> Markdown version of [/jobs/ext/1348807-cyber-defense-risk-analyst](https://www.wearedevelopers.com/jobs/ext/1348807-cyber-defense-risk-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cyber Defense & Risk Analyst - **Company:** Veritiv Publishing & Print Management, Inc. - **Location:** Atlanta, GA, United States - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Software as a Service, Cyber Security, Information Systems, Data Governance, Identity and Access Management, Information Security Management, Information Technology Audit, Information Systems Security Architecture Professional, Microsoft Office, Cloud Services, Phishing, Security Information and Event Management, Systems Integration, Software Vulnerability Management, IT General Controls (ITGC), Information Technology, CIS Benchmarks, Cyber Warfare - **Published:** July 19, 2026 - **Apply:** https://www.jofdav.com/jobs/58901825-cyber-defense-risk-analyst ## About the Role * Working knowledge of common security controls and frameworks (e.g., NIST CSF, ISO 27001/27002, CIS Controls) and the ability to map technical issues to control requirements. * Hands-on experience with at least two of the following areas: security monitoring (SIEM/MDR), incident response, vulnerability management, endpoint security (EDR), identity and access management, email security. * Experience supporting audits and control testing (e.g., ITGC, internal audit, SOC report reviews), including evidence collection and remediation tracking. * Ability to write clearly and maintain thorough documentation (risk statements, procedures, incident notes, and audit evidence narratives). * Strong interpersonal and communication skills, including the ability to work effectively with both technical teams and business stakeholders. * Aptitude and desire to leverage AI-enabled capabilities and automation to improve security outcomes (e.g., workflow automation, scripting, playbooks, and repeatable process improvement) while maintaining appropriate governance and data handling practices. * IT, Risk Management, Computer Science and Business Administration majors preferred. Work Experience: * 3-5 years of related job experience. * Ability to manage multiple projects, work under pressure, and adapt to sudden changes in the work environment. * Ability to work quickly and efficiently. * Excellent verbal, written, people, and diplomacy skills are required. * Experience of interpreting strategy and policy in order to set and deliver objectives. * Proficient with Microsoft Office Suite. * Strong customer service skills (friendly, courteous and helpful). * Strong planning and organization skills are required. Education: * Bachelor's Degree Preferred * Certified Information Systems Security Professional (CISSP) - International Information System Security Certification Consortium * Certified Information Systems Auditor (CISA) - Information Systems Audit and Control Association (ISSACA) ## Description Our Cyber Defense & Risk Analyst is responsible for strengthening Veritiv's security posture through both cybersecurity operations and governance, risk, and compliance. This position partners closely with IT teams, Legal, Internal Audit, and third-party security providers to ensure risks are understood, prioritized, and reduced through practical and measurable actions., * Monitor, analyze, and validate security alerts using Veritiv's security monitoring ecosystem (e.g., SIEM/MDR, endpoint security, identity protection, and email security tools). * Investigate, triage, and respond to incidents (e.g., phishing, identity compromise, malware, suspicious network activity), coordinating with internal stakeholders and third-party providers as needed. * Perform root cause analysis and support containment, eradication, and recovery activities; document incident details, actions taken, and lessons learned. * Assist with technical security reviews of new or changing technologies (SaaS, cloud services, integrations, and vendors), identifying misconfigurations and recommending compensating controls. * Partner with Internal Audit and control owners to support IT audit activities (e.g., evidence collection, walkthroughs, remediation validation, and closure of findings). * Participate in third-party / vendor risk activities, including review of security documentation, questionnaires, and assessment results; help translate vendor technical risks into business impact and mitigation steps. * Communicate complex technical topics clearly to non-technical stakeholders; produce concise written deliverables (incident summaries, risk write-ups, audit evidence narratives). * Identify opportunities to automate and streamline GRC and security operations processes (e.g., alert triage, evidence collection, control testing support, reporting), including the responsible use of approved AI-enabled security capabilities to improve speed, consistency, and quality. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [A practical guide to writing secure Dockerfiles](https://www.wearedevelopers.com/videos/109-a-practical-guide-to-writing-secure-dockerfiles) - [Passkeys: Truly Phishing-Resistant? Implementation and Pitfalls](https://www.wearedevelopers.com/videos/100156-passkeys-truly-phishing-resistant-implementation-and-pitfalls) - [OPA for the cloud natives](https://www.wearedevelopers.com/videos/713-opa-for-the-cloud-natives) - [Skynet wants your Passwords! The Role of AI in Automating Social Engineering](https://www.wearedevelopers.com/videos/770-skynet-wants-your-passwords-the-role-of-ai-in-automating-social-engineering) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology)