Senior Analyst, Security Risk
TwilioRemote (Canada)2d ago
SecurityAnalystremotecurated-jd
Job description
Senior Analyst, Security Risk at Twilio
About the role
This position is integral to Twilio's One Twilio Risk Management program. You will enhance our security risk posture by identifying and addressing potential risks. The role involves close collaboration with Product and Engineering teams to map cyber risks across the company and ensure risk management practices align with regulatory requirements and industry standards.
Key facts
What you'll do
- Oversee and refine the daily operations of the risk management program, focusing on automating cyber risk processes.
- Maintain risk registers, monitoring key indicators and ensuring risks are properly documented, assessed, and managed.
- Partner with various departments to clearly communicate identified risks and their potential impacts.
- Evaluate the effectiveness of risk mitigation strategies and propose improvements.
- Create and present risk reports and dashboards to stakeholders, detailing trends, issues, and mitigation progress.
- Analyze risk data to identify patterns and forecast potential future risks.
- Utilize data analytics and risk modeling to assess the business, financial, operational, and security implications of risks.
- Develop custom reports and presentations to support risk-related decision-making.
- Liaise with internal and external auditors to support compliance checks and address any risk findings.
Requirements
- A minimum of 5 years of experience in risk management, with a focus on security-related frameworks and compliance.
- Proven experience in developing and implementing industry-accepted risk frameworks such as NIST Risk Management Framework, COSO Enterprise Risk Management, or ISO 31000.
- Demonstrated ability to collaborate effectively across different teams to establish strategic direction.
- Experience conducting qualitative and quantitative risk analyses to translate technical vulnerabilities into measurable business impacts.
- Skill in articulating vulnerabilities, control deficiencies, and systemic weaknesses into clear, actionable risk statements.
- A history of managing large-scale, complex risk assessments, registers, and compliance programs across multiple entities and functions, particularly in heavily regulated environments.
- Experience working with technical security and engineering teams to implement technical risk and control solutions, with the ability to interpret control requirements for diverse stakeholder groups.
- A proactive approach to using automation and tooling to scale program effectiveness.
- Experience applying AI to improve risk operations efficiency.
- Strong verbal, written, and interpersonal communication skills.
- Ability to manage multiple projects simultaneously under demanding timelines.
- Comfort with ambiguity and adaptability in rapidly changing environments.
- Strategic thinking and problem-solving capabilities, complemented by exceptional communication skills.
Nice to have
- A Bachelor's degree in Risk Management, Business, Finance, Cybersecurity, or a related field.
- Professional certifications such as CRISC, CISA, CISSP, or FRM.
- Advanced analytical and problem-solving skills, with the ability to interpret complex data and provide actionable insights.
- Proficiency in enterprise AI and GRC (Governance, Risk, and Compliance) tools.
- Experience with project management and cross-departmental collaboration.
Skills & tools
- Risk Management Frameworks (NIST RMF, COSO, ISO 31000)
- Risk Analysis (Qualitative and Quantitative)
- Risk Registers
- Key Risk Indicators (KRIs)
- Data Analytics
- Risk Modeling
- AI for Risk Operations
- GRC Tools
Practical notes
Occasional travel may be required for project or team meetings.