This role requires 6-9 years of experience in information security, IT risk management, security engineering, or a related discipline, preferably within a regulated industry. The ideal candidate will have a Bachelor's degree in Information Security, Computer Science, or a related field, with a Master's degree or relevant certifications (e.g., CISSP, CISM, CRISC, CISA) being strongly preferred. The position involves a strong understanding of cybersecurity risk management, governance, and control frameworks such as NIST CSF, ISO 27001, COBIT, FFIEC, and PCI DSS. Responsibilities include performing security assessments, threat modeling, architectural reviews, and risk analysis. Experience with Microsoft Purview and Microsoft Defender is preferred. Proficiency in cloud security, endpoint protection, and data loss prevention (DLP) technologies is essential. Familiarity with SIEM tools, vulnerability management platforms, and incident response processes is required. Experience with governance, risk, and compliance (GRC) platforms such as Archer, ServiceNow IRM, RiskConnect, or similar is also expected. Additionally, familiarity with artificial intelligence tools and their cybersecurity implications, including data protection, threat detection, automation, and third-party risk considerations, is important. The role demands strong analytical, communication, and stakeholder engagement skills, with the ability to influence technical teams, business stakeholders, and leadership through clear, risk-based recommendations. The candidate should be naturally curious and hands-on, with the ability to solve complex problems, learn new technologies, and address evolving security challenges.
Stand Out From the Crowd
Upload your resume and get instant feedback on how well it matches this job.
Job Type
Full-time
Career Level
Senior