
Senior Security Risk Engineer
Posted 15 hours ago

Posted 15 hours ago
This is a fully remote position, open to applicants in United States, +1 more country.
• Take ownership of risk identification, analysis, and prioritization related to third-party risks, security risk assessments, and security findings using a recognized risk framework.
• Convert technical vulnerabilities, control deficiencies, and risk findings into clear, quantified risk statements for stakeholders and leadership.
• Lead the remediation of findings and risk exceptions to resolution in collaboration with Engineering, IT, Product, and Legal; escalate stalled or high-severity issues.
• Develop and maintain a risk register along with a quarterly reporting routine that addresses open risks, remediation progress, and trends.
• Manage and enhance AI risk management, which includes conducting AI impact assessments, AI risk assessments, and risk treatments in support of ISO 42001 certification.
• Design, develop, and implement key risk indicators and associated metrics for critical risks.
• Create automation, scripting, or AI-enabled tools to streamline manual risk and TPRM workflow processes.
• Contribute to the risk program roadmap by incorporating frameworks, regulatory updates, and lessons learned from assessments.
• Keep track of internal and external risk landscapes to identify and escalate emerging risks.
• Collaborate with Security, Legal, IT, Product, and Engineering teams to convert technical findings and vendor risks into business-relevant risk statements and treatments.
• Present top risks to leadership.
• A minimum of 5 years of experience in security risk management.
• Experience with security-focused risk management or compliance frameworks such as NIST RMF, NIST 800-39, or ISO 31000.
• Familiarity with AI governance frameworks like ISO 42001 or NIST AI RMF is advantageous.
• Proven experience in designing and executing both qualitative and quantitative risk analyses that effectively translate technical risks into measurable business impacts.
• A solid track record of driving risk assessments, maintaining risk registers, and ensuring remediation efforts are completed across IT, Procurement, Internal Audit, Legal, Product, and Engineering in a highly regulated or multi-entity setting.
• Ability to interpret technical control requirements and communicate them effectively to both technical and non-technical stakeholders.
• Demonstrated ability to personally create scripts, workflows, or AI-enabled tools to minimize manual risk or GRC tasks.
• Comfort in navigating ambiguity, managing multiple concurrent assessments, and reprioritizing under tight timeframes.
• Outstanding written and verbal communication skills with a proven ability to translate security risks into business risks.
• Strong knowledge of cloud security, SaaS security models, and DevSecOps practices.
• Relevant certifications such as CISSP, CISM, CISA, or CRISC are preferred, though not mandatory.
• Comprehensive benefits to enhance your health, financial stability, and overall well-being.
• Flexible Paid Time Off.
• Team Member Resource Groups.
• Equity Compensation & Employee Stock Purchase Plan.
• Growth and Development Fund.
• Parental Leave.
Campbell's
VALCE Talent Solutions
The Hello Team
Anduril Industries
Get handpicked remote jobs straight to your inbox weekly.