The Leaflet logo
The Leaflet

An independent platform for cutting-edge, progressive, legal, and political opinion.

Cybersecurity Risk Analyst

Security EngineerSecurity EngineerFull TimeRemoteSeniorTeam 11-50H1B No SponsorCompany SiteLinkedIn

Location

United Kingdom

Posted

7 days ago

Salary

0

Seniority

Senior

Bachelor Degree3 yrs expEnglishCloudCyber Security

Job Description

Cybersecurity Risk Analyst

The Leaflet

• Conduct comprehensive risk assessments of cloud infrastructure, gaming applications, CI/CD pipelines, DevOps processes, payment processing systems, and all other aspects of internal technology operations • Develop and maintain risk registers, threat models, vulnerability and threat management programs, and risk treatment plans across eight enterprise risk categories • Perform quantitative and qualitative risk analysis using industry-standard methodologies (ISO 27005, ISO 31000, NIST RMF) • Evaluate third-party vendor security risks and assess supply chain vulnerabilities using structured TPRM frameworks • Leverage AI tools to accelerate risk identification, analysis, and reporting workflows • Develop and recommend risk mitigation strategies and security controls • Collaborate with technical teams to implement security measures and monitor their effectiveness • Track remediation efforts and verify risk reduction activities via GRC platform integrations • Create and maintain risk metrics and key risk indicators (KRIs) • Ensure alignment with regulatory and industry requirements including state-specific gaming regulations (GLI-19, GLI-33, GLI-GSF), ISO 27001, ISO 42001, PCI DSS v4.0, SOC 2, NIST CSF, and GDPR • Support internal and external audits (Deloitte, Bulletproof, Schellman) by gathering evidence, preparing documentation, and coordinating audit activities • Maintain security policies, procedures, and risk management frameworks within the IMS • Contribute to AI governance activities including AI service registry maintenance, Shadow AI detection, and ISO 42001 compliance • Identify opportunities to extend agentic automation by integrating new MCP servers and APIs into existing AI workflows, reducing manual effort across compliance, audit, and risk operations • Prepare risk reports and dashboards for management, audit committees, and gaming regulators • Document risk assessment methodologies and maintain assessment artifacts.

Job Requirements

  • Bachelor's degree in Computer Science, Information Security, Technology Risk Management, or related field
  • 3-5 years of experience in cybersecurity risk management, GRC, or IT audit within the technology industry
  • Demonstrated experience with risk assessment methodologies and frameworks (ISO 27005, ISO 31000, NIST RMF)
  • Knowledge of security controls and their implementation across cloud environments
  • Experience with GRC platforms (Vanta experience preferred)
  • Practical experience using AI/LLM tools in a professional security or risk management context.
  • Demonstrated proficiency with AI coding assistants and agentic AI tools.
  • Ability to craft effective prompts and work iteratively with AI to produce high-quality risk assessments, policies, and compliance documentation
  • Understanding of AI governance concepts: data classification for AI usage, model training policies, AI risk assessment, and responsible AI principles
  • Familiarity with Model Context Protocol (MCP) or similar frameworks for connecting AI agents to external data sources and APIs.

Benefits

  • Flexible vacation allowance.
  • Remote or Hybrid Flexibility : Enjoy the flexibility of remote work, with opportunities for in-person collaboration at our Austin or Florida headquarters, or a hybrid arrangement.
  • Innovative Environment: Join a team that thrives on pushing boundaries.
  • Growth Opportunities: As we scale, your role will evolve, providing you with unlimited opportunities for personal and professional growth.
  • Diverse and Inclusive: Join a team that values diversity, inclusivity, and embraces varied perspectives.

Related Categories

Related Job Pages

More Security Engineer Jobs

Keysight Technologies, Inc. logo

Cybersecurity Engineer

Keysight Technologies, Inc.

Keysight is on the forefront of technology innovation, delivering breakthroughs and trusted insights in electronic design, simulation, prototyping, test, manufacturing, and optimization. Our ~15,000 employees create world-class solutions in communications, 5G, automotive, energy, quantum, aerospace, defense, and semiconductor markets for customers in over 100 countries. Diversity, equity & inclusion are integral parts of our culture and drivers of innovation at Keysight. We believe that when people feel a sense of belonging, they can be more creative, innovative, and thrive at all points in their careers.

Full TimeRemoteTeam 10,001

Role Description The Keysight Information Security and Compliance team rises daily to the challenges of meeting the cyber security needs of a global, advanced technology company. The team delivers security solutions and services across a range of technology domains. The cybersecurity engineering team is looking for an individual with a passion for applying their experience and skills to secure Keysight’s use of computing infrastructure and platforms. The role requires the ability to analytically assess technology needs of multiple teams, propose solutions to requirements, and help drive execution. - About 60% solutioning, architecting, and engineering cybersecurity - 20% operations for cybersecurity - 20% general work A successful candidate will be a member of the Information Security and Compliance team and will have a key role in the development of enterprise security solutions, from whiteboard conception and design to testing, deployment, and overseeing the handoff to operations. Collaboration on projects with the rest of the security team and engagement with engineers from other departments will be frequent. Qualifications - BS or MS in Computer Science or Information Security or equivalent - 5+ years in Cybersecurity Engineering roles - Ability to understand and explain technical details - Excellent communication skills, on both technical and non-technical issues - Ability to independently handle multiple tasks, prioritize and meet deadlines - Experience with networking architectures and common protocols (HTTP, TLS, DNS, SSH, etc) - Experience with web application security - Experience with IAM technologies - Experience with PKI and certificate management - Experience with cloud security architecture/operations - Experience with Linux/Windows/MacOS - Experience with Automation - Experience with Artificial Intelligence - Experience with vulnerability management - Understanding of public keys, certificates, and authentication concepts Company Description Keysight is at the forefront of technology innovation, delivering breakthroughs and trusted insights in electronic design, simulation, prototyping, test, manufacturing, and optimization. Our ~16,800 employees create world-class solutions in communications, 5G, automotive, energy, quantum, aerospace, defense, and semiconductor markets for customers in over 100 countries. Our award-winning culture embraces a bold vision of where technology can take us and a passion for tackling challenging problems with industry-first solutions. We believe that when people feel a sense of belonging, they can be more creative, innovative, and thrive at all points in their careers.

Romania
GoDaddy logo

Website Security Services Remediation Analyst I

GoDaddy

GoDaddy is a web services platform that helps individuals and businesses worldwide start, grow, and manage their online presence. GoDaddy employs team members a

Role Description The Remediation Support Analyst plays a key role in supporting website security customers by managing the incident response lifecycle. This includes: - Identifying malware - Containing and removing threats - Restoring site functionality - Recommending prevention measures The role focuses on website clean-ups and requires knowledge of PHP, CMS platforms, and how malicious code operates. Each customer interaction is an opportunity to resolve issues and build technical expertise. What you'll get to do: - Perform website clean-up and troubleshooting via support ticket - Follow processes to identify and remove malware while delivering strong customer service - Analyze code to detect malicious activity - Contribute findings to improve automation and processes - Support platforms including WordPress, Joomla, Drupal, and Magento - Collaborate across teams to share security insights Qualifications - Ability to identify and decode complex, multi-step obfuscated malware - Experience writing PHP snippets and Shell scripts and able to read and interpret PHP and JavaScript - Experience with Windows web stack (IIS, SQL Server, ASP.NET) - Ability to read and write regular expressions (Regex) - Database management experience and using advanced command-line tools (e.g., process tracing, advanced search and replace) - Strong written and verbal communication skills - Experience with cPanel/WHM or similar hosting control panels - Solid understanding of web security principles and malware threats - Experience troubleshooting websites across CMS platforms - Working knowledge of Linux/UNIX environments and understanding of networking concepts (DNS, TCP/IP, firewalls) - Strong analytical and investigative mindset Benefits - Paid time off - Retirement savings (e.g., 401k, pension schemes) - Bonus/incentive eligibility - Equity grants - Participation in our employee stock purchase plan - Competitive health benefits - Family-friendly benefits including parental leave

India
Job Closed

Role Description V4C.ai is seeking a skilled AWS Security Engineer to join our team. In this role, you will be responsible for ensuring the security of our AWS cloud infrastructure by: - Designing, implementing, and managing security controls - Monitoring for vulnerabilities - Responding to security incidents You will collaborate closely with the cloud engineering and operations teams to safeguard our systems and data. This role requires a strong understanding of AWS security best practices, cloud security frameworks, and hands-on experience with security tools and automation. Qualifications - Bachelor's degree in Computer Science, Information Security, or a related field - 8+ years of experience in cloud security, specifically AWS environments - Proficiency with AWS security services such as AWS IAM, AWS KMS, AWS CloudTrail, AWS Config, and AWS Security Hub - Experience implementing and managing network security controls including VPCs, security groups, and NACLs - Knowledge of compliance frameworks and standards such as ISO 27001, SOC 2, HIPAA, or GDPR - Hands-on experience with security monitoring, incident response, vulnerability assessment, and penetration testing - Proficiency in scripting languages such as Python or Bash for automation tasks - Familiarity with infrastructure as code tools like Terraform or CloudFormation - Strong problem-solving skills and the ability to work collaboratively in cross-functional teams - AWS security certifications (e.g., AWS Certified Security – Specialty) are highly desirable Company Description

United States
Job Closed
Bertoni Solutions logo

Azure Data Security Engineer

Bertoni Solutions

Translating technology into your success

ContractRemoteTeam 11-50Since 2016H1B No Sponsor

• Strong communication and collaboration skills to work effectively with cross-functional teams • Implement and maintain cloud data and analytics security solutions • Implement access policies to secure databases, schemas, tables, and other database objects • Understand and abide by all Information Security policies and control standards • Conducts troubleshooting of data security issues, performs root cause analysis and optimize security incidents through lessons learned process • Adept understanding of the Cloud Security best practices in Azure • Proven experience with Microsoft technologies including Azure B2B and Application Security in Azure • Collaborate effectively across cross-functional teams to ensure seamless integration and implementation of data security controls within analytics platforms

Brazil
$30 / hour