- Location
- Cohesity - Dublin, Ireland · Ireland - Remote
- Workplace
- Hybrid, Remote
- Type
- Full-time
- Seniority
- Senior
- Experience
- 4+ years
- Education
- Bachelor
- Visa
- Not sponsored
- Source
- Workday
Description
Cohesity is the leader in AI-powered data security. Over 13,600 enterprise customers, including over 85 of the Fortune 100 and nearly 70% of the Global 500, rely on Cohesity to strengthen their resilience while providing Gen AI insights into their vast amounts of data. Formed from the combination of Cohesity with Veritas’ enterprise data protection business, the company’s solutions secure and protect data on-premises, in the cloud, and at the edge. Backed by NVIDIA, IBM, HPE, Cisco, AWS, Google Cloud, and others, Cohesity is headquartered in Santa Clara, CA, with offices around the globe.
We’ve been named a Leader by multiple analyst firms and have been globally recognized for Innovation, Product Strength, and Simplicity in Design , and our culture.
Want to join the leader in AI-powered data security?
We are looking for a hands-on, technically capable Cyber Governance & Risk Senior Analyst to help change how security governance and risk work gets done at Cohesity. This is a builder role, alongside supporting our Security Governance and Cyber Risk programs, you'll identify where control monitoring and risk analysis can move from manual, point-in-time effort to continuous, automated monitoring and then build that cApability, using robotic process automation, agentic workflows, and AI-assisted development of in-house GRC capabilities. You'll partner directly with control owners and operators across Cohesity to drive security posture toward its targets, and you'll help prove that a governance and risk program can scale with a fast-growing company through automation rather than headcount. This role is ideal for someone who combines solid cybersecurity governance and risk fundamentals with a genuine appetite for building.
HOW YOU’LL SPEND YOUR TIME HERE :
- Support both the Security Governance program (Common Controls Framework maintenance, policy and standards, KPI/SLA measurement) and the Cyber Risk program (findings intake, risk analysis through the Risk Management Lifecycle, Risk Register integrity).
- Identify which governance, control-testing, and risk-analysis work can move to continuous, automated monitoring, and build it using robotic process automation, agentic workflows, and in-house GRC tooling.
- Measure control effectiveness continuously against defined thresholds, so control drift surfaces when it happens rather than at the next assessment cycle.
- Codify control-effectiveness logic — what a control must prove, what evidence counts, what trips a finding, and where a human must decide so automation runs against clear logic with defined parameters and guardrails.
- Partner with control owners and control operators to deliver effectiveness drivers and prioritize remediation, ensure the evidence behind each control is available and trusted.
- Take individual or bundled findings through to risk and populate Risk Register entries ready for the risk owner's decision.
- Support the annual ISMS organizational risk assessment and produce continuous-monitoring evidence that meets certification and regulated-customer requirements.
- Build reusable monitoring and automation assets that can be shared across the Security Governance and Cyber Risk programs, and keep that automation itself under proper control governance.
WE'D LOVE TO TALK TO YOU IF YOU HAVE MANY OF THE FOLLOWING :
- 4+ years of experience in cybersecurity governance, risk, or compliance (GRC), with hands-on control assessment or monitoring.
- Demonstrable experience building automation in a GRC, security, or compliance context — robotic process automation, scripting, or agentic workflows with concrete examples of what it replaced.
- Working knowledge of at least two control frameworks (e.g., SOC 2, ISO 27001, NIST CSF) and how control effectiveness is evidenced.
- Experience partnering with control owners or operators to drive remediation to closure, including where accountability sits outside the security team.
- Strong communication skills, with the ability to make control and risk information usable for stakeholders across the business.
- Bachelor's degree or equivalent experience in Cybersecurity, Information Security, Risk Management, or a related field.
WE ARE EXTRA EXCITED IF YOU HAVE ANY OF THE FOLLOWING:
- Experience building or operating continuous controls monitoring, not just periodic or point-in-time assessment.
- Hands-on experience with agentic AI development, Claude or similar tooling, or building in-house GRC capabilities.
- Experience in SaaS, cloud, or data infrastructure companies.
- Exposure to quantitative risk methods and risk register operation.
- Familiarity with audit and compliance requirements (e.g., SOC 2, ISO 27001, GDPR, HIPAA).
- Industry certifications such as Security+, ISO 27001 Lead Implementer, CRISC, or similar are welcome, though not required.
This is a rare chance to shape how an established, security-conscious company runs its governance and risk program in the AI era. Rather than doing the same manual work at greater volume, you'll build the automation that lets the program scale and you'll see your work land directly in Cohesity's security posture, its Risk Register, and the evidence our customers and auditors rely on. You'll work alongside a skilled, collaborative cybersecurity team, with room to grow your building skills and deepen as a senior individual contributor. If you want your governance and risk work to be measured by what you build and the risk you help reduce, this role is for you.
#LI-MS2
Data Privacy Notice for Job Candidates:
For information on personal data processing, please see our Privacy Policy.
Equal Employment Opportunity Employer (EEOE)
Cohesity is an Equal Employment Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, creed, religion, sex, sexual orientation, national origin or nationality, ancestry, age, disability, gender identity or expression, marital status, veteran status or any other category protected by law.
If you are an individual with a disability and require a reasonable accommodation to complete any part of the application process, or are limited in the ability or unable to access or use this online application process and need an alternative method for applying, you may contact us at 1-855-9COHESITY or [email protected] for assistance.
In-Office Expectations
Cohesity employees who are within a reasonable commute (e.g. within a forty-five (45) minute average travel time) work out of our core offices 2-3 days a week of their choosing.
We strongly prefer candidates who are currently located in or near the designated job location. Candidates outside the area should apply only if they are committed to relocating prior to their start date and have the legal right to work in the job location.