Senior Cyber Risk Analyst

Tempus AI · Vertical AI · Chicago, IL

This role focuses on managing the Cyber Risk Register and program for a health-tech company, involving risk identification, quantification, scoring, executive reporting, and supporting compliance with standards like HIPAA and HITRUST. It requires experience in information security, risk management, and GRC within the tech, AI, or healthcare industries.

What you'd actually do

  1. Serve as the primary owner for the "care and feeding" of the Cyber Risk Register. Oversee the end-to-end lifecycle of cybersecurity risks, including identification, logging, analysis, treatment tracking, and closure.
  2. Apply standardized risk assessment methodologies to accurately calculate risk impact/severity, likelihood/occurence, and controls/detectability, ensuring risks are prioritized effectively.
  3. Develop and maintain intuitive risk dashboards and Key Risk Indicators (KRIs). Provide clear, data-driven reports to the Director of Data Security, the CISO, and executive leadership regarding our current risk posture and remediation progress.
  4. Actively support the broader Enterprise Risk Management (ERM) program by translating technical cyber risks into business impacts, ensuring seamless reporting to ERM leadership.
  5. Provide technical expertise during Mergers and Acquisitions (M&A). Conduct pre-acquisition security risk analyses and ensure post-acquisition inherited risks are properly ingested into the Cyber Risk Register and tracked to remediation.

Skills

Required

  • 5+ years of technical experience in information security, risk management, or GRC
  • Deep understanding of cybersecurity principles, threat landscapes, and control frameworks (e.g., NIST CSF, NIST 800-53, ISO 27001, HITRUST)
  • Proven track record of building, maintaining, or heavily contributing to a Cyber Risk Register
  • Experience with risk quantification methodologies
  • Experience with leading GRC platforms (e.g., ServiceNow GRC, RSA Archer, AuditBoard, or similar)
  • Project & Stakeholder Management
  • Excellent written and verbal communication skills
  • Ability to translate technical vulnerabilities into business risk

Nice to have

  • experience in the technology, AI, or healthcare industries
  • experience in the health-tech environment

What the JD emphasized

  • primary custodian of the organization's Cyber Risk Register
  • integrating cyber risk management practices
  • clear visibility into our cyber risk posture
  • continuous security and compliance
  • Own the Risk Lifecycle
  • Risk Quantification & Scoring
  • Executive Reporting & Enterprise Alignment
  • ERM Integration
  • M&A Due Diligence
  • Global Compliance Support
  • technical experience in information security, risk management, or GRC
  • Deep understanding of cybersecurity principles, threat landscapes, and control frameworks
  • Proven track record of building, maintaining, or heavily contributing to a Cyber Risk Register
  • Experience with risk quantification methodologies
  • leading GRC platforms
  • Exceptional ability to manage multiple concurrent programs
  • working proactively to align multi-disciplinary stakeholders toward secure outcomes
  • Excellent written and verbal communication skills
  • act as a "translator" of risk