Hiring.Camp

Senior Cyber Risk Management Engineer

whitecap

·

Today

Location
GA237 - Atlanta GA, United States of America
Workplace
Hybrid
Type
Full-time
Department
Engineering
Seniority
Senior
Experience
5+ years
Source
Workday

Description

A position at White Cap isn’t your ordinary job. You’ll work in an exciting and diverse environment, meet interesting people, and have a variety of career opportunities.

The White Cap family is committed to Building Trust on Every Job. We do this by being deeply knowledgeable, fully capable, and always dependable, and our associates are the driving force behind this commitment.

Job Summary

Responsible for providing expertise in implementing and maintaining cybersecurity risk frameworks, including NIST CSF ( National Institute of Standards and Technology Cybersecurity Framework) and NIST RMF (National Institute of Standards and Technology Risk Management Framework). Assess, review, and help identify areas where security controls do not exist currently.

Major Tasks, Responsibilities and Key Accountabilities

  • Conduct thorough and regular risk assessments to identify and evaluate potential threats and vulnerabilities related to critical infrastructure. Develop and maintain cyber risk-based statements and scenarios to enhance risk register capabilities.

  • Identify, track, and report on Cyber Key Risk Indicators.

  • Collaborate with cross-functional teams to ensure the integration of security measures into organizational processes and systems.

  • Stay updated on emerging cyber threats and industry best practices to enhance risk mitigation strategies. Conduct threat intelligence monitoring and reporting as needed.

  • Lead the implementation of comprehensive cyber risk management strategies and risk monitoring.

  • Perform annual assessments of operating system security baselines.

Nature and Scope

  • Identifies key barriers/core problems and applies problem-solving skills in order to deal creatively with complex situations. Troubleshoots and resolves complex problems. Makes decisions under conditions of uncertainty, sometimes with incomplete information, that produce effective end results.

  • Independently performs assignments with instruction limited to the expected results. Determines and develops an approach to solutions. Receives technical guidance only on unusual or complex problems or issues.

  • May oversee the completion of projects and assignments, including planning, assigning, monitoring and reviewing progress and accuracy of work, evaluating results, etc. Contributes to employees' professional development but does not have hiring or firing authority.

Work Environment

  • Located in a comfortable indoor area. Any unpleasant conditions would be infrequent and not objectionable.

  • Most of the time is spent sitting in a comfortable position and there is frequent opportunity to move about. On rare occasions, there may be a need to move or lift light articles.

  • Typically requires overnight travel less than 10% of the time.

Education and Experience

  • Typically requires BS/BA in a related discipline. Generally 5-8 years of experience in a related field OR MS/MA and generally 3-5 years of experience in a related field. Certification is required in some areas.

Preferred Qualifications

  • REQUIRED: 5+ years of cybersecurity experience conducting risk assessments, identifying security gaps, and recommending mitigation strategies.
  • REQUIRED: Strong analytical and problem-solving skills, with the ability to communicate complex technical issues to senior IT leaders and non-technical stakeholders.
  • Experience with identity and access management (IAM), identity governance and administration (IGA), and Privileged Access Management (PAM) processes and platforms.
  • Knowledge of access governance, least-privilege principles, privileged account lifecycle management, access reviews, role-based access control, and security exception management.
  • Hands-on experience conducting information security assessments, application control self-assessments (SC1/SC2), control testing, and remediation tracking.
  • In-depth knowledge of NIST Cybersecurity Framework (CSF) and Risk Management Framework (RMF), with a strong ability to apply these frameworks to organizational security practices.
  • In-depth knowledge of operating systems and security baselines, including CIS Controls and CIS Benchmarks, with experience assessing technology configurations and documenting control gaps.
  • Experience administering Risk and Control Self-Assessments (RCSAs), maintaining risk and control documentation, validating evidence, and coordinating with risk and control owners.
  • Ability to collect, validate, reconcile, and analyze security data; develop key risk indicators and operational metrics; and investigate missing, incomplete, or inconsistent information.
  • Experience producing security dashboards, program reporting, trend analysis, and concise executive-level presentations for monthly leadership reviews.
  • Strong written, verbal, and stakeholder-management skills, with the ability to communicate control issues clearly to business, technology, security, and leadership audiences.
  • Preferred certifications: CRISC (ISACA), CGRC ((ISC)²), CISSP ((ISC)²), or comparable governance, risk, access management, or information security certifications.

If you’re looking to play a role in building America, consider one of our open opportunities. We can’t wait to meet you.

Skills

CybersecurityRisk ManagementCISSP

Similar Jobs

30

Senior Manager, Technology Risk and Cyber

BDO · Perth, Australia

3 days ago

Senior Consultant, Technology, Risk and Cyber

BDO · Perth, Australia

3 days ago

Model Risk Senior Analyst - Validation (AI, Cyber, Technology)

mtb · Wilmington, DE, United States of America · Hybrid

4 days ago

Cyber Risk Remediation & Technology Modernization, Senior Vice President

citibank · Jersey City, NJ,US, US +1

1 week ago

Sr. Cyber Risk Consultant

Cibc · Toronto-141 Bay, 16th Floor, Canada · Remote, Hybrid, Onsite

1 week ago

Senior Associate, Cyber Risk Specialist Identity & Access Management | Retail Bank

Capitalone · McLean, VA, United States of America +1

1 week ago

Security Risk & Engineering - Tech and Cyber Risk & Compliance - Senior Manager

Pwc · New York - 300 Madison Avenue, United States of America +8

1 week ago

Senior Legal Director, Cyber & Data Risk

Jj · US017 NJ New Brunswick - 1 J&J Plaza, United States of America +2 · Hybrid

1 week ago

Senior Legal Director, Cyber & Data Risk

Jj · US017 NJ New Brunswick - 1 J&J Plaza, United States of America +2 · Hybrid

1 week ago

Cyber Security Risk Governance Senior Associate

Depository Trust Company · TX, United States, US

2 weeks ago

Senior Associate - Cyber Risk & Analysis, Technology Audit

Capitalone · McLean, VA, United States of America +4

3 weeks ago

ETIC, Cyber Risk Senior Associate (German Speaker)

Pwc · Cairo - ETIC, Egypt

1 month ago

Senior Associate, Cyber Governance and Risk

Pfizer · GRC - Thessaloniki, Chortiatis, Greece

1 month ago

Senior Associate, Cyber Governance and Risk

Pfizer · GRC - Thessaloniki, Chortiatis, Greece

1 month ago

Cyber Risk Lead- Security Control Assessor - Senior

Pyramid Systems · , US · Remote

1 month ago

Cyber Third Party Risk Reduction (CTPRR) Senior Manager, Operations Manager

Capitalone · McLean, VA, United States of America +1

1 month ago

Senior Consultant, Cyber Risk Management & Transformation

Bdo · Toronto - Wellington St, Canada +2

1 month ago

Security Analyst/Senior Security Analyst (Technical cyber risk management) - ITDSGGR (Contractual)

Imf · IMF Headquarters 2, United States

1 month ago

Cyber Risk Sr. Group Manager, Director

citibank · New York, NY,US, US

1 month ago

Cyber Risk Sr. Group Manager, Director

Citi Bank · 388 GREENWICH STREET - TOWER, United States of America · Hybrid

1 month ago

Cyber Risk Senior Officer - Senior Vice President

Citi Bank · 6460 LAS COLINAS BLVD IRVING, United States of America · Hybrid

1 month ago

Senior Analyst, Cyber Risk Quantification and GRC

Forrester · Cambridge, MA, United States of America +8 · Remote

2 months ago

Senior Cyber/ Cyber Risk Surveillance Analyst

Sggovterp · MAS: MAS Building, Singapore

2 months ago

Senior Cyber Risk & Insurance Broker

LON3 London - 51 Lime Street · Hong Kong, HK

2 months ago

Senior Analyst, Cyber Risk and Compliance

Digital Realty Global · Ireland, IE · Onsite

2 months ago

ETIC, Cyber Risk Senior Associate

Pwc · Cairo - ETIC, Egypt

2 months ago

Senior Manager - Cyber Risk Consulting

Mmc · Mumbai - Hiranandani, India · Hybrid

2 months ago

Senior Analyst, IT & Cyber Governance, Risk & Control

Questrade Financial Group · 5700 Yonge St, North York, ON M2M 4K2, Canada

2 months ago

Advisory Senior - Cyber Risk Services

EisnerAmper is one of the · Hyderabad, India

3 months ago

Senior Analyst - Cyber Threat Modeling and Risk

Eqbank · Toronto · Hybrid

3 months ago