Citizens Financial GroupNYSE: CFG: Provides retail, commercial, and private banking services to customers.
3+ YOEBachelor's in IT/Cybersecurity/Business required; 3+ years in IT/security/risk/internal audit; familiarity with control frameworks, GRC and ITSM tools; strong communication, analytical, and documentation skills.
Archer, ServiceNow, Jira, Microsoft Excel, Microsoft Word, Microsoft PowerPoint, AWS, Azure, NIST 800-53, NIST Cybersecurity Framework, CRI Profile, COBIT, ITIL
Washington or Boston or Dallas or Chicago or Miami or Denver or Orange or Los Angeles or Las Vegas or Sacramento or Phoenix or San Diego or United States
$130k-$160k/yrRemoteFull Time
DanaherNYSE: DHR: Develops scientific instruments and diagnostic tools for healthcare markets.
7+ YOE7+ years in third-party/vendor risk, enterprise risk, or vendor security; experience administering vendor questionnaires, reviewing SOC 2/ISO 27001 evidence, scoring at scale, reviewing cybersecurity contract provisions, and operating enterprise risk registers.
Principal Technology Risk Analyst - Program & Regulatory Assurance
Merrimack or Smithfield or Westlake
OnsiteFull Time
Fidelity Investments: Provides investment management, retirement planning, and brokerage services.
5+ YOE5+ years in IT risk, controls, or audit; experience documenting controls in large financial services environments; knowledge of cloud, network, resiliency, and security controls; strong communication and analytical skills.
NetBrain: Provides AI-powered no-code network automation and visibility software.
4+ YOEBuild and operationalize a SaaS security and compliance program aligned to SOC 2, ISO 27001, NIST and GDPR; lead risk management, third-party risk, control testing and audit readiness; 4+ years security/compliance experience; cloud experience (AWS/Azure/GCP).
DigitalOceanNew York Stock Exchange: DOCN: Simplifies cloud infrastructure for developers, startups, and SMBs.
6+ YOE6+ years in detection & response, insider risk, or security engineering; hands-on UEBA/SIEM/DLP/UAM/SOAR; scripting with Python/Go/Bash; familiarity with macOS, Windows, Linux, Kubernetes and cloud; knowledge of MITRE ATT&CK and NIST.
Data, AI and Emerging Technology Risk Principal Analyst
Johnston or Iselin or Westwood or Phoenix
HybridFull Time
Citizens Financial GroupNYSE: CFG: Provides retail, commercial, and private banking services to customers.
7+ YOE7+ years IT risk experience; deep expertise with CRI/NIST/COBIT/ITIL; experience with cloud, data platforms, analytics, and security tools; strong executive communication and mentoring skills.
WHOOP: Wearable technology for personalized health and performance tracking.
6+ YOE6+ years in cybersecurity or enterprise risk; experience conducting structured cyber/IT risk assessments, maintaining risk registers, familiarity with security frameworks and AI risk; strong communication and analysis skills.
NIST CSF, ISO 27001, PCI DSS, GDPR, HIPAA, NIST AI RMF, ISO/IEC 42001, FAIR
MACOMNASDAQ: MTSI: Designs and manufactures semiconductor products for communications infrastructure.
1+ YOEBachelor's in relevant field (or equivalent), 1–3 years information security/risk/compliance experience, knowledge of security frameworks, strong analytical and communication skills, and willingness to learn ServiceNow GRC.
ServiceNow GRC, NIST, ISO 27001, SOC2, CIS, ISO9001, ISO14001
Control Risks: Provides risk management, security, and strategic intelligence consulting services.
1+ YOE1–3 years in corporate or governmental security, familiarity with global risk intelligence and incident response, emergency notification and travel risk systems experience advantageous, strong open-source analysis and communication skills.
Control Risks: Provides risk management, security, and strategic intelligence consulting services.
1+ YOEBachelor's preferred; 1–3 years corporate or governmental security experience required; familiarity with global risk intelligence, incident response, and mass notification/travel risk systems; strong open-source analysis and communication skills.
Boston Medical Center: Provides specialized medical care and academic healthcare training.
6+ YOE6+ years information security experience focused on governance, risk, and compliance; bachelor’s preferred; certifications such as CISA/CRISC/CISSP preferred; knowledge of NIST CSF 2.0, HIPAA/HITECH; strong data analysis and communication skills.
Microsoft Excel, Microsoft SharePoint, NIST CSF 2.0, HIPAA, HITECH