Job Title: Cybersecurity Engineer 3 (Cyber Risk / GRC)
Compensation / Location / Contract
- $72 to $75 per hour W2
- Medical, dental, vision, 401k with company match
- Onsite in Peoria, IL; Irving, TX; or Nashville, TN
- 12 month contract
- Monday through Friday, 1st shift
- Minimal travel (0-25 percent)
Overview
Seeking an experienced Cyber Risk / GRC professional to support the execution and ongoing maturation of an enterprise cyber risk management program. This role is highly visible and involves close collaboration with senior leadership, focusing on risk acceptance, qualitative risk analysis, and risk register lifecycle management.
This position offers a strong mix of hands-on execution and program improvement, ideal for someone who can operate independently, communicate effectively at the executive level, and bring structure to complex risk environments.
Key Responsibilities
- Facilitate risk acceptance and awareness discussions with senior leadership
- Translate technical cybersecurity risks into clear business impacts
- Develop executive-ready presentations, anticipating leadership questions and data needs
- Maintain and manage the cyber risk register, including tracking remediation activities and risk decisions
- Perform qualitative risk analysis (likelihood and impact) using scenario-based approaches
- Evaluate control effectiveness and recommend risk-based mitigation strategies
- Support the remediation lifecycle, including follow-ups and action plan tracking
- Contribute to risk program design, enhancements, and process improvement initiatives
- Ensure proper documentation and audit readiness across all risk activities
Required Qualifications
- Bachelors degree with 5+ years of experience, or 7+ years of relevant experience without a degree
- Experience in cyber risk, IT risk, or information security risk (consulting or Big 4 preferred)
- Strong experience managing risk registers and remediation tracking
- Proven ability to perform qualitative risk analysis
- Excellent communication and presentation skills, particularly with senior stakeholders
- Ability to translate technical concepts into business-focused risk language
- Strong organizational skills with a proactive, self-starter mindset
- Solid understanding of systems, controls, and risk scenarios
Preferred Qualifications
- Experience with qualitative risk frameworks or methodologies
- Familiarity with FAIR (Factor Analysis of Information Risk)
- Knowledge of frameworks such as ISO 27001, NIST, or similar
- Experience with ServiceNow IRM or other GRC platforms
- Relevant certifications such as CISSP, CISA, CISM, or CRISC
- Background in audit, business continuity, or disaster recovery
- Experience contributing to program design or process improvement initiatives
What They Are Looking For
- Someone who can operate independently and take ownership
- Strong communicator comfortable engaging with senior leadership
- Experience in enterprise-scale risk environments
- Ability to balance technical understanding with business communication
#LI-DO1
#INDOEM
