Cybersecurity Engineer Risk & Compliance
- Lead the design, implementation, and maintenance of cybersecurity risk management programs.
- Manage and assess third-party/vendor risk, including due diligence, risk assessments, and ongoing monitoring.
- Oversee and maintain SOC2 control environments, including evidence collection, control testing, and remediation of findings.
- Ensure robust controls are in place to protect sensitive customer data, including data classification, encryption, access controls, and secure data handling practices.
- Collaborate with internal teams and external partners to meet partner security requirements, including responding to security questionnaires, audits, and assessments.
- Map and align security controls to NIST CSF and CIS Controls, ensuring continuous improvement and maturity of the cybersecurity program.
- Develop and maintain risk registers, control matrices, and compliance documentation.
- Provide expert guidance on risk mitigation strategies and security best practices.
- Monitor and report on cybersecurity metrics, risk indicators, and compliance status to leadership.
- Support incident response and business continuity planning from a risk and compliance perspective.
- Assist with other Cybersecurity tasks as needed.
- Bachelor’s degree in Cybersecurity, Information Technology, or a related field.
- 2+ years of experience in cybersecurity engineering with a focus on risk management and compliance.
- Deep understanding of the SOC2 framework, including control design, implementation, and audit processes.
- Proven experience with NIST CSF and CIS Controls.
- Demonstrated experience managing controls around sensitive customer data and ensuring compliance with partner/client security requirements.
- Strong knowledge of third-party risk management practices and tools.
- Excellent analytical, communication, and documentation skills.
- Familiarity with GRC platforms (e.g., Hyperproof, OneTrust, AuditBoard, Archer, ServiceNow GRC).
- Relevant certifications such as CRISC, CGRC, CISA, or CISSP are highly desirable.
- Experience working in regulated industries (e.g., logistics, transportation, software).
- Knowledge of cloud security frameworks (e.g., AWS Well-Architected, Azure Security Benchmark).
- Ability to translate technical risks into business impacts for non-technical stakeholders.
Recommended Jobs
Utility Driver
*** $3,000 SIGN ON BONUS*** Go Green! Mahoney Environmental recycles used cooking oil - help the environment as part of our exceptional team. Competitive income, 401K plan, paid holidays and vacatio…
Test Automation Architect
Job Duties: Leading and mentoring quality engineering team members; Creating Test Plans, Test Cases and Test Data; Coordinating and leading testing by all Stakeholders; Develo…
Resident Engineer - Tunnelling
Requisition ID: 96563 Job Category: Construction Location: Pittsburgh, PA, United States Join a company that is passionately committed to the pursuit of a better world through positive c…
Logistics Specialist II
Work Schedule Standard (Mon-Fri) Environmental Conditions Office As part of the Thermo Fisher Scientific team, you’ll discover meaningful work that makes a positive impact on a global …
Installation Technician
Join HelloTech, a leader in in-home tech support services, as our newest Installation Technician. This role is crucial for providing hands-on support and technical expertise to our customers across a …
CDL A OTR Truck Drivers
Nigsam Inc is hiring experienced CDL A OTR Truck Drivers! Are you tired of sitting at the truck stop? Here are some things that will persuade you to join us: ~ Assigned routes + Steady (OTR) mi…
Licensed School Psychologist
We are looking for a School Psychologist to join a supportive school district in the Lancaster area. This is a full-time position for the current school year. Position Details: Full-time, school-…
TargetProcess/Apptio Application Engineer
Description: Hybrid 4 in Pittsburgh, PA Our client is a global investments company that provides investment management and investment services to institutions, corporations, and individual inv…
Coordinator, VAD
FRAUD ALERT: Please note that DSV will never request a chat interview or solicit funds from applicants or employees through its interviewing and hiring process. We do not require any form of payment …
Part Time Day Floater - Pittsburgh
We are looking for an individual to serve as a floater (fill-in) team member to cover open accounts at different locations within the Pittsburgh Metro Areas Basic tasks - empty/take out trash, dus…