Cyber Security Analyst/San Jose, CA OR Austin, TX
Job in
Austin, Travis County, Texas, 78735, USA
Listed on 2026-09-03
Listing for:
TPI Global Solutions
Full Time
position Listed on 2026-09-03
Job specializations:
-
IT/Tech
Cybersecurity, Information Security & Data Protection
Job Description & How to Apply Below
Hi, My name is Sudheer , and I work with TPI Global Solutions. We are a global talent solutions firm providing a wide range of staffing solutions to companies and candidates within the technology field. I have reviewed your profile on one of the Job Portal and feel that your background could be a great fit for an exciting opportunity I am working on right now.
Title:
IT - Cyber Security Analyst 2 Client: AMD
Location:
San Jose, CA OR Austin, TX (hybrid, 3 days onsite per week) Duration: 12 + Months
Job Description:
We are seeking a detail-oriented GRC Risk Management Analyst to support information security and third-party risk management. The role combines structured governance and risk analysis with hands-on technical understanding to evaluate vendors throughout the relationship lifecycle—from onboarding and due diligence through ongoing monitoring and offboarding. The analyst will examine architectures, security controls, configurations, technical evidence, and threat scenarios to identify control gaps, determine business impact, document defensible risk decisions, and support practical remediation.
The role will also apply analytics, automation, and AI responsibly to streamline evidence review, improve assessment quality, and accelerate monitoring and reporting while maintaining human validation, data protection, traceability, and appropriate governance.
Key Responsibilities
• Conduct end-to-end third-party risk assessments, including due diligence, inherent-risk tiering, control evaluation, residual-risk determination, periodic reassessment, and offboarding review
• Administer risk-based vendor questionnaires covering security governance, data protection, access control, vulnerability management, incident response, business continuity, cloud services, and subcontractor oversight; review responses and supporting evidence, clarify gaps with vendors, and translate findings into risk ratings and remediation actions
• Maintain enterprise and vendor risk registers with clear risk statements, ratings, owners, treatment plans, and status
• Analyze security, privacy, resilience, regulatory, concentration, and fourth-party risks based on business criticality and data sensitivity
• Perform technical risk analysis by reviewing system architecture, data flows, cloud and network configurations, identity and access models, encryption, logging, vulnerability results, penetration-test findings, software dependencies, and incident-response capabilities; distinguish design intent from operating effectiveness and document evidence-based conclusions
• Apply hands-on security knowledge to validate control implementation through practical review of technical artifacts, targeted demonstrations, sample-based testing, and collaboration with engineers and system owners; translate technical weaknesses and threat scenarios into clear likelihood, impact, residual-risk, and remediation recommendations
• Partner with Security, IT, Legal, Privacy, Procurement, and business owners to validate findings and drive proportionate mitigation
• Track remediation, escalate material risks and exceptions, and prepare concise leadership reporting, including KRIs, trends, and heat maps
• Support policy governance, control testing, issue management, compliance monitoring, and alignment with NIST, ISO 27001, CMMC, and applicable requirements
• Design and use analytics, automation, and AI-assisted workflows to improve questionnaire triage, evidence extraction, control mapping, risk-statement drafting, issue classification, continuous monitoring, and reporting; measure process gains and maintain human approval, secure handling of sensitive data, output validation, auditability, and compliance with organizational AI governance requirements
Required Qualifications
•
Education:
Bachelor’s degree in Information Security, Risk Management, Business, Computer Science, or a related field
•
Experience:
1–4 years in enterprise risk, third-party risk, GRC, information security, or a related area
• Knowledge of inherent and residual risk, likelihood and impact, controls, treatment, acceptance, and monitoring
• Working technical knowledge of enterprise and…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×