Cybersecurity Senior Risk Analyst
Location: Libertyville, IL
Work Arrangement: Onsite
Contract Duration: 1 year, W2
Pay: $50-55/hr
Position Overview
We are seeking an experienced Cybersecurity Senior Risk Analyst to support enterprise cybersecurity and third-party risk management initiatives. This role will work closely with business stakeholders, cybersecurity teams, and technology partners to identify, assess, and manage risks while driving process improvements and operational efficiencies.
The ideal candidate will combine cybersecurity risk management expertise with strong business analysis skills, helping to translate business needs into scalable solutions that enhance governance, risk, and compliance (GRC) processes. This role offers the opportunity to influence risk management practices, improve enterprise workflows, and contribute to a strong security and compliance posture.
Key Responsibilities
- Evaluate and monitor cybersecurity and third-party risk activities.
- Conduct risk assessments and support remediation tracking efforts.
- Collaborate with stakeholders to gather, analyze, and document business requirements.
- Develop business use cases, process flows, user stories, and functional requirements.
- Support implementation of process improvements and system enhancements.
- Coordinate testing activities, including user acceptance testing (UAT), defect tracking, and solution validation.
- Analyze existing workflows and identify opportunities to improve automation, efficiency, data quality, and user experience.
- Serve as a liaison between business, risk, cybersecurity, and technology teams.
- Support data governance initiatives and maintain the integrity of risk-related information.
- Develop dashboards, metrics, reports, and other tools to measure risk and operational performance.
- Create and maintain business documentation, process documentation, training materials, and testing artifacts.
- Assist with audit, regulatory, and compliance-related activities.
Required Qualifications
- Bachelor’s degree in Information Security, Cybersecurity, Computer Science, Information Systems, Business, or a related field, or equivalent professional experience.
- 3+ years of experience in cybersecurity risk management, information security, governance, risk and compliance (GRC), or a related field.
- Experience gathering and documenting business requirements and supporting process improvement initiatives.
- Strong analytical, problem-solving, communication, and stakeholder management skills.
- Ability to work independently and effectively within cross-functional teams.
- Experience supporting software testing activities, including UAT and defect management.
Preferred Qualifications
- Experience supporting cybersecurity risk, third-party risk management, or GRC programs.
- Experience with ServiceNow or similar risk management, workflow, or vendor management platforms.
- Knowledge of cybersecurity frameworks, controls, standards, and best practices.
- Experience creating business requirements, workflow diagrams, process maps, use cases, and user stories.
- Familiarity with audit, compliance, and regulatory requirements.
- Experience developing dashboards, metrics, and reporting solutions.
- Understanding of procurement, vendor management, and operational risk processes.
- Familiarity with industry standards and frameworks such as ISO 27001, SOC 2, HITRUST, FedRAMP, and ISO 22301.
- Professional certifications such as CISSP, CISM, CRISC, or similar are preferred.
Desired Skills
- Cybersecurity Risk Management
- Third-Party Risk Management
- Governance, Risk & Compliance (GRC)
- ServiceNow
- Business Analysis
- Requirements Gathering
- User Stories & Process Mapping
- User Acceptance Testing (UAT)
- Risk Assessments
- Data Analysis & Reporting
- Stakeholder Management
- Process Improvement
- Audit & Compliance Support
Why Join Us
This position offers the opportunity to work at the intersection of cybersecurity, risk management, and business strategy. You’ll collaborate with diverse teams, contribute to impactful risk management initiatives, and help shape processes that strengthen organizational resilience and security.
#LI-EP1
