Cyber Security Analyst 2
Sunrise Systems
Cyber Security Analyst 2 (GRC Risk Management Analyst) 12 Months San Jose, CA / Austin, TX Hybrid
We are seeking a detail-oriented GRC Risk Management Analyst to support information security and third-party risk management. The role combines structured governance and risk analysis with hands-on technical understanding to evaluate vendors throughout the relationship lifecycle—from onboarding and due diligence through ongoing monitoring and offboarding. The analyst will examine architectures, security controls, configurations, technical evidence, and threat scenarios to identify control gaps, determine business impact, document defensible risk decisions, and support practical remediation. The role will also apply analytics, automation, and AI responsibly to streamline evidence review, improve assessment quality, and accelerate monitoring and reporting while maintaining human validation, data protection, traceability, and appropriate governance.
Key Responsibilities
•Conduct end-to-end third-party risk assessments, including due diligence, inherent-risk tiering, control evaluation, residual-risk determination, periodic reassessment, and offboarding review
•Administer risk-based vendor questionnaires covering security governance, data protection, access control, vulnerability management, incident response, business continuity, cloud services, and subcontractor oversight; review responses and supporting evidence, clarify gaps with vendors, and translate findings into risk ratings and remediation actions
•Maintain enterprise and vendor risk registers with clear risk statements, ratings, owners, treatment plans, and status
•Analyze security, privacy, resilience, regulatory, concentration, and fourth-party risks based on business criticality and data sensitivity
•Perform technical risk analysis by reviewing system architecture, data flows, cloud and network configurations, identity and access models, encryption, logging, vulnerability results, penetration-test findings, software dependencies, and incident-response capabilities; distinguish design intent from operating effectiveness and document evidence-based conclusions
•Apply hands-on security knowledge to validate control implementation through practical review of technical artifacts, targeted demonstrations, sample-based testing, and collaboration with engineers and system owners; translate technical weaknesses and threat scenarios into clear likelihood, impact, residual-risk, and remediation recommendations
•Partner with Security, IT, Legal, Privacy, Procurement, and business owners to validate findings and drive proportionate mitigation
•Track remediation, escalate material risks and exceptions, and prepare concise leadership reporting, including KRIs, trends, and heat maps
•Support policy governance, control testing, issue management, compliance monitoring, and alignment with NIST, ISO 27001, CMMC, and applicable requirements
•Design and use analytics, automation, and AI-assisted workflows to improve questionnaire triage, evidence extraction, control mapping, risk-statement drafting, issue classification, continuous monitoring, and reporting; measure process gains and maintain human approval, secure handling of sensitive data, output validation, auditability, and compliance with organizational AI governance requirements
Required Qualifications
•Education: Bachelor's degree in Information Security, Risk Management, Business, Computer Science, or a related field
•Experience: 1–4 years in enterprise risk, third-party risk, GRC, information security, or a related area
•Knowledge of inherent and residual risk, likelihood and impact, controls, treatment, acceptance, and monitoring
•Working technical knowledge of enterprise and cloud environments, including networking, operating systems, identity and access management, encryption, secure configuration, vulnerability management, logging and monitoring, application security, and incident response
•Ability to interpret technical evidence such as architecture and data-flow diagrams, access reviews, configuration outputs, vulnerability and penetration-test reports, security logs, and independent assurance reports, and to identify when deeper technical validation is required
•Ability to assess business impact, apply risk criteria, and communicate clear, defensible recommendations
•Strong analytical, organizational, stakeholder-management, and written and verbal communication skills
•Proficiency with Microsoft Office and familiarity with GRC, analytics, or automation tools
•Practical experience using generative AI, scripting, workflow automation, or low-code tools to improve repeatable business processes, with an understanding of prompt design, output validation, sensitive-data handling, access controls, model limitations, and responsible human oversight
Preferred Qualifications
•Relevant certification or active pursuit, such as Security+ or an AI fundamentals credential
•Experience with GRC platforms, vendor monitoring tools, audit support, or control evidence collection
•Familiarity with NIST CSF, ISO 27001, CMMC, SOC 2, GDPR, CCPA, or similar requirements
•Experience creating clear procedures, SOPs, or workflow documentation in a technology or regulated environment
- ...motivated candidate to join our talented Team. Job Title: IT Auditor 2 Location: Austin, TX Job Description: Office of Court... ...Candidate(s), who meets the general qualifications of IT Auditor 2, Security and the specifications outlined in this document for the Office...SuggestedContract workWork at office
- Cybersecurity Analyst - Tier 2 (3rd shift) Maveris is an IT and cybersecurity services company committed... ...to helping organizations create secure digital solutions to accelerate their mission... ...assets and responding to potential cyber threats. Your primary focus will be supporting...SuggestedPermanent employmentFull timeWork experience placementNight shift
- ...Position: Network Engineer 2 Location: will be at 4000 Jackson Avenue, Austin, Texas 78731 Duration: 6 Months WORKER SKILLS AND QUALIFICATIONS Minimum Requirements: Years Skills/Experience 5 Active Directory architect...Suggested
- ...Intelligence®. We design, build, operate, and maintain cyber-physical solutions for the nation’s most mission-critical facilities, secure environments, complex infrastructure, and... ...industries.We are seeking an Engineer 2 to join our Security and Electronic Systems (...SuggestedFor contractorsWork at officeLocal area
- ...maritime operations through autonomous and intelligent platforms.Security at Saronic is a force multiplier, not a blocker. We’re looking for... ...are considered to be a “U.S. Person”: (1) U.S. citizens, (2) legal permanent residents (a.k.a. green card holders), and (3)...SuggestedPermanent employment
$159.3k - $202.4k
...vast and varied as Amazon's requires the applied skills of smart security engineers and experienced, innovative security leaders willing to... ...Security Engineer on the STRIKE team, you will:• Conduct time-bound (2-4 month) targeted security engagements with business units...Flexible hours$159.3k - $202.4k
Cloud security is our highest priority at AWS. As an AWS customer, you benefit from an environment built to meet the requirements of the most... ...Supply Chain Security experiencePreferred qualification - 2+ years of any combination of the following: threat modeling experience...Remote workFlexible hours$136k - $184k
The AWS Hardware Supply Chain Security (HSCS) Team is looking for a Security Engineer to help guide our global hardware supplier and manufacturing... ...at home, there’s nothing we can’t achieve.Basic qualifications- 2+ years of web protocols, common security attacks, and...InternshipFlexible hoursShift work$159.3k - $202.4k
Amazon Healthcare Security's (HealthSec) Security Operations team is hiring a Security Engineer to be the first line of defense to our most... ...at home, there’s nothing we can’t achieve.Basic qualifications- 2+ years of programming in Python, Ruby, Go, Swift, Java, .Net, C++...Flexible hours$82.6k - $162.8k
Position Summary Join our Deloitte Cyber team to deliver powerful solutions to help... ...confidence, and proactively manage to secure success. Identity security market is undergoing... ...cloud environments.QualificationsRequired:2+ years of experience in identity and...Local areaVisa sponsorship$120k - $202.5k
...are looking for an Enterprise Integration Security Architect. You will be responsible for designing... ...enterprise technology solutions, reducing cyber risk while enabling business innovation... ...authorization frameworks including OAuth 2.0, OpenID Connect, SAML, JWT, mTLS, and...Full timeTemporary workFlexible hoursShift work- ...Cybersecurity organization protects the company’s global operations through secure, scalable solutions that enable innovation. Within Security... ...authentication and authorization patterns including SAML, OAuth 2.0, and OpenID ConnectEstablish scalable standards for identity...Full timeLocal areaWork from homeRelocation package
- Position Summary Analyst, Cyber Strategy & TransformationOur Deloitte Cyber team understands... ....Enhance application, cloud, and IoT security; manage vulnerabilities.Support cyber... ...Enterprise Technology Strategy and TransformationSame job available in 2 locationsVisa sponsorship
$122.57k - $204.25k
...foundational to everything we do. Offensive Security is a top area of investment within... ...capabilities.Job OverviewAs a member of the Cyber Security team, the Senior Penetration Tester... ..., servicing and custodying approximately $2.3 trillion in brokerage and advisory assets...Full timeWork from home$97.61k - $188.38k
Position Summary Our Deloitte Cyber team understands the unique challenges and opportunities... ...confidence, and proactively manage to secure success.Recruiting for this role ends on 1... ..., or architecting information systems.2+ years of experience with technical...Local areaVisa sponsorship$82.6k - $162.8k
..., and artificial intelligence, Deloitte’s Cyber Defense & Resilience team offers the scale... ...will support organizations as they modernize security operations through advanced analytics,... ...operational experience.QualificationsRequired:2+ years of analytics consulting or...Local areaVisa sponsorship- Position Summary The Chief Information Security Officer (CISO) owns enterprise security strategy... ...security, AI security, and all associated cyber or cyber adjacent incident response.Set... ...the company’s compliance posture across SOC 2 Type II, ISO 27001, Cyber Essentials Plus...Work at officeLocal areaWorldwide
$118.7k - $218.6k
Position Summary Cyber Data Protection and PKI Specialist - Senior ConsultantOur Deloitte... ...confidence, and proactively manage to secure success.Recruiting for this role ends on 1... ...own key (BYOK), server-side encryption.2+ years of professional experience developing...Work experience placementLocal areaVisa sponsorship$159.3k - $202.4k
Help us protect not only the Amazon Security (AmSec) cloud computing environment but all of our customers as well! Since 2006, our great team... ..., supporting engineering projects from concept to delivery, and 2 years in two or more of the following technical categories:)-...Flexible hours- ...meet you. About the Role Hippo is hiring a Chief Information Security Officer to lead cybersecurity strategy, security operations, and... ...and compliance across the enterprise. This role owns Hippo’s SOC 2 program, leads security operations, and drives compliance with...Temporary workFlexible hours
- ...candidate to join our talented Team. Job title: Developer/Programmer Analyst 3 Location: Austin, TX DESCRIPTION OF SERVICES:Client... ...Bitbucket for version control.5 Years Required: Nomad and Consul.2 Years Required: .NET 8.0/9.0 framework, C#, Visual Studio.5 Years...
- ...seeking an Associate Application Support Analyst to provide technical support to external customers... ...modifications• Ensure compliance with security, availability, confidentiality, and... ...relevant field or equivalent experience (0-2 years); advanced degree holders may apply...Full timeBank staffLocal areaRemote workWork visaShift work
- ...term system roadmaps.Ensure solution designs, integration patterns, security standards, cloud strategies, and technical best practices are... ...reports, and executive-level presentations.Ensure compliance with WCAG 2.1 accessibility standards.Support audits, security reviews,...
- ...architectures spanning business, application, integration, data, technology, security, and operating-model considerations. * Shape integrated solution... ...process. Please advise the talent acquisition team or contact [2] ****@*****.*** if you require accommodations...Temporary workLocal area
- ...application architecture decisions, and partners across engineering, security, and business teams to ensure solutions are consistent,... ...frequently. (Frequently: activity or condition exists from 1/3 to 2/3 of the time) to lift, carry, push, pull or otherwise move objects...Full timeWork experience placement
$128k - $252.5k
...domain. • Bachelor’s degree. • 4+ years consulting or industry experience; alternatively, Master of Business Administration (MBA) and 2+ years of consulting or industry experience. • Ability to travel up to 50%, on average, based on the work you do and the clients and...Local areaVisa sponsorshipFlexible hours- ...across enterprises, governments, and consumers. Fueled by decades of security expertise, global threat research, and continuous innovation,... ...security starts here. TrendMicro.com Location: Austin, TX — Hybrid (2 days/week in office) TrendAI is hiring a Threat News Monitoring...Temporary workH1bWork at officeFlexible hours2 days per week
- ...enterprise cloud and infrastructure architecture to enable scalable, secure, and cost-effective technology platforms across the organization.... ..., regulatory, and compliance requirements (e.g., SOC 2, ISO, FedRAMP where applicable)Identify and mitigate enterprise-...Full timeWork experience placement
- ...motivated candidate to join our talented Team.Job Title: Systems Analyst 1Location(s): Austin, TX Level Description 1-3 years of experience... ...to automate processing or to improve existing computer systems.2 Required Ability to write detailed description of user needs,...
- ...Trinnex is seeking a Senior Cyber Security Analyst to join their Security Team in Austin, Texas. In this role, you will help secure essential software systems for water utilities by embedding security controls and managing vulnerabilities. You will closely collaborate...
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Cyber Security Analyst 2. Be the first to apply!
- information security consultant Austin, TX
- entry level cyber security analyst Austin, TX
- remote cyber security analyst Austin, TX
- cyber security analyst Austin, TX
- cyber Austin, TX
- cyber insurance Austin, TX
- cyber sales Austin, TX
- cyber security technician Austin, TX
- cyber security lead Austin, TX
- remote cyber security Austin, TX


