Sr. Security Risk Analyst
On-siteHouston, Texas, United States
Job Summary
Conduct threat modeling, vulnerability scanning, and audits while leading security framework certification efforts. Design, develop, and implement IT security controls for cloud-based enterprise systems aligned with policy and compliance requirements. Execute risk and threat analyst activities to track, measure, validate, and report on risk identification, acceptances, and remediation efforts. Advise on acceptable mitigating controls and manage the security risk register to support organizational cyber security objectives. Serve as an internal security consultant to ensure IT investments align with Crane's security policies and standards. Manage tooling effectiveness, define metrics for the security automation program, and influence continuous improvement of the security program.
Required Qualifications
- Bachelor's Degree
- Minimum 7 years of experience working with security frameworks and implementing cyber security controls across a heterogenous environment
- Experience with public cloud architecture, cloud strategy, networking, security, and compliance workload types
- Knowledge of risk management frameworks and applying risk methodologies
- Understanding of conducting risk and/or self-assessment activities to identify key risk areas in the business
- Experience associated with 3rd party risk assessments
- Understanding security in-depth principles to measure risk
- Knowledge of security auditing procedures
- Knowledge of current data privacy laws (CCPA, GDPR)
- Excellent verbal and written communication skills
- Excellent time management abilities
- Strong customer orientation
- Excellent interpersonal and communication skills
- Ability to use vision, adjust focus and work on a standard computer screen
- Use of audio-visual equipment
- Job may require presence on-site at the assigned work location
- We maintain a drug-free workplace and perform pre-employment substance abuse testing
- This position requires the final candidate to successfully pass an E-Verify Check
Desired Qualifications
- Experience working on applications deployed within Azure
- Understanding of DevOps and CI/CD practices and tools
- Experience with security compliance monitoring tool including SIEM tools, vulnerability scanning tools, DLP (Data Loss Prevention) PAM (Privileged Access Management), and other infrastructure security tools
- Knowledge of GRC and risk assessment tools (Archer or OneTrust preferred)
- Industry certification preferred in one of the following areas: (e.g., CISSP, CISM, CRISC, or CISA)
- Familiarity with standards such as ISO 27001/27002 or the NIST Cybersecurity Framework is desirable
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.