro area or Raleigh/Durham, NC is ideal
- CRISC - Certified in Risk and Information Systems Control
- CISSP- Certified Information Systems Security Professional
- CCSK- Certificate of Cloud Security Knowledge or CCSP
- CISA-Certified Information Systems Auditor certifications
- CISM- Certified Information Security Manager
Benefits
- Comprehensive medical insurance to include dental and vision
- Short Term & Long-Term Disability
- 401k Retirement Savings Plan with Company Match
- Tuition and Professional Development Assistance
- Flex Spending Accounts (FSA)
Share this job:
Similar Remote Jobs
- π°$75k-$125kπUnited States
- π°$80k-$110kπUnited States
- πWorldwide
- π°$120k-$155kπUnited States
- π°$86k-$148kπUnited States
- πUnited Kingdom
- π°$57k-$93kπCanada
- π°$80k-$130kπUnited States
- πIndia