# Cybersecurity Risk Analyst

Hiring organization: [CAA](https://career.thegoodapps.co/organizations/caa)

Canonical page: https://career.thegoodapps.co/jobs/9cab0f4f-9dff-4c0b-84d0-79d1ed9a64b3

Listed on CAA's own careers site. Applications go to them directly.

- Employment type: full time
- Location: Nashville, TN
- Salary: 87000 – 104000 USD per year

## Summary

A hands-on security role focused on delivering enterprise risk management and threat detection within an entertainment agency's Information Security group. The position suits someone with cybersecurity risk experience who can conduct vendor assessments, coordinate security integrations across cloud and on-premises systems, and help the organization maintain a defensible security posture.

_Our summary, not CAA's wording._

## Skills named

Active Directory, Amazon Web Services (AWS), Data Privacy Law (GDPR/CCPA), GDPR, ITIL, Jira, Microsoft Azure, Microsoft Office, PCI DSS, Security Assertion Markup Language (SAML), SoC System on Chip, Splunk

## Required

- 3-4 years of IT experience
- 2 years of cybersecurity risk management experience
- Bachelor's or Master's degree in a relevant field
- Strong analytical skills for vendor risk assessment and due diligence
- Familiarity with information security frameworks (NIST, ISO 27001)
- Familiarity with data privacy regulations (GDPR, CCPA)
- Familiarity with information security certifications and attestations (SOC, ISO, PCI DSS, FedRAMP)
- Experience coordinating technical integrations for security tooling
- Ability to review complex system architectures for security opportunities
- Can produce comprehensive written security assessments of vendor security posture
- Experience using security analytics tooling for operational metrics and dashboards
- Understanding of servers, operating systems, cloud applications, and infrastructure fundamentals

## Nice to have

- Core cybersecurity fundamentals and third-party risk management skills
- Familiarity with third-party risk management tools (OneTrust, SIG, or similar GRC platforms)
- Hands-on experience with Azure and AWS cloud environments and core cloud services
- Familiarity with single sign-on concepts (PingFed, SAML)
- Familiarity with identity and access administration (Active Directory, Azure AD, AWS IAM)
- Familiarity with event management tools (Splunk)
- Expert-level proficiency with Microsoft Office and JIRA

Apply on CAA's site: https://caa.wd1.myworkdayjobs.com/en-US/Careers/job/Nashville-TN/Cybersecurity-Risk-Analyst_JR8926
