Remote job
Senior Security Risk Analyst
Job details
About this role
Role overview
Protect the people, data, and infrastructure of a space systems organization by leading security risk practice across every function, from engineering and IT to operations, finance, and supply chain. This senior role blends hands-on risk assessment with leadership-facing communication, owning the company's view of its security posture and driving remediation with the teams that hold each risk.
Responsibilities
- Lead enterprise-wide security risk assessments, identifying, analyzing, and prioritizing risks across engineering, IT, operations, and business functions. - Maintain the risk register and deliver a clear, current view of organizational risk posture for leadership. - Partner across the company to drive remediation of identified risks and track them to closure. - Assess security risk for new tools, vendors, third parties, and proposed architectural or process changes before adoption. - Define and apply a consistent risk framework covering likelihood/impact scoring, risk acceptance, and exceptions. - Map risks and controls to compliance requirements such as NIST 800-171 and CMMC, supporting audits and assessments. - Report risk trends and metrics to leadership and recommend where to invest for the greatest risk reduction. - Coach teams to build risk-aware processes and take ownership of the risks they hold.
Requirements
- 5+ years in information security, security engineering, or security risk/GRC roles. - Hands-on experience running security risk assessments and managing a risk register. - Strong working knowledge of security risk frameworks such as NIST RMF, NIST 800-30, FAIR, or comparable methodologies. - Familiarity with compliance frameworks such as NIST 800-171, CMMC, SOC 2, or ISO 27001. - Excellent written and verbal communication, with the ability to convey risk and priorities to both engineers and executives.
Nice to have
- Relevant certifications such as CISSP, CRISC, or CISA. - Background operating in environments subject to ITAR/EAR export control requirements.
Benefits and work setup
- Base salary range of $154,000-$207,000, plus equity and a comprehensive benefits package. - Medical, dental, and vision insurance; 401(k); short- and long-term disability plus life insurance. - Three weeks paid vacation for new hires, 12 paid holidays, unlimited sick time, and paid parental leave. - On-site, hybrid, or fully remote from approved U.S. locations; role requires access to export-controlled information, so candidates must be a U.S. person or otherwise eligible under ITAR/EAR.