Senior Cybersecurity Risk Specialist

2 weeks ago


Remote, Oregon, United States Liberty Mutual Insurance Full time

Pay Philosophy
The typical starting salary range for this role is determined by a number of factors including skills, experience, education, certifications and location. The full salary range for this role reflects the competitive labor market value for all employees in these positions across the national market and provides an opportunity to progress as employees grow and develop within the role. Some roles at Liberty Mutual have a corresponding compensation plan which may include commission and/or bonus earnings at rates that vary based on multiple factors set forth in the compensation plan for the role.
Description
At Liberty Mutual Insurance, we believe progress happens when people feel secure. Our cybersecurity program must continually evolve, adapt, and advise on practices to deliver against growing regulatory requirements, increased threats, and changing people, process, and technology drivers.
Our Cybersecurity Governance, Risk, and Compliance (cGRC) organization manages IT compliance and cybersecurity risk supported by an integrated set of products and services that support the lifecycle of our assessment functions. From design and documentation of controls, to testing and assessment of our enterprise and information systems, to consulting on and validation of issues and remediations, we partner with teams across the company to understand their business drivers and optimize security practices in relation to external/regulatory drivers, cybersecurity frameworks, and organizational risk posture.
About the job:
As a Senior Analyst in the Cyber Risk Management space, you will be a key member of our growing information security risk management program. In this role, you will:

  • Analyze and evaluate risks through organizational and system level risk assessment across our global footprint.
  • Learn and apply risk management and threat modeling frameworks to perform assessments in the financial services industry.
  • Apply quantitative risk valuation models and tooling to inform and support strategic and tactical risk-based decisions.
  • Collaborate with control and information system engineering teams to close gaps during assessment.
  • Partners with specialists, peers, and technology teams to communicate cybersecurity risk drivers and their relationships with controls, technology, and processes to ensure impact of decisions is communicated.
  • Contribute to the creation and curation of a comprehensive cybersecurity risk and compliance control framework and library.
  • Understand and communicate baseline measures for control effectiveness.
  • Have the ability to communicate technical issues to diverse audiences and have knowledge and/or experience in application and infrastructure security, public cloud (SaaS, PaaS, IaaS) or another technical domain.
  • Deliver and assist others in providing technical recommendations to partners, IT management and other infrastructure staff in risk assessments, implementation, and operational aspects of information security procedures and products.
  • Research and assess new threats and security alerts and recommend remedial action.
  • Maintain and share understanding of the latest security threats, trends, and technologies.

Ideal candidates have a passion for security, the drive to share their expertise, and the ability to collaborate and help teams deliver solutions that meet our business goals while protecting the confidentiality, integrity and availability of information systems and our data.
Qualifications:

  • Bachelors or Master's Degree in technical or business discipline or related experience.
  • 5+ years professional experience.
  • Current CISSP, CRISC, CISA, GIAC, OpenFAIR or equivalent certification preferred.
  • Working knowledge and practice of risk assessments for IT controls to assess and quantify impacts and relationships of technology to corresponding controls, gaps, and applicable testing strategies.
  • Knowledge of cybersecurity control, program, and risk frameworks such as CIS Controls, NIST CSF, Factor Analysis of Information Risk (FAIR), NIST RMF, and ISO 27001 preferred.
  • Knowledge and experience working in a diverse tooling, technology, and provider environments including custom software, commercial-off-the-shelf and third-party SaaS and PaaS solutions.
  • Familiarity with secure engineering best practices.
  • Understanding of one or more Technology Platforms (AWS, Azure, GCP, Windows, Linux, Mainframe, Middleware Applications, Database Applications) - specifically as they apply to successful security control mitigation and risk factors
  • Highly collaborative with peers and customers on a technical and professional level and driven to improve service and engagement models.
  • Ability to understand and align business drivers in relation to cyber risk considerations.

Qualifications

  • Overview of the minimum knowledge, skills and abilities that are typically required to perform the duties of the role
  • In lieu of any required and/or preferred technical/managerial experience, participation in a company wide sponsored rotational assignment program that provides broad exposure to multiple functions within the organization would be considered
  • Bachelor`s or Master`s degree in technical discipline or equivalent experience
  • Generally, 5+ years of professional experience
  • Highly proficient in security, risk and compliance concepts, processes and able to execute existing patterns
  • Thorough knowledge of new and emerging technologies, well versed in IT concepts, strategies, and methodologies, as well as security aspects of multiple platforms, operating systems, software, communications, and network protocols
  • Strong negotiation, facilitation and consensus building skills; strong oral and written communication skills; able to present to senior contributors and management
  • Highly capable consultative skills, including the ability to understand and assist in applying customer requirements
  • Extensive understanding of backlog tracking, burndown metrics, and incremental delivery
  • Strong collaboration, prioritization, and adaptability skills required

About Us
At Liberty Mutual, our purpose is to help people embrace today and confidently pursue tomorrow. That's why we provide an environment focused on openness, inclusion, trust and respect. Here, you'll discover our expansive range of roles, and a workplace where we aim to help turn your passion into a rewarding profession.
Liberty Mutual has proudly been recognized as a "Great Place to Work" by Great Place to Work US for the past several years. We were also selected as one of the "100 Best Places to Work in IT" on IDG's Insider Pro and Computerworld's 2020 list. For many years running, we have been named by Forbes as one of America's Best Employers for Women and one of America's Best Employers for New Graduates as well as one of America's Best Employers for Diversity. To learn more about our commitment to diversity and inclusion please visit:
We value your hard work, integrity and commitment to make things better, and we put people first by offering you benefits that support your life and well-being. To learn more about our benefit offerings please visit:
Liberty Mutual is an equal opportunity employer. We will not tolerate discrimination on the basis of race, color, national origin, sex, sexual orientation, gender identity, religion, age, disability, veteran's status, pregnancy, genetic information or on any basis prohibited by federal, state or local law.
USD $ $



  • Remote, Oregon, United States Block Full time

    Company DescriptionBlock is one company built from many blocks, all united by the same purpose of economic empowerment. The blocks that form our foundational teams - People, Finance, Counsel, Hardware, Information Security, Platform Infrastructure Engineering, and more - provide support and guidance at the corporate level. They work across business groups...


  • Remote, Oregon, United States Amentum Full time

    The Senior Cybersecurity Analyst role is a remote-telework position that supports our Risk and Compliance (R&C) arm of the cybersecurity team. This role contributes to Amentum's data protection requirements through the assessment of cybersecurity controls and working with teams through the mitigation process of gaps that have been identified. Qualified...


  • Remote, Oregon, United States Coalfire Full time

    About CoalfireCoalfire is on a mission to make the world a safer place by solving our clients' toughest cybersecurity challenges. We work at the cutting edge of technology to advise, assess, automate, and ultimately help companies navigate the ever-changing cybersecurity landscape. We are headquartered in Denver, Colorado with offices across the U.S. and...


  • Remote, Oregon, United States Amentum Full time

    Amentum is seeking a Senior Cybersecurity Operations Engineer to support our cyber environment. This is a remote-telework and hands-on role, responsible for ensuring Amentum assets are protected from cyber threats. This role provides technical expertise in multiple areas of cybersecurity to include cloud security, endpoint security, access management, secure...


  • Remote, Oregon, United States SailPoint Full time

    Cybersecurity Triage EngineerSailPoint's Cybersecurity organization is seeking a Cybersecurity Triage Engineer with a passion for cybersecurity and protecting the organization. The successful candidate will advance the existing Vulnerability Management Remediation effort into a new standalone capability, drive our efforts to coordinate the vulnerability...


  • Remote, Oregon, United States Consensus Cloud Solutions Full time

    Consensus Cloud Solutions is a publicly traded, leading digital cloud fax and interoperability solutions organization in the United States and globally, focusing on connecting and empowering healthcare providers, payers, care teams, and technology innovators to unify multiple systems that wouldn't otherwise talk to each other. Consensus is a trailblazer in...


  • Remote, Oregon, United States Origami Risk Full time

    As the Senior Cloud Solution Architect at Origami Risk, you will play a pivotal role in shaping our cloud strategy and ensuring that our SaaS products and services are built on a robust, scalable, and secure cloud infrastructure. You will lead the development and evolution of Origami's cloud architecture, providing highly scalable solutions to help drive and...


  • Remote, Oregon, United States Motorola Solutions Full time

    Company OverviewAt Motorola Solutions, we're guided by a shared purpose - helping people be their best in the moments that matter - and we live up to our purpose every day by solving for safer. Because people can only be their best when they not only feel safe, but are safe. We're solving for safer by building the best possible technologies across every part...


  • Remote, Oregon, United States Trail of Bits Full time

    Who We AreFounded in 2012 by 3 expert hackers with no investment capital, Trail of Bits is the premier place for security experts to boldly advance security and address technology's newest and most challenging risks. It has helped secure some of the world's most targeted organizations and devices. Our combination of novel research with practical solutions...


  • Remote, Oregon, United States Green Dot Corporation Full time

    We're looking for talented professionals, anywhere in the United States, to join us in bringing smart money management and payment solutions to everyone's fingertips.At Green Dot, we are evolving to a new and permanent "Work from Anywhere" model designed to maximize the benefits of remote work, promote and enable a strong culture of performance and...


  • Remote, Oregon, United States Origami Risk Full time

    The Sr Account Manager is responsible for identifying opportunities and closingadditional revenue from assigned clients, including upselling and cross-selling of relatedproducts. They are also accountable for client renewal, and retention efforts.Starting base pay for this role is between $89,000 and $109,000. The actual base pay isdependent upon many...


  • Remote, Oregon, United States GE Full time

    Job Description SummaryAn effective go-to-market strategy, while establishing a balanced strategy for the delivery of cybersecurity services ideally through GA internal resources, or selectively via our external technology partners.______________________________________________________________________________Une stratégie de mise sur le marché efficace,...


  • Remote, Oregon, United States Airwallex Full time

    Airwallex is the leading financial technology platform for modern businesses growing beyond borders. With one of the world's most powerful payments infrastructure, our technology empowers businesses of all sizes to accept payments, move money globally, and simplify their financial operations, all in one single platform. Established in 2015 in Melbourne, our...


  • Remote, Oregon, United States Fusion Risk Management Full time

    The Role We are looking for an experienced People Operations Specialist to join our dynamic Talent Team. The candidate will be responsible for the following: Managing the day-to-day operations of the HR TeamAdministering Dayforce updates (HRIS) Compensation AnalysisOnboarding and Offboarding of employees Contractors and subcontractorsCompleting critical...


  • Remote, Oregon, United States The Cigna Group Full time

    The job profile for this position is Provider Data Senior Analyst, which is a Band 3 Senior Contributor Career Track Role.Excited to grow your career?We value our talented employees, and whenever possible strive to help one of our associates grow professionally before recruiting new talent to our open positions. If you think the open position you see is...


  • Remote, Oregon, United States SageSure Full time

    Overview: If you are looking for the stability of a profitable, growing company with the entrepreneurial spirit of a startup, we are hiring. SageSure, a leader in catastrophe-exposed property insurance, is seeking a Senior Analyst to join the Catastrophe Risk Research & Development (Cat Risk R&D) Team. In this role, you will be crucial in building an...


  • Remote, Oregon, United States Cloudflare Full time

    About UsAt Cloudflare, we are on a mission to help build a better Internet. Today the company runs one of the world's largest networks that powers millions of websites and other Internet properties for customers ranging from individual bloggers to SMBs to Fortune 500 companies. Cloudflare protects and accelerates any Internet application online without...


  • Remote, Oregon, United States MetLife Full time

    Description and RequirementsIDI Senior Claim Specialist Work Location: Virtual Tampa, FL hires will be training IN OFFICE. Role Value Proposition: At MetLife, we seek to make a meaningful impact in the lives of our customers and our communities. The IDI Senior Claims Specialist evaluates individual disability income insurance claims and makes claims...


  • Remote, Oregon, United States Green Dot Corporation Full time

    We're looking for talented professionals, anywhere in the United States, to join us in bringing smart money management and payment solutions to everyone's fingertips.At Green Dot, we are evolving to a new and permanent "Work from Anywhere" model designed to maximize the benefits of remote work, promote and enable a strong culture of performance and...


  • Remote, Oregon, United States FiscalNote Full time

    About the PositionFiscalNote's Business Development team is seeking an experienced Senior Account Executive to drive growth in the supply chain and operational risk markets with our transformative alternative data offerings. Your expertise will be critical in packaging our data solutions and navigating the entire sales process—from initial outreach to...