üõ°Ô∏è We‚Äôre Hiring: Technology Risk Analyst | Cyber Risk Consultant
üïí Employment Type: Full-Time
üíº Level: Mid-Level to Senior
We are seeking a detail-oriented and analytical Technology Risk Analyst | Cyber Risk Consultant to identify, assess, monitor, and manage technology and cybersecurity risks across the organization. This role will work closely with IT, Cybersecurity, Compliance, Internal Audit, and business teams to strengthen technology-risk management, improve security controls, and support a resilient and secure operating environment.
üéØ Key Responsibilities‚Ä¢ Identify and assess technology, cybersecurity, information-security, and operational risks across the organization.
• Conduct technology risk assessments covering infrastructure, applications, cloud environments, networks, and business systems.
• Evaluate cybersecurity threats, vulnerabilities, control weaknesses, and potential business impacts.
• Develop and maintain technology and cyber risk registers, risk assessments, and risk treatment plans.
• Monitor key risk indicators (KRIs), key performance indicators (KPIs), and emerging technology-risk trends.
• Assess the effectiveness of existing IT security controls, policies, procedures, and risk-management frameworks.
• Identify control gaps and recommend appropriate remediation and mitigation actions.
• Work with technology teams to track and resolve identified risks, findings, and control deficiencies.
• Support enterprise risk assessments and integrate technology risks into broader organizational risk-management processes.
• Conduct cybersecurity risk assessments for third-party vendors, service providers, and technology partners.
• Evaluate risks associated with cloud computing, SaaS platforms, APIs, data systems, and emerging technologies.
• Support risk assessments related to system implementations, technology changes, and digital transformation projects.
• Analyze cybersecurity incidents and contribute to post-incident risk assessments and remediation activities.
• Monitor emerging cyber threats, vulnerabilities, regulatory developments, and technology-risk trends.
• Develop risk scenarios and assess their potential financial, operational, regulatory, and reputational impacts.
• Support business continuity, disaster recovery, and technology resilience assessments.
• Review access controls, identity management, data protection, vulnerability management, and security monitoring practices.
• Assist with internal and external audits by preparing risk documentation, evidence, and management responses.
• Support compliance assessments against applicable technology and cybersecurity standards and requirements.
• Prepare risk reports, dashboards, assessment summaries, and management presentations.
• Communicate technology and cybersecurity risks clearly to both technical and non-technical stakeholders.
• Facilitate risk workshops, control assessments, stakeholder interviews, and remediation discussions.
• Provide practical recommendations to strengthen technology governance, security controls, and risk-management practices.
• Track remediation plans and escalate overdue or high-priority risk issues where appropriate.
• Maintain accurate documentation of risk assessments, controls, findings, action plans, and risk acceptance decisions.
• Support the development and continuous improvement of technology-risk policies, standards, procedures, and methodologies.
• Evaluate the risk implications of new technologies, applications, platforms, and technology initiatives.
• Conduct periodic reviews of risk profiles to identify changes in threat exposure and control effectiveness.
• Support senior management with data-driven insights for technology-risk and cybersecurity decision-making.
✅ Requirements• Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, Information Security, Risk Management, or a related field.
• Previous experience in Technology Risk, Cyber Risk, IT Risk, Information Security, Technology Consulting, or a similar role.
• Strong understanding of cybersecurity principles, technology risk, and information-security controls.
• Experience conducting IT and cybersecurity risk assessments.
• Knowledge of risk-management frameworks and control-assessment methodologies.
• Familiarity with frameworks and standards such as ISO 27001, NIST CSF, COBIT, CIS Controls, or similar frameworks.
• Understanding of common cybersecurity threats, vulnerabilities, attack vectors, and risk scenarios.
• Knowledge of network security, cloud security, identity and access management, endpoint security, and data protection.
• Experience evaluating IT general controls (ITGCs), application controls, and security controls.
• Familiarity with third-party risk management and vendor security assessments.
• Strong analytical, investigative, and problem-solving skills.
• Ability to assess complex technical information and translate it into business risk implications.
• Strong understanding of risk identification, risk scoring, mitigation, acceptance, and monitoring processes.
• Excellent report-writing, documentation, and presentation skills.
• Strong stakeholder-management and communication abilities.
• Ability to communicate effectively with cybersecurity professionals, IT teams, auditors, compliance teams, and business stakeholders.
• Experience supporting technology audits, regulatory assessments, or compliance reviews is preferred.
• Familiarity with GRC platforms, vulnerability-management tools, SIEM solutions, or security assessment tools is advantageous.
• Relevant certifications such as CISA, CRISC, CISSP, CISM, ISO 27001, or equivalent qualifications are advantageous.
• Strong attention to detail and ability to manage multiple risk assessments and remediation activities.
• Ability to work independently while collaborating effectively across technical and business functions.
üåü What We Offer‚Ä¢ Competitive salary and comprehensive employee benefits.
• Opportunity to work across technology risk, cybersecurity, governance, and compliance functions.
• Exposure to enterprise-level technology and cybersecurity environments.
• Professional development in cyber risk, IT governance, information security, and risk management.
• Access to modern cybersecurity, GRC, risk-management, and analytics technologies.
• Opportunities to participate in major technology transformation and security initiatives.
• Exposure to senior management and strategic technology-risk decision-making.
• Support for relevant cybersecurity, risk, audit, and compliance certifications.
• Collaborative environment focused on security, resilience, governance, and continuous improvement.
• Recognition for identifying risks and delivering effective risk-mitigation solutions.
- • Career progression toward Senior Technology Risk Analyst, Cyber Risk Manager, Technology Risk Manager, Cybersecurity Risk Consultant, or Head of Technology Risk.