Senior Security Risk Management Analyst
Job description
About the role
We are seeking a Senior Security Risk Management Analyst to join our team in Cork, Ireland. This role is centered on the evaluation and management of security risks within the organization, ensuring that all activities align with established compliance requirements. The successful hire will be responsible for contributing to the development and refinement of our security strategies based on detailed analysis. You will own the assessment of potential threats and vulnerabilities across the enterprise landscape. A key part of this position involves collaborating with diverse teams to design and execute risk mitigation plans effectively. The individual in this role will champion the enhancement of security protocols to protect organizational assets. You will translate complex risk data into actionable insights for leadership and technical partners. This position requires a proactive mindset dedicated to maintaining a robust security posture through continuous evaluation and improvement.
Key facts
What you'll do
- Conduct comprehensive evaluations of security risks across enterprise systems, applications, and operational processes to identify potential vulnerabilities.
- Partner with cross-functional stakeholders to design, implement, and monitor risk mitigation strategies that reduce exposure and align with business objectives.
- Author, update, and maintain detailed security policies, standards, and procedures to ensure they reflect current threats and regulatory expectations.
- Compile and synthesize complex risk data into clear, concise reports for executive and technical audiences, highlighting trends and recommended actions.
- Monitor the evolving threat landscape and regulatory environment to ensure organizational practices remain compliant and resilient.
- Perform quantitative and qualitative risk analyses using established frameworks to determine the potential impact and likelihood of identified threats.
- Facilitate workshops and working sessions with IT, security, and business units to validate risk assumptions and secure stakeholder buy-in.
- Track the effectiveness of implemented controls and adjust mitigation plans based on observed outcomes and new intelligence.
- Support the incident response team by providing risk context and guidance during security events or investigations.
- Promote a culture of security awareness by sharing knowledge and best practices related to risk management and data protection.
Requirements
- Hold a Bachelor's degree in Computer Science, Information Security, or a closely related technical field that provides a foundational understanding of IT systems and security principles.
- Bring a minimum of 5 years of hands-on experience in security risk management, audit, or a related role where you assessed and reported on organizational risk.
- Demonstrate a strong understanding of widely adopted security frameworks and compliance standards such as ISO 27001 and NIST, including how they apply in practical scenarios.
- Show proven proficiency in using risk assessment tools, methodologies, and frameworks such as FAIR, OCTAVE, or similar approaches to evaluate threats.
- Exhibit excellent analytical and problem-solving skills, with the ability to interpret complex data, identify root causes, and develop logical conclusions.
- Possess strong communication skills, both verbal and written, enabling you to explain technical risk concepts to non-technical stakeholders clearly.
- Have experience working in a regulated environment where documentation, audit readiness, and adherence to policies are critical to success.
- Display a high level of integrity and judgment when handling sensitive information and making decisions that impact organizational risk.
Nice to have
- Possess industry-recognized certifications such as CISSP, CISM, or CRISC that validate your expertise in security and risk management practices.
- Bring direct experience with cloud security architectures and data protection technologies used in modern cloud environments.
- Have familiarity with security incident response processes, including how risks are identified, assessed, and managed during and after incidents.
Skills & tools
- Experienced with risk assessment tools and platforms such as FAIR, OCTAVE, or other frameworks used to measure and track risk.
- Comfortable working with Security Information and Event Management (SIEM) systems to correlate data and identify potential security risks.
- Knowledge of major cloud platforms including AWS, Microsoft Azure, and Google Cloud, and how security and risk are managed within them.
- Familiarity with data encryption technologies, key management practices, and data protection mechanisms used to secure information at rest and in transit.
Practical notes
- Visa sponsorship is available for qualified candidates who meet the outlined requirements and demonstrate the necessary experience.
- A competitive salary and comprehensive benefits package are offered to align with your expertise and contributions.
- Applications will remain open until the position is filled, allowing for a thorough review of all qualified candidates.