Cyber Security Analyst 2 # 26-19151

US Tech Solutions, Inc.

  • SAN JOSE, CA
  • Today

    Highlights

    The analyst will examine architectures, security controls, configurations, technical evidence, and threat scenarios to identify control gaps, determine business impact, document defensible risk decisions, and support practical remediation. The role will also apply analytics, automation, and AI responsibly to streamline evidence review, improve assessment quality, and accelerate monitoring and reporting while maintaining human validation, data protection, traceability, and appropriate governance.

    Numbers & Facts

    LocationSAN JOSE, CA

    Description

    Duration: 12 Months
    Summary:
    About the Role
    • We are seeking a detail-oriented GRC Risk Management Analyst to support information security and third-party risk management.
    • The role combines structured governance and risk analysis with hands-on technical understanding to evaluate vendors throughout the relationship lifecycle—from onboarding and due diligence through ongoing monitoring and offboarding.
    • The analyst will examine architectures, security controls, configurations, technical evidence, and threat scenarios to identify control gaps, determine business impact, document defensible risk decisions, and support practical remediation.
    • The role will also apply analytics, automation, and AI responsibly to streamline evidence review, improve assessment quality, and accelerate monitoring and reporting while maintaining human validation, data protection, traceability, and appropriate governance.
    Key Responsibilities
    • Conduct end-to-end third-party risk assessments, including due diligence, inherent-risk tiering, control evaluation, residual-risk determination, periodic reassessment, and offboarding review.
    • Administer risk-based vendor questionnaires covering:
      • Security governance
      • Data protection
      • Access control
      • Vulnerability management
      • Incident response
      • Business continuity
      • Cloud services
      • Subcontractor oversight
    • Review vendor responses and supporting evidence, clarify gaps with vendors, and translate findings into risk ratings and remediation actions.
    • Maintain enterprise and vendor risk registers with clear risk statements, ratings, owners, treatment plans, and status.
    • Analyze security, privacy, resilience, regulatory, concentration, and fourth-party risks based on business criticality and data sensitivity.
    • Perform technical risk analysis by reviewing:
      • System architecture
      • Data flows
      • Cloud and network configurations
      • Identity and access models
      • Encryption
      • Logging
      • Vulnerability results
      • Penetration-test findings
      • Software dependencies
      • Incident-response capabilities
    • Distinguish design intent from operating effectiveness and document evidence-based conclusions.
    • Apply hands-on security knowledge to validate control implementation through practical review of technical artifacts, targeted demonstrations, sample-based testing, and collaboration with engineers and system owners.
    • Translate technical weaknesses and threat scenarios into clear likelihood, impact, residual-risk, and remediation recommendations.
    • Partner with Security, IT, Legal, Privacy, Procurement, and business owners to validate findings and drive proportionate mitigation.
    • Track remediation, escalate material risks and exceptions, and prepare concise leadership reporting, including:
      • Key Risk Indicators (KRIs)
      • Trends
      • Heat maps
    • Support policy governance, control testing, issue management, compliance monitoring, and alignment with NIST, ISO 27001, CMMC, and applicable requirements.
    • Design and use analytics, automation, and AI-assisted workflows to improve:
      • Questionnaire triage
      • Evidence extraction
      • Control mapping
      • Risk-statement drafting
      • Issue classification
      • Continuous monitoring
      • Reporting
    • Measure process gains and maintain:
      • Human approval
      • Secure handling of sensitive data
      • Output validation
      • Auditability
      • Compliance with organizational AI governance requirements
    Required Qualifications
     
    Education
    • Bachelor’s degree in Information Security, Risk Management, Business, Computer Science, or a related field.
    Experience
    • 1–4 years of experience in enterprise risk, third-party risk, GRC, information security, or a related area.
    Knowledge and Technical Skills
    • Knowledge of:
      • Inherent and residual risk
      • Likelihood and impact
      • Controls
      • Risk treatment
      • Risk acceptance
      • Risk monitoring
    • Working technical knowledge of enterprise and cloud environments, including:
      • Networking
      • Operating systems
      • Identity and access management
      • Encryption
      • Secure configuration
      • Vulnerability management
      • Logging and monitoring
      • Application security
      • Incident response
    • Ability to interpret technical evidence, including:
      • Architecture and data-flow diagrams
      • Access reviews
      • Configuration outputs
      • Vulnerability reports
      • Penetration-test reports
      • Security logs
      • Independent assurance reports
    • Ability to identify when deeper technical validation is required.
    • Ability to assess business impact, apply risk criteria, and communicate clear, defensible recommendations.
    • Strong analytical, organizational, stakeholder-management, written, and verbal communication skills.
    • Proficiency with Microsoft Office and familiarity with GRC, analytics, or automation tools.
    • Practical experience using generative AI, scripting, workflow automation, or low-code tools to improve repeatable business processes.
    • Understanding of:
      • Prompt design
      • Output validation
      • Sensitive-data handling
      • Access controls
      • Model limitations
      • Responsible human oversight
    Work Location
    • Must be able to commute to San Jose, CA, or Austin, TX and work on-site at least 3 days per week.
    Preferred Qualifications
    • Relevant certification or active pursuit of a certification, such as:
      • Security+
      • An AI fundamentals credential
    • Experience with:
      • GRC platforms
      • Vendor monitoring tools
      • Audit support
      • Control evidence collection
    • Familiarity with:
      • NIST Cybersecurity Framework (CSF)
      • ISO 27001
      • CMMC
      • SOC 2
      • GDPR
      • CCPA
      • Similar requirements
    • Experience creating clear procedures, Standard Operating Procedures (SOPs), or workflow documentation in a technology or regulated environment. 
     
    About US Tech Solutions:
    US Tech Solutions is a global staff augmentation firm providing a wide range of talent on-demand and total workforce solutions. To know more about US Tech Solutions, please visit www.ustechsolutions.com.

    US Tech Solutions is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, colour, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran.

    AI Statement: By applying, you acknowledge that AI-assisted tools may be used during hiring.

    #LI-AS140

    Similar Jobs

    New!

    Cyber Security Analyst 2 CYNET SYSTEMS

    San Jose, CA5 days ago
    • $68–$72 Per Hour
    • Temporary
    • Contractor
    • Part-time
    See more jobs