Cyber Risk Analyst - Remote

501 CSAA Insurance Services, Inc.
New Mexico, United States
Remote
Full-time

Job Information

CSAA Insurance Group (CSAA IG), a AAA insurer, is one of the top personal lines property and casualty insurance groups in the U.

S. Our employees proudly live our core beliefs and fulfill our enduring purpose to help members prevent, prepare for and recover from life's uncertainties, and we're proud of the culture we create together.

As we commit to progress over perfection, we recognize that every day is an opportunity to be innovative and adaptable. At CSAA IG, we hire good people for a brighter tomorrow.

We are actively hiring for a Cyber Risk Analyst - Remote! Join us and support CSAA IG in achieving our goals.

Your Role : Supports the management of Information Technology risk for both new build and existing infrastructure and environments.

Provides subject matter expertise to leadership, IT teams, and the business on cybersecurity matters. Works with the security team, including vulnerability management, logging and monitoring, and threat intelligence teams to understand threats and the CSAA IT environment to communicate CSAA’s security posture.

Your work : Performs more complex work supporting implementation of IT risk management processes and cyber risk quantification (CRQ).

Incumbents in this level work under general supervision on projects of moderate to high scope and complexity and rely on experience to advise the business on their technology security risk exposure and measures to manage and mitigate risk.

Security Risk Management :

Conduct risk assessments, analyze the effectiveness of CSAA IG's IT compliance activities, and report with recommendations to leadership.

Performs compliance reviews to ensure applications, platforms, and cloud environments are operating in accordance with established policies and procedures.

Support business projects, often using Agile methodologies, to identify security requirements and concerns, coordinating with staff from the IT organization and business units.

Track and manage security findings and exceptions in the governance, risk, and compliance (GRC) platform.

Develop and maintain security dashboards to inform security risk management, IT teams, and business leadership of risk exposure.

Cyber Risk Quantification :

Using Factor Analysis of Information Risk (FAIR) methodology, analyze technology risk scenarios modeling impact and likelihood of cyber risk events.

Utilize the MITRE ATT&CK framework to develop threat models for use in cyber risk quantification.

Develop methodologies and models to support technology risk management decisions.

Third Party Risk Management :

Conduct reviews of third-party / vendor risk assessments and escalate significant issues to leadership.

Track and manage third party risk assessments within designated portfolio of projects.

Required Experience, Education and Skills :

8+ years’ work experience in relevant fields

Bachelor's degree in related area (Computer Science, Information Systems or other related field) or an equivalent combination of education and experience

Ability to build and maintain constructive working relationships with a diverse community throughout the organization.

Ability to effectively communicate in both written and verbal manner to influence both technical and non-technical audiences.

Ability to manage projects of moderate scope involving stakeholders from multiple business units inside and outside of IT.

What would make us excited about you?

Actively shapes our company culture (e.g., participating in employee resource groups, volunteering, etc.)

Lives into cultural norms (e.g., willing to have cameras when it matters : helping onboard new team members, building relationships, etc.)

Travels as needed for role, including divisional / team meetings and other in-person meetings

Fulfills business needs, which may include investing extra time, helping other teams, etc.

8+ years System documentation experience and / or technical writing (Preferred)

Master’s degree in STEM field or equivalent combination of education and experience (Preferred)

CSAA IG Careers

At CSAA IG, we’re proudly devoted to protecting our customers, our employees, our communities, and the world at large. We are on a climate journey to continue to do better for our people, our business, and our planet.

Taking bold action and leading by example. We are citizens for a changing world, and we continually change to meet it.

Join us if you

BELIEVE in a mission focused on building a community of service, rooted in inclusion and belonging.

COMMIT to being there for our customers and employees.

CREATE a sense of purpose that serves the greater good through innovation.

Recognition : We offer a total compensation package, performance bonus, 401(k) with a company match, and so much more!

30+ days ago
Related jobs
501 CSAA Insurance Services, Inc.
New Mexico, United States
Remote

We are actively hiring for a Cyber Risk Analyst - Remote! Join us and support CSAA IG in achieving our goals. Using Factor Analysis of Information Risk (FAIR) methodology, analyze technology risk scenarios modeling impact and likelihood of cyber risk events. Performs more complex work supporting imp...

Promoted
Robert Half
Albuquerque, New Mexico

Robert Half is seeking a Business System Analyst position for EDI (Electronic Data Interchange). The Business Analyst key responsibilities include but are not limited to:. Requirements Gathering: Work closely with business stakeholders to gather and document requirements for EDI transactions, ensuri...

Promoted
Dynamic Solutions Technology LLC
Organ, New Mexico

Information Security Specialist. Providing Information Assurance support to the Cyber Security Management Office in the areas of documentation, new user account creation requests for varying systems, and database maintenance and support. Applicant will be subject to a government security investigati...

Promoted
TELOS
Cannon AFB, New Mexico

Telos is looking for an IT Security Analyst to provide Functional Mission Analysis-Cyber assistance to identify the United States Air Force weapon system's critical information technology architecture and supporting infrastructure that aids the warfighting mission. Therefore, any employment with Tel...

Promoted
Chenega Corporation
Albuquerque, New Mexico

Business Analyst, Intermediate. At Cyberstar, we aim to analyze and boost human and business performance through the implementation of business process redesign and information technology (IT) modernization to include data analytics and cloud computing. Business Analyst, Intermediate. Business Analy...

Promoted
Prime Therapeutics
Santa Fe, New Mexico
Remote

Job Posting TitleSenior Compliance Analyst (Interpretation and Advising) - RemoteJob DescriptionThe Senior Compliance Analyst assists in the implementation of Prime’s compliance programs and leads initiatives within their designated areas. This role partners with key internal stakeholders to monitor...

Jackson Hewitt - 2861
Belen, New Mexico

The Data Analyst will be responsible for collecting, organizing, and analyzing tax and financial data to support tax preparation and compliance, reporting, and strategic decision-making. We are seeking a detail-oriented and analytical Data Analyst to join our dynamic tax team. Perform regular audits...

ARA
Albuquerque, New Mexico

We are looking for a Pricing Compliance Analyst who is a self-starter with excellent pricing skills, written and verbal communication skills, outstanding customer service background, detail orientated, and thrives in a team environment. What will you do as a Pricing Compliance Analyst? You will be r...

Nevada National Security Site
Los Alamos, New Mexico

Mission Support and Test Services, LLC (MSTS) manages and operates the Nevada National Security Site (NNSS) for the. National Nuclear Security Administration (NNSA). Our MISSION is to help ensure the security of the United States and its allies by providing high-hazard experimentation and incident r...

Akima
Albuquerque, New Mexico

We are looking for a Cyber Security Engineer to help us protect our systems and networks from cyber threats. As a cybersecurity engineer, you will be responsible for designing, implementing, and maintaining security solutions that align with Federal objectives and industry best practices. Tuvli is l...