Risk management experience: previous experience working and reviewing cyber risk assessments
Familiarity with cyber security frameworks, such as, NIST-CSF
Experience with risk tools (administrative, power user, user)
Facilitate cyber risk communications, cyber risk lifecycle task completion and cyber risk aware decision making with technical and non-technical audiences
Key Responsibilities
CRA Responsibilities:
Managing cyber risk assessments
Evaluating internal operational controls for alignment to cyber risk treatment needs.
Analyzing, framing, and updating threat and risk scenarios for use in cyber risk management
Communicating cyber risk to Management and designated stakeholders.
Assess and update cyber risk appetites for LOB.
Evaluate cyber risk treatment options and facilitate communication to stakeholders.
Training employees on cyber risk aware and risk first culture.
Adjust cyber risk scores based on available controls and treatment options.
Create cyber risk dashboards/reports based on complex risk, process and control relationships.
Facilitate risk management oversight in supporting internal/external audits and regulatory exams.
CRA Requirements:
Prefer 5-10 years experience in governance, risk, and compliance
Job field related certification(s), CISSP/CISA/CRISC (preferred but not required)
Previous experience as a compliance analyst in a related field.
In-depth knowledge of industry compliance requirements and standards.
Proficiency in compliance management software, Archer, ServiceNow, MetricStream, etc.
Ability to accurately complete applications for compliance certification.
Ability to effectively train employees.
Exceptional communication and interpersonal skills.
Understanding of regulatory frameworks
Requirements analysis
Ability to develop standards to maintain legal compliance
Quality management
Critical thinking and problem-solving skills
Organization, project management, and strategic planning skills