Senior Cybersecurity Governance Analyst
Listed on 2026-07-26
-
IT/Tech
Cybersecurity, Information Security & Data Protection
Description:
OUR CULTURE Our organization believes we can all do well by doing good. We value the contributions of diverse minds and prioritize the success and well-being of our employees. We also believe every person in our organization plays a role in supporting a healthy environment and helping to achieve our goal of prosperity for all. To this end, we recruit bright, energetic, and talented people to be members of our team.
In return, we offer a dynamic workplace that presents opportunities for professional advancement and individual growth. We strive to always display integrity, self-awareness, courage, and respect for one another while continuing to seek opportunities to learn. We really believe that when our employees succeed, our community wins.
The Senior Cybersecurity Governance Analyst provides second-line oversight of the organization’s cybersecurity risk management program by leading security architecture governance, threat-informed risk analysis, vulnerability management oversight, and independent security assurance activities. This role ensures cybersecurity risks are identified, evaluated, communicated, and managed in alignment with the organization's risk appetite, regulatory requirements, and strategic objectives. The Senior Cybersecurity Governance Analyst serves as a key advisor to technology, business, and risk stakeholders by providing independent challenge, governance oversight, and risk-informed recommendations to strengthen the organization’s overall cybersecurity posture.
NORMALDAY-TO-DAY WORK
- Conduct independent, risk-based reviews of system, network, application, cloud, and third-party architectures to identify cybersecurity risks and evaluate alignment with security policies, standards, and secure-by-design principles.
- Provide governance oversight of network segmentation, identity management, cloud security, and infrastructure security initiatives, identifying risks and recommending appropriate mitigating controls.
- Participate in project governance and system development lifecycle processes to ensure cybersecurity risks are identified, assessed, and addressed throughout technology initiatives.
- Perform cybersecurity risk assessments for technology initiatives, applications, infrastructure changes, and third-party services, evaluating threats, vulnerabilities, control effectiveness, and residual risk exposure.
- Facilitate risk acceptance, exception management, and remediation tracking processes, ensuring cybersecurity risks are appropriately documented, communicated, and managed in alignment with organizational risk tolerance.
- Support enterprise and operational risk management activities through risk analysis, reporting, and communication.
- Monitor and assess relevant threat intelligence sources and industry threat activity to identify emerging cyber threats and evaluate potential impacts on organizational risk exposure.
- Translate threat intelligence into risk informed recommendations for control enhancements, mitigation strategies, and cybersecurity planning.
- Provide independent oversight of the vulnerability management program, including review of prioritization methodologies and validation of remediation plans for critical and high-risk vulnerabilities.
- Monitor remediation performance against established service level objectives and provide reporting on vulnerability trends, exposure metrics, program effectiveness, and significant risk conditions.
- Coordinate and oversee penetration testing, red team assessments, and independent security reviews; evaluate results and ensure identified risks are appropriately addressed and remediated.
- Develop and maintain cybersecurity metrics, dashboards, risk reporting, policies, standards, and control frameworks, while contributing to cybersecurity strategy, maturity improvement initiatives, and governance committee activities as a subject matter expert on cybersecurity risk and governance matters.
- Display integrity, self-awareness, courage, and respect for staff while ensuring learning agility and flexibility communicating and delegating effectively. Work effectively, collaboratively, and creatively in a team-oriented…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).