CompQsoft

Cyber Risk Management Analyst

CompQsoft  •  $120k - $128k/yr  •  United States (Hybrid)  •  1 day ago
Apply
AI can make mistakes so check important info. Chat history is never stored.

Job Description

Title: Cyber Risk Management Analyst

Location: Brooklyn NY ( Hybrid)

Experience: 3+ years

Certifications: CISA, CRISC, CGEIT, CISSP, Security+, CCSK, or CGRC.

Requirements

Drive enterprise cybersecurity risk management by transforming compliance into a strategic advantage. Quantify risks, assess control effectiveness, and ensure alignment with NIST 800-53 and FISMA frameworks. Collaborate with Cybersecurity Engineers and Business Analysts to define compliance guardrails, prioritize remediation, and track key cyber risks. Conduct enterprise-wide risk assessments, audits, and user awareness programs to reduce risk and continuously improve the organization’s security posture.

Key Requirements

  • Expertise in GRC methodologies, third-party risk management (TPRM), and federal compliance (NIST SP 800-53, 800-37). Skilled in Risk Register tracking and maintenance, performing Security Impact Analyses, managing the POA&M lifecycle, and developing security awareness content to mitigate human-centric risks.
  • Risk Identification & Quantification: Lead enterprise-wide risk assessments using GRC methodologies to identify, evaluate, and prioritize risks, translating technical vulnerabilities into business impact for stakeholders.

17

  • Regulatory & Framework Alignment: Ensure ongoing compliance with federal frameworks, including NIST SP 800-53 and 800-37 (RMF), through periodic audits and Security Impact Analyses for new and existing system interconnections.
  • Strategic POA&M & Risk Register Oversight: Maintain and manage the enterprise Risk Register, tracking key cyber risks and overseeing the full lifecycle of Plans of Action and Milestones (POA&M), ensuring findings are documented, validated, and remediated within defined SLAs.
  • Key Cyber Risk Tracking: Continuously monitor and report critical cyber risks, using risk dashboards and metrics to provide actionable insights to leadership and maintain enterprise risk posture.
  • Human-Centric Risk & Awareness: Design and implement security awareness programs and phishing simulations (e.g., KnowBe4, Proofpoint) to reduce social engineering risks and strengthen organizational security culture.
  • Technical Remediation Partnership: Collaborate with Cybersecurity Engineers and Business Analysts to define compliance guardrails and prioritize remediation activities based on risk impact.
  • Advanced Risk Analytics & Visualization: Leverage GRC platforms (Archer, ServiceNow) and tools like Power BI and Excel to generate automated risk metrics, heat maps, and executive-level security posture reports.

Technologies: GRC Platforms (Archer/ServiceNow), TPRM Tools (OneTrust/Prevalent), Awareness Platforms (KnowBe4/Proofpoint), MS Power BI, Excel (Advanced), and JIRA.

CompQsoft provides equal opportunity in all aspects of employment and in the working environment to all employees and applicants. CompQsoft does not take any non-merit factors like race, color, religion, sex (gender), mental/physical disability, and age into account for purposes of recruitment, hiring and development.

Salary Description

$120000- $128000

CompQsoft

About CompQsoft

CompQsoft is a customer-centric digital platform and IT services company. We empower organizations across industries and technology verticals to leverage Software Development & Engineering, Unified Communication, Cloud, Data & Analytics, Application Modernization, Cybersecurity, Network Management, RPA and Automation, and next-gen technologies like generative AI to drive innovation and transform their businesses.

For 25 years, we have been dedicated to helping clients maximize their technology investments and achieve superior business outcomes.

Our expertise spans:

• Public Sector (Government) - Federal agencies, including the Department of Defense and state and local governments.

• Private (Commercial IT) - Startups, Small & Medium (SMBs) and Enterprises.

We help businesses integrate design, software engineering, and agile delivery capabilities to produce business outcomes and drive innovation.

Headquartered in Houston, Texas, CompQsoft operates engineering centers worldwide, extending the benefits of our true global presence to customers across industries.

We are ISO 9001:2008, 27001:2005, 20000:2005 & CMMI Level 3 certified company.

For more details, please visit: https://compqsoft.com/

Industry
IT & Software
Company Size
201-500 employees
Headquarters
Leesburg, Virginia
Year Founded
1997
Social Media