Staff Cybersecurity Analyst, Risk Management

Rivian Rivian · Auto · Atlanta, GA · Information Technology

This role supports Rivian's cybersecurity risk management practice, focusing on day-to-day risk management, monitoring key risk indicators (KRIs), and facilitating risk discussions. The analyst will use AI-enabled tooling and risk platforms to improve efficiency and transparency in risk decisions, maintain risk registers, and collaborate with various teams. The role requires experience with cybersecurity frameworks like NIST CSF and ISO 27001, and the ability to influence risk treatment decisions.

What you'd actually do

  1. Maintain and continuously improve the cybersecurity and crown-jewel risk registers, ensuring risks are clearly defined, scored, prioritized, and kept current.
  2. Design, implement, and monitor KRIs and related metrics, such as control health, incident trends, and assessment throughput, to provide an objective view of risk posture.
  3. Use Rivian’s risk platform and AI-enabled tools to improve efficiency, effectiveness, and expediency in risk logging, analysis, reporting, and communication.
  4. Apply NIST CSF and ISO 27001 concepts when assessing controls, documenting risks, and proposing treatments, helping ensure consistency with the ISMS and enterprise risk practices.
  5. Collaborate with the Cyber TPRM lead where responsibilities intersect, including supplier-driven risks, concentration risk, and systemic control gaps, to ensure consistent risk assessment and treatment.

Skills

Required

  • Cybersecurity risk management
  • Risk registers
  • Key Risk Indicators (KRIs)
  • NIST Cybersecurity Framework (CSF)
  • ISO 27001
  • Risk assessment
  • Risk treatment
  • GRC/IRM platforms
  • Analytical skills
  • Communication skills
  • Cross-functional collaboration

Nice to have

  • Modern GRC/IRM or dedicated risk platforms
  • Building risk dashboards
  • CRISC, PMI-RMP, CISM certifications
  • Experience in fast-paced, high-growth environments (technology, automotive, manufacturing)

What the JD emphasized

  • primary responsibility for leading or owning a risk management function, program, or risk domain
  • Hands-on experience maintaining and operating risk registers and risk management tooling
  • Working knowledge of the NIST Cybersecurity Framework (CSF) and exposure to frameworks such as ISO/IEC 27001
  • Demonstrated ability to influence risk treatment decisions, not just document them
  • Strong analytical and quantitative risk skills
  • High comfort working with AI tools for analysis, synthesis, workflow automation, and responsible experimentation