Nscale logo
NscalePosted 1 month ago

Cyber Risk Lead

$150,000–$180,000 year

On-siteHouston, Texas, United States

Part TimeSenior LevelSmall

Job Summary

Build and operate Nscale's continuously measured cyber risk program, transforming technical telemetry into actionable insights and scalable treatment plans. Develop a dynamic risk model reflecting asset exposure across technology, data centers, and software supply chains, then quantify risks using methodologies like FAIR or NIST SP 800-30 to prioritize by likelihood and loss magnitude. Own the risk treatment lifecycle, establishing measurable objectives and validating remediation activities produce demonstrable risk reductions through technical evidence rather than administrative closure. Integrate risk into compliance-as-code platforms and apply risk-as-code to improve measurement fidelity via automation and analytics. Report material enterprise risk scenarios to leadership with defensible logic while helping shape the broader GRC program architecture.

Required Qualifications

  • 8+ years of experience in enterprise security risk management
  • Experience building or running a risk register and treatment program
  • Risk quantification and treatment expertise grounded in a recognized method such as the NIST Cybersecurity Framework, ISO 27005, or FAIR
  • A track record of driving remediation across engineering teams
  • Comfort working directly with risk data using SQL, scripting, or equivalent tooling
  • Experience building risk tooling or automation
  • Experience with integrations between scanners, asset inventories, GRC platforms, and engineering issue trackers
  • Ability to use automation and AI-assisted workflows to reduce manual GRC work
  • Strong understanding of cloud infrastructure and security controls
  • Ability to read infrastructure-as-code such as Terraform
  • Experience with automation-first risk management, continuous control monitoring, or actuarial approaches to risk modeling
  • Experience with AI infrastructure, hyperscale, regulated environments, critical infrastructure, data center operations, or sovereign cloud requirements

Desired Qualifications

  • Relevant certifications such as CISSP or CRISC
  • A strong statistics or mathematics background

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

Apply to this job in one click with Sorce

Apply on Sorce