The Senior Cybersecurity Risk Analyst is a US remote, senior individual contributor position within the Cybersecurity Governance, Risk, and Compliance (GR&C) team. This role owns the enterprise's cyber risk assessment work: evaluating activities and operational decisions across the enterprise and articulating the resulting cyber risk to business leadership against the enterprise's risk appetite. The work is assessment heavy. The Senior Cybersecurity Risk Analyst examines technology and operational decisions for cyber risk that compliance-driven review alone does not surface, then frames that risk in business terms so GR&C and leaders can make informed accept, mitigate, or remediate decisions. The role is a twin to the Compliance function: where Compliance concentrates on the administrative work of demonstrating conformance to mandatory controls, this role works alongside it to drive cohesive cyber risk management across the enterprise regardless of which framework imposes a given requirement. Consistent with the GR&C charter, the role helps protect Amentum against internal and external cyber threats and helps set, improve, and make recommendations on the enterprise security program based on industry best practices, regulations, policies, standards, and guidelines. GR&C surfaces and advises on risk so that business and operational owners can make informed decisions. This person must be technical enough to recognize risk in networking, cloud, endpoint, and identity decisions made by engineering and IT, and credible enough that their risk judgments carry weight with those teams and with leadership. The role acts on behalf of the entire enterprise rather than any single team, contract, or project, and brings attention to risk without hindering the business. This position is US remote telework and requires US Citizenship.
Stand Out From the Crowd
Upload your resume and get instant feedback on how well it matches this job.
Job Type
Full-time
Career Level
Senior