About this role
This role involves supporting cybersecurity governance activities, assessing third-party security standards, and ensuring compliance with industry frameworks.
Key Responsibilities
- Apply frameworks to third-party entities
- Perform risk-based analysis
- Assess risks using NIST and ISO
- Review compliance documentation
- Conduct information system risk assessments
Technical Overview
The position requires knowledge of ISO 27001, SOC2, NIST, risk assessment methodologies, and security compliance processes.
Ideal Candidate
The ideal candidate is a cybersecurity governance analyst with experience in ISO 27001, SOC2, and NIST frameworks. They possess strong risk assessment skills, knowledge of security standards, and the ability to communicate complex risks effectively.
Must-Have Skills
Cyber Security Governancerisk assessmentISO 27001SOC2NISTISOsecurity frameworkscompliance documentationrisk management
Nice-to-Have Skills
experience in cybersecurity governanceoperating system knowledgemulti-taskingadaptabilityheavy ticket volume handlingconfidentiality principlesintegrity principlesavailability principleslaws and regulations knowledge
Tools & Platforms
NISTISOSOC2
Required Skills
ISO 27001SOC2NISTrisk assessmentsecurity frameworkscompliance documentationrisk managementinformation system risk assessmentsconfidentialityintegrityavailability principlesauthenticationauthorizationaccess controllaws and regulations
Hard Skills
ISO 27001SOC2NISTISOCyber Security FrameworksRisk Management Frameworksrisk assessmentsecurity risksverification of standards and controlsassessmentrisk analysisrisk mitigationinformation system risk assessmentscompliance documentationsystem accreditationconfidentialityintegrityavailability principlesauthenticationauthorizationaccess controllaws and regulations
Soft Skills
organizationinterpersonal skillscommunicationteam collaborationproblem-solving
Certifications
Required
ISO 27001SOC2NIST
Keywords for Your Resume
Cyber Security GovernanceISO 27001SOC2NISTRisk Management Frameworksrisk assessmentsecurity riskscompliance documentationsystem accreditationconfidentialityintegrityavailability principlesauthenticationauthorizationaccess controllaws and regulationssecurity frameworkscompliancerisk managementinformation system risk assessmentsverification of standards
Deal Breakers
Lack of experience with ISO 27001, SOC2, or NIST, No cybersecurity governance background, Inability to communicate risk assessments
Get matched to jobs like this
Luna finds roles that fit your skills and career goals — no endless scrolling required.
Create a Free Profile