
Cybersecurity Analyst – Risk
GM Financial
full-time
Posted on:
Location Type: Hybrid
Location: Arlington • Texas • United States
Visit company websiteExplore more
Job Level
Tech Stack
About the role
- Execute Cyber Vendor Risk and Cyber Application Risk assessments to identify, document, and communicate cybersecurity risks across the organization.
- Perform cybersecurity vendor risk and application risk assessments in accordance with enterprise standards.
- Review vendor security documentation and application assessment evidence to identify gaps and risks.
- Document assessment results clearly, accurately, and consistently.
- Assign risk ratings and remediation recommendations.
- Engage with IT, Procurement, Privacy, Legal, and business partners throughout the assessment lifecycle.
- Track remediation actions and support follow-up activities as needed.
- Contribute to continuous improvement of assessment processes, templates, and guidance.
- Escalate complex or high-risk issues to senior analysts or management when appropriate.
Requirements
- Hands-on experience performing cybersecurity risk assessments for vendors or applications.
- Working knowledge of NIST CSF and NIST 800-53 control frameworks.
- Strong written communication and documentation skills.
- Ability to apply judgment within established standards and guidance.
- Organized, detail-oriented, and able to manage multiple assessments simultaneously.
- Comfortable collaborating with both technical and non-technical stakeholders.
- Consistent, accurate, and timely completion of work assignments.
- Minimum of 1-5 years’ experience in large and complex business environment with a successful track record working directly with senior level management preferred
- At least 1 year of experience in one or more of the following domains: Cybersecurity Governance, Risk Management, Operational Security, Business Continuity & Disaster Recovery, Legal Regulations, Investigations and Compliance, IT or Security Audit, IT or Security Compliance preferred
- Bachelor’s Degree in related field or equivalent work experience strongly preferred
- Information Security Certifications strongly preferred
Benefits
- Generous benefits package available on day one to include: 401K matching
- bonding leave for new parents (12 weeks, 100% paid)
- tuition assistance
- training
- GM employee auto discount
- community service pay
- nine company holidays
Applicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills & Tools
cybersecurity risk assessmentsNIST CSFNIST 800-53risk ratingsremediation recommendationsvendor security documentation reviewapplication assessment evidence reviewassessment documentationcontinuous improvement processesrisk management
Soft Skills
strong written communicationorganizational skillsdetail-orientedjudgment applicationcollaboration with stakeholderstimely completion of work assignmentsability to manage multiple assessmentsengagement with business partnersescalation of issuessupport follow-up activities
Certifications
Information Security Certifications