
Security Risk Management Specialist
Posted 9 hours ago

Posted 9 hours ago
This is a fully remote position, open to applicants in Illinois.
• Identify, evaluate, report, and monitor security risks across enterprise security and business functions.
• Collaborate with various departments to ensure adherence to security policies and standards.
• Suggest security measures to safeguard organizational assets from potential threats.
• Conduct thorough security risk assessments of enterprise systems and processes.
• Provide recommendations for mitigating identified risks.
• Review, analyze, and propose actions for exceptions related to policies, standards, and baseline configurations.
• Execute vendor risk assessments, including the identification, analysis, and mitigation of inherent and residual risks.
• Monitor vendor risk remediation until completion.
• Advise on vendor contractual requirements based on the outcomes of risk assessments.
• Act as a project security advisor, including performing risk analysis gate checks in the secure SDLC process.
• Conduct threat modeling exercises to pinpoint potential security vulnerabilities and risks.
• Keep abreast of security trends, threats, and best practices to enhance the organization’s security posture.
• Carry out additional duties as assigned.
• Bachelor's degree or equivalent experience.
• Over 2 years of experience in IT security, privacy, audit, controls, regulatory compliance, or a related field.
• Proficient in conducting risk assessments in alignment with industry-standard frameworks and standards.
• Intermediate understanding of infrastructure, networking, storage, databases, operating systems, cloud services, applications, and related IT domains.
• Strong knowledge of SSO, IAM, DLP, EDR, SIEM, firewalls, gateways, IDS/IPS, CASB, antivirus, SSDLC, cryptography, PKI, and associated security technologies.
• Familiarity with risk and control frameworks such as NIST CSF, NIST 800-53, ISO/IEC 27001, NIST 800-30, and ISO/IEC 27005.
• Excellent oral and written communication skills.
• Ability to manage multiple projects/tasks simultaneously and delegate key responsibilities effectively.
• Capable of liaising across operational, functional, and technical disciplines.
• Strong analytical, problem-solving, and critical-thinking abilities.
• Preferred: Master’s degree and/or LOMA certification.
• Preferred: Over 2 years of experience in a leadership role.
• Preferred: Knowledge or experience in the Insurance/Reinsurance industry.
• Preferred: Certifications in information security, compliance, risk, or audit, such as CISSP, CISA, CISM, CGEIT, CRISC, CPA, OSCP, CCSP, or CCSK.
• Preferred: Project management skills or experience.
• Preferred: Experience with cloud assessments on AWS, Azure, or Google Cloud.
• Preferred: Experience in Cyber Risk Quantification, such as FAIR.
• Preferred: Automation experience using Python, REST API, or PowerShell.
• Preferred: Previous roles as a Systems Administrator, IT Auditor, Developer, Security Engineer, Penetration Tester, or Cloud Engineer.
• Annual bonus plan.
• Eligibility for long-term equity incentive plans for certain positions.
• Comprehensive health benefits.
• Retirement benefits.
• Additional employee benefits.
• A diverse and supportive team of colleagues worldwide.
• A respectful and welcoming work environment.
• Opportunities for career growth and global mobility.
Avedo GmbH
Avedo GmbH
Avedo GmbH
Avedo GmbH
Get handpicked remote jobs straight to your inbox weekly.