> Markdown version of [/jobs/ext/655767-it-cyber-security-risk-analyst](https://www.wearedevelopers.com/jobs/ext/655767-it-cyber-security-risk-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # IT Cyber Security Risk Analyst - **Company:** Cretex - **Location:** Elk River, MN, United States - **Experience:** Experienced - **Salary:** $91,200.0 - **Contract:** Permanent contract - **Skills:** Software as a Service, Cyber Security, Disaster Recovery, Identity and Access Management, Remote Access Technology, Azure Active Directory, Phishing, Zero Trust Network Access, Software Vulnerability Management, Data Logging, Okta, Information Technology, CIS Benchmarks - **Published:** June 26, 2026 - **Apply:** https://www.juju.com/job/00000000gb47kp ## About the Role Minimum Requirements, Education & Experience (incl. KSA's and certifications) + Bachelor's degree in Cybersecurity, Information Technology, or a related field + 2+ years in IT or cybersecurity roles, ideally with experience in user support, IAM, or risk management + Excellent communication and teaching skills; comfortable presenting to technical and non-technical audiences + Familiarity with Zero Trust concepts and tools (e.g., MFA, identity providers, conditional access) + Working knowledge of phishing, endpoint protection, and threat mitigation techniques + Strong organizational and documentation skills Desirable Criteria & Qualifications + Security certifications (e.g., Security+, SSAP, GSEC, or similar) + Experience with identity & access management tools (e.g., Azure AD, Okta, Duo, etc.) + Experience managing phishing simulation platforms (Mimecast, KnowBe4) + Familiarity with business continuity planning and disaster recovery best practices + Experience conducting or facilitating tabletop exercises + Exposure to NIST, ISO 27001, or CIS Controls frameworks + Manufacturing, regulated industry, or multi-site IT experience #LI-JW1 ## Description The Cybersecurity Risk Analyst is a key member of the Digital & IT team, helping drive a culture of cybersecurity, improve risk posture, and enhance user-focused security practices across the enterprise.This individual will serve as a backup to the Security Engineer(s), assisting with incident response, employee support, and cybersecurity projects. They will lead efforts to improve employee cybersecurity awareness, champion a Zero Trust approach to access and identity management, and help ensure business continuity and disaster recovery plans are in place, tested, and improved over time.This role blends hands-on technical support with program management and education, making it ideal for someone who is both people-oriented and detail-driven. Responsibilities Essential Job Functions Security Operations Support + Act as a secondary resource for daily security monitoring, incident response, and vulnerability remediation. + Assist in configuring and managing tools related to endpoint protection, logging, email security, and access control. + Help execute security-related projects, such as patching programs, encryption rollouts, and policy enforcement. Access Management & Zero Trust Initiatives + Help assess and improve identity and access management practices across systems. + Partner with IT teams to implement role-based access controls and Just-In-Time access principles. + Lead projects and process design supporting Zero Trust architecture, especially for remote access and SaaS tools. + Participate in account reviews and privilege audits to ensure appropriate access levels. Cybersecurity Awareness & Culture + Develop and lead training and awareness campaigns to reduce employee-related cyber risk. + Manage phishing simulation programs and track effectiveness. + Deliver cybersecurity onboarding for new employees and ongoing training for all staff. + Serve as the go-to contact for employee questions related to phishing, passwords, or safe technology use. Risk Management & Resilience + Own the development and maintenance of Business Continuity and Disaster Recovery plans. + Facilitate tabletop exercises and capture lessons learned to enhance resilience. + Collaborate with IT and business leaders to identify and reduce operational risk. + Contribute to regulatory, insurance, and customer security documentation as needed. Governance, Policy, and Metrics + Assist in drafting and maintaining cybersecurity policies and procedures. + Track and report on training compliance, incidents, and risk KPIs. + Stay current on emerging cyber threats and security trends, providing proactive recommendations. + Coordinate with external vendors (e.g., MDR, IAM, phishing) and internal teams to support tool effectiveness and projects. ## Related Videos - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Crypto-secure Data Management with In-Database Blockchain](https://www.wearedevelopers.com/videos/632-crypto-secure-data-management-with-in-database-blockchain) - [Passkeys: Truly Phishing-Resistant? Implementation and Pitfalls](https://www.wearedevelopers.com/videos/100156-passkeys-truly-phishing-resistant-implementation-and-pitfalls) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Build Delightful Mobile Experiences with Kotlin, Realm, and Atlas Device Sync](https://www.wearedevelopers.com/videos/694-build-delightful-mobile-experiences-with-kotlin-realm-and-atlas-device-sync) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [The Most Popular IT Jobs on the Market](https://www.wearedevelopers.com/magazine/376-the-most-popular-it-jobs-on-the-market) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated)