E logo

Enterprise Risk Analyst

Expert In Recruitment SolutionsDurham, NC

Automate your job search with Sonara.

Submit 10x as many applications with less effort than one manual application.1

Reclaim your time by letting our AI handle the grunt work of job searching.

We continuously scan millions of openings to find your top matches.

pay-wall

Overview

Remote
On-site

Job Description

The experienced Risk Analyst role executes the VA Enterprise Risk Analysis process using a custom ERA tool to identify key cyber security risk factors in network connected medical devices and Special Purpose Systems (e.g., building automation systems, physical security systems, operational technology). These risk factors are summarized, evaluated, and reported using quantitative and qualitative scores to provide a VA authorizing official with awareness of the residual cyber risk prior to connecting these devices to the VA network. The Risk Analyst must acquire, review and leverage system documentation and data gathered through questionnaires and interviews with customers in the field and vendor/manufacturer representatives to accurately document critical security posture elements in a common reporting format. These elements include hardware/software inventory, communications profile, system interconnections, data types and stores, and the presence or lack of security controls, settings and mechanisms for a given device type. The Risk Analyst performs annual reviews to support effective continuous monitoring and to ensure documented residual risks are current, accurate, and complete. The analyst works within a Risk Management team and is expected to collaborate with Federal and contractor team mates to achieve best outcomes for the ERA process.

You Have:

Experience with Cybersecurity, risk management, or risk assessment for complex systems

Experience with NIST SP 800-53 and NIST SP 800-30

Experience with documenting and depicting network topology and network protocols

Ability to engage directly with clients, and third parties to facilitate enterprise risk analysis

Ability to obtain and maintain a Public Trust or Suitability/Fitness determination based on client requirements

Bachelor's degree in Computer Science, Mathematics, Engineering or technical discipline and 10 years of relevant work experience or 18 years of relevant work experience in lieu of degree

Nice If You Have:

Experience with cybersecurity analysis of medical technology or Internet of Things (IoT)

Experience with Governance, Risk, and Compliance (GRC)

Experience with Assessment and Authorization (A&A) and eMASS

Experience with Excel and Visio

CompTIA Security+ or Certified Risk Management Professional (CRISC) or Certified in Risk and Information Systems Control (CRISC)

Public Trust clearance

Automate your job search with Sonara.

Submit 10x as many applications with less effort than one manual application.

pay-wall

FAQs About Enterprise Risk Analyst Jobs at Expert In Recruitment Solutions

What is the work location for this position at Expert In Recruitment Solutions?
This job at Expert In Recruitment Solutions is located in Durham, NC, according to the details provided by the employer. Some roles may also include multiple work locations depending on the requirement.
What pay range can candidates expect for this role at Expert In Recruitment Solutions?
Employer has not shared pay details for this role.
What employment applies to this position at Expert In Recruitment Solutions?
The employer has not provided this information. This may be discussed during the hiring process.
What is the process to apply for this position at Expert In Recruitment Solutions?
You can apply for this role at Expert In Recruitment Solutions either through Sonara's automated application system, which helps you submit applications 10X faster with minimal effort, or by applying manually using the direct link on the job page.