Risk & Governance Analyst
الوصف الوظيفي
Risk & Governance Analyst
The Risk & Governance Analyst plays a pivotal role in driving our organization's cybersecurity governance, risk, and compliance (GRC) program. This role is centered around managing the cybersecurity risk register, conducting control assessments, collecting evidence, overseeing governance activities, and generating insightful performance reports.
The ideal candidate will collaborate closely with various teams, including business units, IT, internal audit, security operations, and compliance, to ensure all cybersecurity risks are identified, evaluated, tracked, and reported, while maintaining adherence to organizational policies, industry standards, and regulatory requirements.
- Risk Management
- Administer and maintain the enterprise cybersecurity risk register.
- Identify, assess, and document cybersecurity risks in conjunction with business and technical stakeholders.
- Perform qualitative and quantitative risk assessments.
- Track risk treatment plans and monitor remediation progress.
- Facilitate periodic risk reviews and updates.
- Escalate overdue or high-risk findings to management.
- Support risk acceptance and exception management processes.
- Prepare risk summaries and dashboards for leadership review.
- Governance & Control Assessment
- Coordinate security control assessments across technology and business environments.
- Evaluate the design and effectiveness of security controls.
- Perform gap assessments against internal security policies and industry frameworks.
- Track control deficiencies and remediation activities.
- Support periodic governance reviews and compliance meetings.
- Maintain governance documentation, standards, and procedures.
- Assist in developing and updating cybersecurity policies and standards.
- Evidence Management
- Coordinate the collection of evidence required for internal and external audits.
- Maintain an organized repository of governance and compliance evidence.
- Validate the completeness and accuracy of submitted evidence.
- Support audit readiness activities.
- Coordinate with control owners to obtain required documentation.
- Track evidence submission deadlines and outstanding requests.
- Performance Reporting
- Prepare cybersecurity governance reports and executive dashboards.
- Develop and maintain Key Risk Indicators (KRIs) and Key Performance Indicators (KPIs).
- Produce regular reporting on risk register status, control assessment results, audit findings, compliance status, remediation progress, and policy compliance.
- Present governance metrics to security leadership and management.
- Support board and executive reporting as required.
- Compliance Support
- Support compliance initiatives aligned with various standards and regulations.
- Assist in preparing for certification and regulatory audits.
- Monitor compliance obligations and track corrective actions.
- Coordinate responses to audit findings.
- Continuous Improvement
- Identify opportunities to improve governance processes and reporting.
- Recommend enhancements to risk management methodologies.
- Assist in implementing governance and GRC tools.
- Promote awareness of governance, risk, and compliance processes across the organization.
- Support automation of governance reporting where applicable.
Required Qualifications
Bachelor's degree in Cybersecurity, Information Security, Information Technology, Business Administration, Risk Management, or a related field.
3–5 years of experience in cybersecurity governance, risk management, compliance, audit, or information security.
Proven experience in maintaining cybersecurity risk registers and performing risk assessments.
Familiarity with security control frameworks and governance processes.
Experience supporting audits and evidence collection.
Technical Skills
Enterprise Risk Management (ERM), Cybersecurity Risk Assessment, Risk Register Management, Security Control Assessments, Governance Frameworks, Audit Coordination, Evidence Management, Compliance Monitoring, Policy and Procedure Development.
يمكن أن يرتكب الذكاء الاصطناعي أخطاءً.