Cyber Risk Analyst
Sun King
Cyber Risk Analyst
We are looking for a Cyber Risk Analyst to strengthen our governance, risk, and compliance posture across the organization. In this role, the Cyber Risk Analyst will drive cyber security audits, vendor security reviews, business continuity (BCP/DR) drills, and security awareness initiatives, while supporting the implementation of frameworks such as NIST Cybersecurity Framework (CSF) and ISO 27001 ISMS. This role is ideal for someone who enjoys working cross-functionally, can communicate clearly with both technical and non-technical stakeholders, and is comfortable working remotely with high ownership and accountability.
What you will be expected to do:
Cyber Security Audits & Assessments (30%)
- Plan and execute internal cyber security audits and control reviews across applications, infrastructure, and business processes.
- Document findings, assess risk and impact, and track remediation through closure with respective teams.
Vendor and Third-party Security Reviews (30%)
- Conduct security due diligence for vendors and third parties: review security questionnaires, certifications, and technical controls to ensure they meet organizational requirements.
- Identify and track vendor risks, recommend mitigation measures, and support contractual security requirements where needed.
Business Continuity and BCP/DR drills (25%)
- Work with stakeholders to maintain and test business continuity and disaster recovery (BCP/DR) plans.
- Plan, coordinate, and document tabletop exercises and technical BCP/DR drills, track and follow up on corrective actions.
Cyber Governance and Risk Management (10%)
- Maintain up-to-date security policies, standards, procedures, and guidelines, ensuring alignment with NIST CSF, ISO 27001, and relevant regulations.
- Prepare regular reports and dashboards on audit findings, risk status, BCP drill outcomes, vendor risk posture, and ISMS/NIST CSF progress for management.
- Maintain and update the cyber risk register, working with control owners and business stakeholders to identify, assess, and prioritize risks.
- Perform risk assessments (likelihood/impact), propose risk treatment options (mitigate, accept, transfer, avoid), and track treatment plans to closure.
Cyber Security Awareness & Training (5%)
- Develop and deliver cyber security awareness sessions and targeted training for employees, including phishing awareness, secure handling of data, and role-based security topics.
- Create clear, engaging communication materials (presentations, FAQs, quick guides) to improve security culture.
You might be a strong candidate if you have/are:
- Bachelor's degree in any engineering discipline.
- At least 3 years of experience in cyber governance, risk and compliance domain.
- Experience in implementing security controls and processes across business functions adhering to NIST CSF, ISO 27001 standards.
- Practical experience into at least 70% of the above-mentioned responsibilities.
- Exposure to industry standards and regulations (e.g., SOC 2, ISO 27001, GDPR/DPDP etc.).
- Security certifications such as CISA, ISO 27001 Lead Implementer / Lead Auditor is preferred.
- AI-governance or AI-risk credentials such as ISO/IEC 42001 training, NIST AI RMF Architect/Lead Implementer, or recognized AI Security & Governance certifications is a strong plus.
- Good communication and interpersonal skills, with the ability to engage effectively with diverse stakeholders.
What Sun King offers:
- Professional growth in a dynamic, rapidly expanding, high-social-impact industry
- An open-minded, collaborative culture made up of enthusiastic colleagues who are driven by the challenge of innovation towards profound impact on people and the planet.
- A truly multicultural experience: You will have the chance to work with and learn from people from different geographies, nationalities, and backgrounds.
- Structured, tailored learning and development programs that help you become a better leader, manager, and professional through the Sun King Center for Leadership.
About Sun King:
Sun King is the world's leading off-grid solar energy company, combining cutting-edge product design, fintech, and field operations to deliver energy access for the 1.8 billion people who live without an affordable and reliable electric-grid connection. Sun King has built a new kind of energy utility: distributed, green, customer-centric, and affordable. We bring clean, reliable, decentralized energy directly into people's lives — from solar kits that provide first-time energy access to multi-kilowatt systems that serve both off-grid users and grid-connected customers powering larger homes, schools, hospitals, farms, offices, and light manufacturing. Already, 25 million homes and businesses rely on Sun King for electricity supply and the appliances and services it enables: lighting, televisions, fans, refrigeration, and smartphones. Sun King combines energy generation, energy-efficient appliances, installation, and financing into one seamless offering. Think of it as a distributed utility, designed for wherever energy is needed and designed to scale with its users as incomes and energy needs grow. Sun King makes solar products affordable to low-income households and businesses via 'pay-as-you-go' (PAYG) purchase financing. Sun King installs solar after customers pay a small deposit. Customers then make small, manageable payments of as little as US $0.14 a day via mobile money or cash. Instead of paying for expensive, polluting, and health-damaging kerosene for lighting or diesel for power, customers unlock savings through accessing solar power and after one to two years of payments, customers own their solar equipment outright. Sun King collects payments digitally through mobile money systems and its 35,000 field agents — over 1 million payments each day. To date, Sun King has extended more than $1.4 billion in PAYG loans to customers. Sun King began by powering homes and businesses with solar systems delivered through PAYG financing. Now, we're using the same model to make smartphones and clean cooking equipment affordable: helping households connect to the digital economy and transition from wood-based fuels to modern, sustainable alternatives. Sun King employs 3,500 full-time staff in 14 countries, with specialties spanning product design, data science, logistics, customer service, sales, software, operations, and more — all with a passion to serve off-grid families. Sun King is committed to gender diversity in the workplace. Women represent 42% of Sun King's workforce. Apply Now
- A cybersecurity company is seeking a Cyber Risk Analyst to identify and prioritize vulnerabilities in their systems. This full-time role requires proficiency in vulnerability assessment tools and a strong understanding of cybersecurity frameworks. The candidate will conduct...SuggestedFull timeRemote work
- ...Job Title: Cyber Risk Analyst Location: CINCINNATI preferred, remote in EST Payrate: $35/hr on W2 Top Skills Risk management, specifically cyber risk. At least some experience in a cyber role. Good communication skills - written and verbal, ability to work with all different...SuggestedRemote work
$40 - $45 per hour
...A cybersecurity firm is seeking an entry-level Cyber Risk Analyst to join their team in Columbus, OH. This hybrid role requires on-site work twice a week and offers a contract duration of one year. Responsibilities include assisting in cyber risk assessments, implementing...SuggestedHourly payContract work- ...Supporting the execution of Alpaca's cybersecurity risk management program, the full-time remote Cyber & AI Risk Analyst will assess cybersecurity and AI-related risks, develop governance controls, and collaborate with cross-functional teams to enhance security and compliance...SuggestedFull timeRemote work
- Title: Cyber Risk Analyst Location: Columbus, OH (Hybrid: On-site twice a week) Contract Type: W2 (Must be authorized to work in the U.S.; No sponsorships, No F1-OPTs, No C2C, No 1099) Contract Duration: 1 Year (Contract to Hire) Rate: $40 - $45/hr with 401k Benefits...SuggestedContract workInternshipWork at officeLocal area2 days per week
- Job Description A premier healthcare system in Houston, Texas is looking to add a Senior Cyber Risk Analyst to their team. This person will be joining a team of 4 analysts. This team is working on 20-25 risk assessments at any given time and they split the assessments...Work at office
- Travelers is hiring a Cybersecurity Technologist in Hartford, Connecticut. You will engage with third parties to assess cybersecurity risks and provide operational support for security processes. The ideal candidate will have a Bachelor's Degree in a STEM field, five...
- ...HHS webpage. Functional Title: Cybersecurity Governance & Risk Analyst Job Title: Cybersecurity Analyst III Agency: Health & Human Services... ...agency leave policy and performs other duties as assigned. Cyber Governance - 30% Performs reviews and risk management for...Permanent employmentFull timeContract workTemporary workPart timeWork at officeRemote workShift workDay shift
$69.3k - $158k
Cybersecurity Engineer and Risk Analyst The Opportunity: Are you looking for an opportunity to advance your experience in cybersecurity... ...Navy missions by championing cybersecurity, discovering cyber risks, and providing hands-on support to critical mission areas...Full timeContract workPart timeWork at officeLocal areaRemote work- A recruiting firm specializing in Cyber Security is seeking a Cyber Security Analyst to identify and mitigate risks to their clients' products and services. This role involves working closely with a team to maintain compliance with regulatory standards while ensuring the...
$80k - $100k
...Kearney & Company is seeking a skilled and vigilant Cybersecurity Risk Analyst to join our dynamic team. The Cybersecurity Risk Analyst is... ...management, auditing, or related fields. Understanding of cyber threats, vulnerabilities, cloud security, identity and access...Local areaFlexible hours- ...Preference will be given to candidates with prior experience in the Financial Services Industry . Position Summary The Information Risk Analyst/Cybersecurity Risk Analyst will be responsible for developing risk assessment questionnaires, conducting risk assessments for...
- ...Cybersecurity Risk and Controls Analyst 1 Beusa The Woodlands Corporate Office - The Woodlands, TX 77380 Overview Level: Experienced Position Type: Full Time Job Shift: Day Education Level: 4 Year Degree Travel Percentage: up to 10% Description Cybersecurity...Full timeWork at officeRemote workMonday to FridayShift workWeekend workAfternoon shiftEarly shift
$100k - $150k
...Position is contingent upon contract award Cybersecurity Risk Analyst Salary Range: $100,000 – $150,000 Clearance: TS/SCI + CI Poly Location... ...Risk Analyst to support enterprise cybersecurity and cyber defense operations in the Washington, D.C. metropolitan area....Full timeContract work$87k - $104k
...detect, contain, and respond to threats quickly. Responsibilities Support a Technology Vendor Management program, ensuring technology risk reviews across multiple disciplines and monitoring renewals and savings opportunities. Participate in risk reviews of the IT control...Work at officeLocal area- ...Phase2 Technology in Arlington, Virginia is looking for an experienced information security risk specialist to mitigate complex cybersecurity threats. This role requires collaboration with stakeholders to assess cybersecurity postures, leveraging eMASS and RMF for effective...Remote work
$62k - $141k
The Opportunity:Cyber threats are everywhere, and the constantly evolving nature of these threats can make understanding them seem overwhelming... ...“cyber noise,” how can these organizations understand their risks and how to mitigate them? The answer is you. We need your...Full timeContract workPart timeWork at officeLocal areaRemote work- ...Providing advanced Governance, Risk, and Compliance (GRC) support, the full-time Cybersecurity Risk Management Analyst will manage Assessment & Authorization (A&A) activities, conduct cybersecurity risk assessments, and ensure compliance with federal cybersecurity requirements...Full timeRemote work
- ...As a Cyber & AI Risk Analyst , you will play a critical role in strengthening Alpaca’s security, compliance, and AI risk posture across the organization. Working closely with the Cyber GRC Lead , you will support the identification, assessment, and documentation of...Full timeInternshipRemote work
$500 per month
...Have Empathy, and Be Accountable—and are ready to make a significant impact, we encourage you to apply. Your Role: As a Cyber & AI Risk Analyst, you will play a critical role in strengthening Alpaca's security, compliance, and AI risk posture across the organization....InternshipRemote workHome office- A leading financial services company in Cincinnati seeks a Cybersecurity Governance Analyst III to support compliance requirements for its Cybersecurity Program. The role includes facilitating governance committee meetings, developing cybersecurity metrics, and assisting...
$62k - $141k
Job Number: R0242703 Cybersecurity Risk Analyst The Opportunity Cyber threats are everywhere, and the constantly evolving nature of these threats can make understanding them seem overwhelming to the global enterprise. In all of this "cyber noise," how can these organizations...Contract workLocal area$67 - $70 per hour
Overview Job Number: 26-01087 ECLARO is looking for a Cybersecurity Risk Analyst for our client in Manassas, VA . ECLARO’s client is a leading... ...(TPRM) operations and supporting the organization’s broader Cyber Governance & Risk. The successful consultant will be the...Contract work$69.3k - $158k
Cybersecurity Engineer and Risk Analyst We are looking for an experienced cybersecurity and security engineer to safeguard our nation. As... ...impact Navy missions by championing cybersecurity, discovering cyber risks, and providing hands‑on support to critical mission...Local area$117k - $151k
...are proud to be an outlet for opportunity and for personal growth and success. Job Description The Senior Cyber Governance, Risk & Compliance Analyst is a senior level security professional whose primary responsibility is to design, operate, and continuously...Contract workCasual workFlexible hours$50k - $290k
A leading consulting firm is seeking a Network Evaluator to assess and improve operational networks in Annapolis Junction, MD. Candidates must evaluate vulnerabilities, recommend countermeasures, and support security solutions. A Bachelor’s degree with relevant experience...$57 per hour
Cybersecurity & Technology Risk Compliance Analyst (DTC1JP00003425) Location: Tampa or Coppell, TX (Coppell preferred) Experience level: Mid-senior... ...and has a thorough knowledge of technology controls (IT and cyber) including how they are executed in today’s IT threat...Hourly payVisa sponsorship- ...experience in security operations, vulnerability management, or risk analysis. Hands-on experience with industry vulnerability scanning... ...DC. Role and Responsibilities: The Risk and Vulnerability Analyst supports a 24x7 Security Operations Center (SOC) by identifying,...
$120k - $150k
...where you can learn and thrive, Brown Brothers Harriman is the right place for you. Join us as our Custody and Digital Assets Risk Analyst. BBH is seeking a risk professional to support the risk and governance oversight of traditional and digital asset servicing activities...Full timeWork experience placementLocal area$60k - $180k
...Risk and Vulnerability Analyst Remote - Secret clearance required M9 Solutions is dedicated to providing IT services and solutions to the Federal... ...include IT Talent Solutions, Data Delivery & Analytics, Cyber Security, Cloud Migration, Applications and Infrastructure...For subcontractorRemote work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Cyber Risk Analyst. Be the first to apply!
- information security consultant United States
- cyber security analyst internship United States
- cyber security operations analyst United States
- remote cyber security analyst United States
- entry level cyber security analyst United States
- cyber security analyst United States
- cyber security analyst no experience United States
- junior cyber security analyst United States
- market risk analyst United States
- risk consultant United States


