Enterprise Risk Analyst

Expert In Recruitment Solutions
  • Durham, NC
  • Remote
  • Quick Apply
30+ days ago

Job Description

The experienced Risk Analyst role executes the VA Enterprise Risk Analysis process using a custom ERA tool to identify key cyber security risk factors in network connected medical devices and Special Purpose Systems (e.g., building automation systems, physical security systems, operational technology). These risk factors are summarized, evaluated, and reported using quantitative and qualitative scores to provide a VA authorizing official with awareness of the residual cyber risk prior to connecting these devices to the VA network. The Risk Analyst must acquire, review and leverage system documentation and data gathered through questionnaires and interviews with customers in the field and vendor/manufacturer representatives to accurately document critical security posture elements in a common reporting format. These elements include hardware/software inventory, communications profile, system interconnections, data types and stores, and the presence or lack of security controls, settings and mechanisms for a given device type. The Risk Analyst performs annual reviews to support effective continuous monitoring and to ensure documented residual risks are current, accurate, and complete. The analyst works within a Risk Management team and is expected to collaborate with Federal and contractor team mates to achieve best outcomes for the ERA process.

You Have:

Experience with Cybersecurity, risk management, or risk assessment for complex systems

Experience with NIST SP 800-53 and NIST SP 800-30

Experience with documenting and depicting network topology and network protocols

Ability to engage directly with clients, and third parties to facilitate enterprise risk analysis

Ability to obtain and maintain a Public Trust or Suitability/Fitness determination based on client requirements

Bachelor's degree in Computer Science, Mathematics, Engineering or technical discipline and 10 years of relevant work experience or 18 years of relevant work experience in lieu of degree

Nice If You Have:

Experience with cybersecurity analysis of medical technology or Internet of Things (IoT)

Experience with Governance, Risk, and Compliance (GRC)

Experience with Assessment and Authorization (A&A) and eMASS

Experience with Excel and Visio

CompTIA Security+ or Certified Risk Management Professional (CRISC) or Certified in Risk and Information Systems Control (CRISC)

Public Trust clearance

Numbers & Facts

LocationDurham, NC (
Remote
)

Skills

  • Analysis Skillsunmatched
  • Automation Systemsunmatched
  • CompTIA Security+unmatched
  • Computer Scienceunmatched
  • Federal Contractsunmatched
  • Fitnessunmatched
  • Home Automationunmatched
  • Information Technology & Information Systemsunmatched
  • Internet Securityunmatched
  • Internet of Thingsunmatched
  • Mathematicsunmatched
  • Medical Equipmentunmatched
  • Microsoft Excelunmatched
  • Microsoft Visiounmatched
  • Network Connectivityunmatched
  • Network Securityunmatched
  • Physical Securityunmatched
  • Riskunmatched
  • Risk Analysisunmatched
  • Risk Managementunmatched
  • System Operationsunmatched
  • Systems Analysisunmatched
  • Technology Analysisunmatched

Be found by employers

5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.

Level up your application

Professional resume templates

Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.

Free resume templates

Free resume builder

Improve your existing resume or start from scratch and create a standout, ATS-friendly resume. Add job-specific content, download and apply.

Free resume builder