Victoria’s Secret & Co. · 2 days ago
Lead Cyber Risk Analyst
Maximize your interview chances
ApparelBeauty
No H1B
Insider Connection @Victoria’s Secret & Co.
Get 3x more responses when you reach out via email instead of LinkedIn.
Responsibilities
Develop, implement, and mature security risk management framework, including risk methodology (FAIR, FAIR-MAM, FAIR-CAM), risk analysis, and risk reporting.
Build relationships with other cybersecurity team members and technical teams to develop knowledge of VS&CO system environments, threat landscape, attack paths, and technical controls.
Build relationships with business partners to leverage key business metrics and business impacts in our risk analysis.
Develop risk scenarios that are meaningful to our stakeholders, both business and technical.
Establish, maintain, and mature security risk register.
Identify evolving risk scenarios for analysis.
Communicate cyber risk to stakeholders in timely fashion to inform decision making.
Peer review identified risks and analysis by other analysts.
Gather, analyze, and report status and metrics on risks.
Develop and mature risk management dashboards and reports to inform risk prioritization, risk remediation, and cyber leadership decision making.
Develop subject matter expertise in using our cyber risk quantification software and partner with our software vendor in the support of the platform.
Qualification
Find out how your skills align with this job's requirements. If anything seems off, you can easily click on the tags to select or unselect skills to reflect your actual expertise.
Required
5+ years of experience in information security, risk management and/or IT (Information Technology) audit fields.
Solid communication and cross-functional collaboration skills.
Strong analytical, research, and problem-solving skills.
Experience in qualitative and quantitative risk assessment.
Experience mentoring junior staff.
Experience leading meetings with cross functional teams to collect information.
Preferred
Bachelor’s Degree in Information Technology/Information Security/Mathematics/Business preferred.
Certifications preferred: FAIR fundamentals, FAIR analyst, CRISC