Cybersecurity Specialist
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
Job description
· The Cybersecurity Risk Management specialist is responsible for governing changes that could introduce cybersecurity risk into the environment, via IT and OT changes. They operationally govern the environment, following the enterprise’s cybersecurity policies and standards, via defining and enforcing operational processes for cybersecurity risk assessment and remediation covering the organization’s IT and OT environment. They establish operational risk management processes and operational playbooks, aligned to corporate cybersecurity policy and agreed upon risk management frameworks and enterprise risk management guidelines, to ensure secure IT and OT changes, while providing enterprise-wide cybersecurity risk visibility.
They serve as the focal point and technical consultant to the business units and IT and OT project team and management to assess and identify cybersecurity risks related to environment changes. They establish risk remediation approaches based upon corporate policies and standards, steering and facilitating implementation of any needed cybersecurity controls with the appropriate control owners.
They are responsible for planning, managing, and coordinating various cybersecurity risk management activities, focused on identifying, assessing, and mitigating unacceptable risks while enabling the underlying business goals and objectives. They also oversee and manage all 3rd-party risk management and act as a gatekeeper for enabling integrations with 3rd-party partners, suppliers, and vendors, overseeing TPRM assessments and specifying controls needed to protect the organization’s data and connectivity with 3rd-parties. APAC
KEY ACOUNTABILITIES
· Maintain enterprise risk management operational frameworks and risk scoring criteria in accordance to company cybersecurity policies, standards, and frameworks and enterprise risk management guidelines
· Perform cybersecurity risk assessments for all qualifying IT and OT environment changes
· Coordinate with the cybersecurity architecture senior specialist to validate risk assessment findings, and to request guidance when pre-approved risk mitigation strategies are not available for identified risks
- Establish and track risk remediation plans for all identified risks
- Coordinate with the cybersecurity assurance specialist to ensure ongoing verification of mitigated risks are effective over time
- Implement, manage, and maintain risk-related workflows, including coordination with the appropriate risk owners and authority functions to obtain approval for risk exceptions and policy deviations.
- Act as a gatekeeper between Implementation Phase and production go-live (Manage & Measure phase) to ensure all identified risks have been addressed via closure of risk remediation plans. 0.35
Third Party Risk Management
- Ensure all 3rd-party / external partner, vendor, and supplier interactions have undergone an appropriate risk assessment to verify the safety, security, and risk mitigation of all 3rd-party integrations and interactions
- Maintain a register of approved 3rd-parties, including the controls required to ensure safe and secure interactions, and the approved use case(s) of each 3rd-party
- Establish and maintain a 3rd-party re-verification program to verify that usage, risks, and risk mitigations are updated as needed, if any 3rd-party relationships change over time
- Coordinate with the cybersecurity Assurance team to ensure on-going operational validation of 3rd-party integrations and interactions
- Review all third-party contracts for IT / OT services and solutions to ensure all required risk-mitigating controls and clauses are included and enforced contractually. 0.25
Risk Register Management
- Oversight and management of the enterprise cybersecurity risk register to facilitate the monitoring and reporting of risks.
- Management of the operational risk assessment methodology covering the organization’s IT , OT, and 3rd-party integration components related to secure, compliant and resilient operations.
- Oversight of the managed services providers performing risk assessments to ensure they are following the methodology in compliance with company policies, standards, processes, and expectations 0.15
Compliance Support & Alignment
- Provide evidences to Assurance function, Legal, approved stakeholders, and contribute to internal and external audits and assessments as needed in regard to cybersecurity risks
- Ensure feedback from cybersecurity Assurance role and similar stakeholders are used to improve risk assessment methodologies and processes 0.1
Continuous Improvement
- Identifies gaps and needs in regards to risk assessment, working with the cybersecurity architect role to ensure needs are incorporated into the cybersecurity strategy and roadmap
- Manages control implementations and improvement projects in the area of risk management, following the organization’s project management and project execution processes
- Drives operational risk assessment maturity and process improvements and automation for processes and controls in-scope of role 0.05
Communication and Stakeholder management:
- Understand stakeholder challenges and opportunities
- Manage escalations and stakeholder’s expectations
- Provides stakeholder and leadership views of state of organizational cybersecurity risks 0.1
Requirements
· Minimum Qualifications: (Degree, training, or certification required) BS or MA in computer science, information security, cybersecurity or a related field Cybersecurity certification in risk assessment (or appropriate on-the job experience)
· Minimum Experience: (Technical, functional, and/or leadership experience required) 5+ years of experience in a cybersecurity, enterprise (ERM), or IT risk management role 5+ years of experience with regulatory compliance, risk management frameworks and information security management frameworks (e.g. ISO, NIST, etc) Strong understanding of Zero Trust principals
· Job Specific Skills: (Key functional, leadership, or business skills required) Cybersecurity principles and practices, including IT and OT cybersecurity risk assessment, cybersecurity risk mitigation, and third-party risk assessment.
· Cybersecurity frameworks and standards, such as the NIST CSF, Secure Controls Framework, ISO/IEC 27001, and OT cybersecurity standards (62443, …).
· Strong background in conducting Business Impact Analysis (BIA) to evaluate the potential impact of cybersecurity risk on critical business processes and functions. Third Party and Vendor Risk Regulatory and Compliance alignment
Benefits & conditions
Pulled from the full job description
- Parental leave
- 401(k)
- Retirement plan
- Dental insurance
- Employee assistance program
- Flexible schedule, * 401(k)
- Dental insurance
- Employee assistance program
- Flexible schedule
- Parental leave
- Retirement plan
About the company
Over six decades of materials science. Built around what engineers truly need.
NexPoint exists for specialists working where ordinary materials won’t do. Applications that demand reliability, precision, and a partner who understands the problem. We are the engineering thermoplastics business previously part of SABIC, now operating on our own, with production across the Americas and Europe and customers in industries worldwide. Same portfolio, production facilities and people, combined with the focus and agility of a stand-alone company.
Our story begins in the early 1950s with the invention of polycarbonate, first commercialized as LEXAN resin, still our flagship brand today. Over six decades, the portfolio grew to seven brand families: LEXAN, VALOX , CYCOLOY , CYCOLAC , GELOY , XENOY and XYLEX resins.
In 2026, the business has become a standalone company, NexPoint Materials. The materials, production facilities, employees and customer relationships remain. What has changed is a reenergized focus on responsiveness and helping customers solve complex challenges - enabling them to move forward with confidence.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Is Software Engineering Over-Saturated?
System change: restart as developer?
Best Paying Jobs in Technology
Fully Remote Software Engineer Jobs