Track This Job
Add this job to your tracking list to:
- Monitor application status and updates
- Change status (Applied, Interview, Offer, etc.)
- Add personal notes and comments
- Set reminders for follow-ups
- Track your entire application journey
Save This Job
Add this job to your saved collection to:
- Access easily from your saved jobs dashboard
- Review job details later without searching again
- Compare with other saved opportunities
- Keep a collection of interesting positions
- Receive notifications about saved jobs before they expire
AI-Powered Job Summary
Get a concise overview of key job requirements, responsibilities, and qualifications in seconds.
Pro Tip: Use this feature to quickly decide if a job matches your skills before reading the full description.
Location: Remote
Job Description
Our client, located in Augusta, ME has an immediate need for a Cyber Security Analyst to join their team. The Cyber Security Analyst will be responsible for evaluating, analyzing, and assessing cybersecurity risks associated with new technologies, proposed solutions, and third-party vendors. This includes reviewing vendor security attestations, assessing architectural designs, validating security controls, and supporting procurement decisions through structured risk assessments. This role will also support the development and maturation of the Third-Party Risk Management (TPRM) program, including the enhancement and operation of tools such as Black Kite. Additionally, the CSA will assist with evaluating cybersecurity waiver submissions requiring deeper technical analysis and will help maintain the risk register to ensure tracking and remediation of risks that exceed the risk tolerance.
Responsibilities
New Technology & Solution Security Reviews:
- Conduct security reviews for new technologies, cloud services, applications, and proposed solutions.
- Review architectural diagrams to verify appropriate security controls, configurations, and data-protection mechanisms.
- Assess alignment with security requirements and applicable regulatory or compliance standards.
- Develop and document risk assessments with actionable recommendations to support procurement and technology-adoption decisions.
- Review and analyze third-party cybersecurity attestations, including SOC 2 Type II, ISO 27001 certifications, external penetration tests, and security questionnaires.
- Identify control gaps, inherited risks, and areas requiring additional compensating controls.
- Coordinate with procurement, legal, and business stakeholders during vendor onboarding and technology evaluation.
- Assist in developing, enhancing, and maintaining the TPRM program.
- Leverage and operationalize TPRM tools, including Black Kite, to support ongoing monitoring, vendor tiering, and risk scoring.
- Contribute to the creation of policies, processes, templates, and guidelines that mature the third-party risk-evaluation process.
- Utilize the Archer GRC platform to document risk assessments, waiver reviews, and remediation tracking activities.
- Support the continued implementation and refinement of Archer workflows related to enterprise risk management.
- Contribute to data quality, reporting accuracy, and process improvements to enhance risk visibility and governance maturity.
- Support the review of security waiver requests that require deeper technical analysis to evaluate risks of temporary control exceptions.
- Document findings, risk impacts, and recommended mitigation strategies to inform risk acceptance decisions.
- Assist in maintaining the security risk register, ensuring risks are documented, categorized, and updated.
- Track remediation progress and validate completion for risks that exceed established tolerance thresholds.
- Collaborate with stakeholders to monitor deadlines, escalate overdue items, and verify mitigation plans remain effective.
- Demonstrated experience in cybersecurity analysis, technology or architecture review, third-party or solution security evaluations, or related security-engineering activities.
- Familiarity with cybersecurity standards, control frameworks, and risk-management practices applicable to government environments is strongly desired.
- Strong understanding of cybersecurity principles, best practices, and control frameworks (e.g., NIST CSF, NIST 800-53).
- Demonstrated ability to interpret SOC 2 Type II reports, ISO 27001 certifications, penetration test reports, and related third-party security documentation.
- Familiarity with architectural review processes, cloud security concepts, and secure design principles.
- Experience conducting third-party, vendor, or technology risk assessments and identifying compensating controls.
- Experience supporting or operating within a Third-Party Risk Management (TPRM) program.
- Working knowledge of Governance, Risk, and Compliance (GRC) platforms (e.g., Archer or similar tools) is strongly preferred.
- Experience leveraging third-party risk monitoring tools (e.g., Black Kite) or similar platforms is desirable.
- Strong analytical, technical writing, and documentation skills with the ability to clearly communicate risk to both technical and non-technical stakeholders.
- Ability to manage multiple concurrent assessments while meeting deadlines in a fast-paced environment.
- Strong organizational skills, attention to detail, and sound professional judgment in evaluating and documenting risk.
Delphi-US is a national recruiting firm based in Newport, Rhode Island. We specialize in IT, Engineering and Professional Staffing services for premier corporations and a multitude of industries across the United States. We are the Peacemakers In The Talent War – bringing the best and brightest talent to Employers of Choice, enabling critical project success, fostering progressive employment relationships, and promoting competitive advantages for our Clients and the Talent Marketplace we serve. Delphi accomplishes this with a proprietary skill-based and cultural matching process that results in higher qualified submissions along with increased interviews and offer rates. You’ll find our team is highly experienced, friendly, professional and ready to advocate on your behalf, armed with industry trends, and an understanding of employer expectations.
Key Skills
Ranked by relevanceReady to apply?
Join Delphi-US, LLC - Peacemakers in the Talent War and take your career to the next level!
Application takes less than 5 minutes

