- Location
- Hyderabad, TS,IN, IN
- Workplace
- Onsite
- Type
- Full-time
- Seniority
- Senior
- Source
- Eightfold
Description
Req. ID:
JR112543 Staff IT Risk Analyst
Our vision is to transform how the world uses information to enrich life for all.
Micron Technology is a world leader in innovating memory and storage solutions that accelerate the transformation of information into intelligence, inspiring the world to learn, communicate and advance faster than ever.
The Third‑Party Cybersecurity Risk Management (TPCRM) Staff Analyst is a senior individual contributor responsible for shaping, governing, and continuously improving information risk management related to external suppliers. The analyst leads complex and ambiguous third‑party cybersecurity risk issues, advises senior business and security stakeholders, drives program maturity, and supports enterprise‑level decision‑making across Information Security, Privacy, Regulatory Compliance, Procurement, Legal, and Governance.
Responsibilities
- Serve as a staff-level subject matter expert for third‑party cybersecurity risk management, including enterprise supplier risk governance, regulatory alignment, and assessment quality.
- Lead highly complex third‑party risk assessments involving critical suppliers, high‑risk services, sensitive data, manufacturing dependencies, or material business impact.
- Shape assessment methodology, risk criteria, evidence expectations, and control evaluation practices to improve consistency, scalability, and defensibility of TPCRM outcomes.
- Perform advanced gap analysis against frameworks and standards such as ISO 27001, NIST, SOX, TISAX, and GDPR, and advise stakeholders on enterprise‑level remediation priorities.
- Lead risk treatment strategy for material supplier findings, including mitigation planning, risk acceptance recommendations, supplier escalations, evidence validation, and closure decisions.
- Develop, revise, and mature third‑party risk management policies, standards, processes, guidelines, and runbooks through formal governance and change management.
- Lead third‑party governance activities, including onsite supplier audits, executive risk reporting, cross‑functional working groups, and escalation of material supplier risks.
- Translate cybersecurity, regulatory, supplier, and threat intelligence insights into actionable risk themes, program enhancements, and supplier risk mitigation strategies.
- Interpret risk tolerance, contractual obligations, control tradeoffs, supplier criticality, and business impact to support informed risk acceptance, mitigation, avoidance, or transfer decisions.
- Partner with procurement, legal, information security, business, privacy, resilience, and vendor management teams to embed TPCRM expectations throughout the supplier lifecycle.
- Advise business‑led initiatives on third‑party cyber risk, due diligence requirements, standards compliance, supplier engagement, and governance escalation paths.
- Mentor senior and junior analysts, lead process improvement initiatives, advance automation and reporting maturity, and help establish consistent TPCRM execution across teams and regions.
Education
- Bachelor’s Degree in Computer Science/Management Information Systems/Business Administration. Master’s degree is preferred.
- Related field of study or equivalent combination of education and experience.
Experience:
Analyzing and applying Information Security, Cyber Risk Management, Third‑Party Risk Management, and Privacy practices for a minimum of seven years of experience, with demonstrated ability to lead complex supplier risk issues, influence cross‑functional stakeholders, and improve risk management practices in the following areas:
- Advanced third‑party / vendor risk management, supplier assessments, external assurance programs, cybersecurity governance, or enterprise risk functions.
- Strong IT business process knowledge, supplier lifecycle understanding, business acumen, and ability to connect supplier risk to operational and enterprise impact.
- Experience influencing procurement, legal, vendor management, privacy, information security, business, and executive stakeholders on risk decisions and remediation priorities.
- Experience working with and improving third-party risk management tools such as ServiceNow, Optro, Archer, AuditBoard, SecurityScorecard, BitSight, or equivalent platforms.
- Experience developing risk analytics, dashboards, scorecards, executive reporting, metrics, and narratives that communicate third-party risk posture and program maturity.
- Advanced understanding of threat, vulnerability, business continuity, supplier security, incident response, and third-party risk assessment methodologies.
- Knowledge of national and international regulatory and security frameworks including NIST Cybersecurity Framework, ISO standards, SOX, GDPR, HIPAA, PCI DSS, TISAX, and related supplier security expectations.
- Experience leading risk treatment decisions, remediation governance, supplier escalations, executive briefings, onsite supplier assessments, or high-risk supplier reviews.
- CRISC, CISA, CISSP, ISO 27001 Lead Auditor, CISM, or equivalent certifications are preferred.
- Preferred skills in SharePoint, Teams, reporting tools, workflow platforms, AI-enabled automation, and other collaboration or knowledge management platforms.
- Demonstrated ability to mature cybersecurity risk practices, establish reusable processes, and improve outcomes across third-party ecosystems and high-risk supplier relationships.
Soft skills requirements
- Ability to define, communicate, and influence enterprise third‑party cybersecurity risk decisions in business‑relevant language.
- Excellent verbal and written communication skills, including the ability to craft and deliver concise executive-level communications, risk narratives, and decision briefs.
- Ability to lead confidently through ambiguity, competing priorities, sensitive supplier issues, and rapidly changing risk conditions.
- Ability to communicate cybersecurity and third‑party risk concepts clearly to technical, non‑technical, supplier, and executive audiences.
- Strong problem‑solving, analytical, facilitation, negotiation, and risk‑based decision‑making skills.
- Ability to mentor analysts, build stakeholder trust, influence without direct authority, and drive consistent execution across cross‑functional and regional teams.
Job Profile(s):
IT Risk Analyst 4
Relocation level: (TBD)
Before Getting Started
Please review Micron’s Internal Job Application Policy on your regional PeopleNow Career Opportunities page before searching and applying for jobs. Note in particular that:
- Hiring managers may view your performance appraisals, original resume, transcripts or other performance-related documentation in your personal file. This information will be held in confidence.
- If you are selected to interview for a position, you must notify your direct supervisor before participating in the interview process.
As a world leader in the semiconductor industry, Micron is dedicated to your personal wellbeing and professional growth. Micron benefits are designed to help you stay well, provide peace of mind and help you prepare for the future. We offer a choice of medical, dental and vision plans in all locations enabling team members to select the plans that best meet their family healthcare needs and budget. Micron also provides benefit programs that help protect your income if you are unable to work due to illness or injury, and paid family leave. Additionally, Micron benefits include a robust paid time-off program and paid holidays. For additional information regarding the Benefit programs available, please see the Benefits Guide posted on Benefits | Micron Technology, Inc
Micron is proud to be an equal opportunity workplace and is an affirmative action employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, age, national origin, disability, protected veteran status, gender identity or any other factor protected by applicable federal, state, or local laws.