Sunrise Systems Inc logo

Cyber Security Analyst 2

Sunrise Systems Inc

  • SAN JOSE, CA
  • 5 days ago

    Highlights

    Administer risk-based vendor questionnaires covering security governance, data protection, access control, vulnerability management, incident response, business continuity, cloud services, and subcontractor oversight; review responses and supporting evidence, clarify gaps with vendors, and translate findings into risk ratings and remediation actions. •Perform technical risk analysis by reviewing system architecture, data flows, cloud and network configurations, identity and access models, encryption, logging, vulnerability results, penetration-test findings, software dependencies, and incident-response capabilities; distinguish design intent from operating effectiveness and document evidence-based conclusions.

    Numbers & Facts

    LocationSAN JOSE, CA
    IndustryStaffing/Employment Agencies
    Company Size100 to 499 employees
    Year Founded1990
    Websitehttp://www.sunrisesys.com/

    Description

    Cyber Security Analyst 2 (GRC Risk Management Analyst)
    12 Months
    San Jose, CA / Austin, TX Hybrid

    Must be able to commute to San Jose, CA or Austin, TX and work on-site at least 3 days per week


    Description: We are seeking a detail-oriented GRC Risk Management Analyst to support information security and third-party risk management. The role combines structured governance and risk analysis with hands-on technical understanding to evaluate vendors throughout the relationship lifecycle—from onboarding and due diligence through ongoing monitoring and offboarding. The analyst will examine architectures, security controls, configurations, technical evidence, and threat scenarios to identify control gaps, determine business impact, document defensible risk decisions, and support practical remediation. The role will also apply analytics, automation, and AI responsibly to streamline evidence review, improve assessment quality, and accelerate monitoring and reporting while maintaining human validation, data protection, traceability, and appropriate governance.
    ________________________________________
    Key Responsibilities
    •Conduct end-to-end third-party risk assessments, including due diligence, inherent-risk tiering, control evaluation, residual-risk determination, periodic reassessment, and offboarding review
    •Administer risk-based vendor questionnaires covering security governance, data protection, access control, vulnerability management, incident response, business continuity, cloud services, and subcontractor oversight; review responses and supporting evidence, clarify gaps with vendors, and translate findings into risk ratings and remediation actions
    •Maintain enterprise and vendor risk registers with clear risk statements, ratings, owners, treatment plans, and status
    •Analyze security, privacy, resilience, regulatory, concentration, and fourth-party risks based on business criticality and data sensitivity
    •Perform technical risk analysis by reviewing system architecture, data flows, cloud and network configurations, identity and access models, encryption, logging, vulnerability results, penetration-test findings, software dependencies, and incident-response capabilities; distinguish design intent from operating effectiveness and document evidence-based conclusions
    •Apply hands-on security knowledge to validate control implementation through practical review of technical artifacts, targeted demonstrations, sample-based testing, and collaboration with engineers and system owners; translate technical weaknesses and threat scenarios into clear likelihood, impact, residual-risk, and remediation recommendations
    •Partner with Security, IT, Legal, Privacy, Procurement, and business owners to validate findings and drive proportionate mitigation
    •Track remediation, escalate material risks and exceptions, and prepare concise leadership reporting, including KRIs, trends, and heat maps
    •Support policy governance, control testing, issue management, compliance monitoring, and alignment with NIST, ISO 27001, CMMC, and applicable requirements
    •Design and use analytics, automation, and AI-assisted workflows to improve questionnaire triage, evidence extraction, control mapping, risk-statement drafting, issue classification, continuous monitoring, and reporting; measure process gains and maintain human approval, secure handling of sensitive data, output validation, auditability, and compliance with organizational AI governance requirements
    ________________________________________
    Required Qualifications
    •Education: Bachelor’s degree in Information Security, Risk Management, Business, Computer Science, or a related field
    •Experience: 1–4 years in enterprise risk, third-party risk, GRC, information security, or a related area
    •Knowledge of inherent and residual risk, likelihood and impact, controls, treatment, acceptance, and monitoring
    •Working technical knowledge of enterprise and cloud environments, including networking, operating systems, identity and access management, encryption, secure configuration, vulnerability management, logging and monitoring, application security, and incident response
    •Ability to interpret technical evidence such as architecture and data-flow diagrams, access reviews, configuration outputs, vulnerability and penetration-test reports, security logs, and independent assurance reports, and to identify when deeper technical validation is required
    •Ability to assess business impact, apply risk criteria, and communicate clear, defensible recommendations
    •Strong analytical, organizational, stakeholder-management, and written and verbal communication skills
    •Proficiency with Microsoft Office and familiarity with GRC, analytics, or automation tools
    •Practical experience using generative AI, scripting, workflow automation, or low-code tools to improve repeatable business processes, with an understanding of prompt design, output validation, sensitive-data handling, access controls, model limitations, and responsible human oversight
    ________________________________________
    Preferred Qualifications
    •Relevant certification or active pursuit, such as Security+ or an AI fundamentals credential
    •Experience with GRC platforms, vendor monitoring tools, audit support, or control evidence collection
    •Familiarity with NIST CSF, ISO 27001, CMMC, SOC 2, GDPR, CCPA, or similar requirements
    •Experience creating clear procedures, SOPs, or workflow documentation in a technology or regulated environment
     

    About Company

    Sunrise Systems was founded in 1990 with a clear vision to deliver world-class staffing service solutions in all labor categories, including IT consulting and solutions; all with the commitment to provide service that exceeds expectations and become the most trusted name in the industry. More than two and a half decades later, we pride ourselves on being at the forefront of the staffing industry. Combining our deep industry expertise, insights, and global resources, we have partnered with our clients to connect them with top professionals across several different industries.

    We provide cost-effective Managed Staffing Solutions, Information Technology and Information Technology Consulting Services to several Fortune 500 companies and U.S. Government agencies. We provide our clients with flexible engagement models and customized products that are budget and time specific. Understanding the challenges that every business faces, we offer our services either on-site at the clients' site or from one of our globally distributed technology centers. Our onshore and offshore development capabilities ensure that we excel at meeting customer requirements every single time.

    Our collective business experience spans over two and a half decades and ranges from:

    • Business, management, and technical fields
    • Information technology consulting and software solutions.
    • Providing strategic support for the development and long-term growth of new business ventures across several industries including but not limited to; accounting, banking, finance, and recruitment.
    • Motivating technology staff and establishing partnerships with Fortune 500 companies

    Sunrise Systems has a vast range of competence in:

    • Design, development, and support of cloud-based solutions from simple to highly complexed
    • Database administration of multi-platform applications, complex databases, and web-based environments that include all aspects of installation, planning, maintenance, and monitoring.
    • Data processing and data migration
    • Application re-engineering and platform migration
    • Working with the Information Systems and end-user communities at all levels to resolve issues and establish consensus.

    Similar Jobs

    See more jobs