Cyber Security Analyst 2//San Jose, CA OR Austin, TX
Listed on 2026-08-08
-
IT/Tech
Cybersecurity, Information Security & Data Protection, IT Business Analyst
IT - Cyber Security Analyst 2
We are seeking a detail-oriented GRC Risk Management Analyst to support information security and third-party risk management. The role combines structured governance and risk analysis with hands-on technical understanding to evaluate vendors throughout the relationship lifecycle—from onboarding and due diligence through ongoing monitoring and offboarding. The analyst will examine architectures, security controls, configurations, technical evidence, and threat scenarios to identify control gaps, determine business impact, document defensible risk decisions, and support practical remediation.
The role will also apply analytics, automation, and AI responsibly to streamline evidence review, improve assessment quality, and accelerate monitoring and reporting while maintaining human validation, data protection, traceability, and appropriate governance.
Key responsibilities include conducting end-to-end third-party risk assessments, administering risk-based vendor questionnaires, maintaining enterprise and vendor risk registers, analyzing security, privacy, resilience, regulatory, concentration, and fourth-party risks, performing technical risk analysis, applying hands-on security knowledge to validate control implementation, partnering with various departments to validate findings and drive mitigation, tracking remediation, preparing leadership reporting, supporting policy governance, control testing, issue management, compliance monitoring, designing and using analytics, automation, and AI-assisted workflows, and maintaining human approval, secure handling of sensitive data, output validation, auditability, and compliance with organizational AI governance requirements.
Required qualifications include a bachelor's degree in Information Security, Risk Management, Business, Computer Science, or a related field, 1–4 years of experience in enterprise risk, third-party risk, GRC, information security, or a related area, knowledge of inherent and residual risk, likelihood and impact, controls, treatment, acceptance, and monitoring, working technical knowledge of enterprise and cloud environments, ability to interpret technical evidence, ability to assess business impact, apply risk criteria, and communicate clear, defensible recommendations, strong analytical, organizational, stakeholder-management, and written and verbal communication skills, proficiency with Microsoft Office, familiarity with GRC, analytics, or automation tools, practical experience using generative AI, scripting, workflow automation, or low-code tools to improve repeatable business processes, with an understanding of prompt design, output validation, sensitive-data handling, access controls, model limitations, and responsible human oversight, and must be able to commute to San Jose, CA or Austin, TX and work on-site at least 3 days per week.
Preferred qualifications include relevant certification or active pursuit, such as Security+ or an AI fundamentals credential, experience with GRC platforms, vendor monitoring tools, audit support, or control evidence collection, familiarity with NIST CSF, ISO 27001, CMMC, SOC 2, GDPR, CCPA, or similar requirements, and experience creating clear procedures, SOPs, or workflow documentation in a technology or regulated environment.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).