About The Position

We are on the hunt for a talented Technology & Cybersecurity Risk Management (T&CRM) Engineer who supports the T&CRM program by analyzing technology and cybersecurity risks, conducting risk assessments, leading risk-related initiatives, and enhancing risk management processes. This role helps identify, visualize, and reduce technology and cybersecurity risks while guiding stakeholders through risk-based decision-making.

Requirements

  • Technology and Cybersecurity Fundamentals: Demonstrates a solid understanding of security controls, threats, and risk concepts.
  • NIST, COBIT, and ISO 27001 framework knowledge.
  • Risk Assessment & Analysis: Ability to identify, assess, and document technology and cybersecurity risks and control gaps.
  • Understanding of control design, control effectiveness, and risk mitigation concepts.
  • Project Management: Effectively plans, tracks, and executes work across multiple concurrent initiatives.
  • Process Improvement: Identifies opportunities to streamline workflows and improve operational efficiency.
  • Stakeholder Collaboration: Works effectively with cross‑functional teams and external partners.
  • Communication: Clearly communicates technical risk information to both technical and non‑technical audiences.
  • Attention to Detail: Produces accurate, well‑documented assessments and maintains reliable risk records.
  • Tool proficiency: Microsoft Word, Excel, PowerPoint, and Copilot. ServiceNow.
  • Bachelor's degree in Information Technology, Cybersecurity, Computer Science, Business, or a related field (or equivalent experience).
  • 1–3 years of experience in cybersecurity or technology risk management, IT risk, cybersecurity, compliance, or related discipline.
  • Foundational understanding of cybersecurity principles, risk assessment methodologies, and common security control frameworks.
  • Experience supporting projects or initiatives that require coordination across multiple stakeholders.
  • Strong written and verbal communication skills, with the ability to clearly document risks and recommendations.

Nice To Haves

  • Comfortable navigating conversations with Control Owners and stakeholders.
  • Clear and structured articulation of technology risks and controls.
  • Strong attention to detail and documentation quality.
  • Willingness to learn and grow within a Technology & Cybersecurity Risk Management function.
  • Collaborative mindset across technical and non-technical teams.

Responsibilities

  • Conduct risk intake, assessments, triage sessions, and stakeholder risk discussions.
  • Assess technology and cybersecurity risks using NIST, COBIT, and ISO frameworks.
  • Identify, document, and evaluate inherent, residual, and emerging technology risks.
  • Review controls and evaluate their effectiveness in mitigating identified risks.
  • Map risks to controls and applicable framework and policy requirements.
  • Facilitate control walkthroughs and risk discussions with control owners and stakeholders.
  • Document risk statements, controls, evidence, and assessment results in governance tools and Word/Excel/PPT.
  • Develop risk treatment recommendations and track remediation activities through closure.
  • Escalate overdue actions, unresolved risks, and significant control or compliance concerns.
  • Prepare executive-ready risk reports, dashboards, and governance presentation materials.
  • Participate in OP monthly team meetings and participate in team-building efforts.
  • Contribute to OP technical discussions, peer reviews, etc.
  • Contribute content and collaborate via the OP-Wiki/Knowledge Base.
  • Provide status reports to OP Account Management as requested.

Benefits

  • 401(k)
  • Dental Insurance
  • Health insurance
  • Vision insurance
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service