Cybersecurity BA Analyst / Data Analyst

Estuate Inc.
Juno Beach, United States of America
yesterday

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours
Languages
English
Experience level
Senior

Job location

Juno Beach, United States of America

Tech stack

Agile Methodologies
JIRA
Configuration Management Databases
Computer Security
Information Systems
Learning Management Systems
Data Governance
Data Warehousing
Identity and Access Management
Scrum
Power BI
Phishing
Requirements Management
Requirements Traceability
Software Vulnerability Management
Tanium Platform Expertise
Information Technology
Data Lineage
Atlassian Tools
Splunk
ServiceNow

Job description

Domain Metric-Definition Workshop Facilitation

· Plan and run structured metric-definition workshops with domain SMEs across all 7 CISO cyber domains, confirming up to 4 priority metrics per domain and documenting agreed calculation logic, definitions, and business rules.

· Take over workshop facilitation currently carried by the Product Owner, directly relieving the Sprint 1-2 capacity overload identified in the program''s risk register.

· Co-facilitate with the Data Scientist and Architect where technical depth (e.g. Gold-layer semantic view feasibility) is required, ensuring metrics are both business-meaningful and technically buildable.

Requirements Documentation

· Translate workshop outcomes into structured business and functional requirements - metric definitions, business rules, data lineage, and acceptance criteria - in a consistent, dashboard-ready format.

· Maintain and evolve the domain metric catalog as workshops confirm, revise, or reject the illustrative draft metrics currently placeholder-scoped in the backlog.

· Document the persona access model (Operations / Business / Executive) per domain in partnership with the Architect and QA Engineer, feeding downstream row-level security design.

Data Source & Domain Mapping Validation

· Validate and maintain the domain-to-data-source mapping across all 16 integrated sources (Tanium, Tenable, Service-Now CMDB, EDP-BU, KEV, SPM-LMS, GRC Central, Splunk, SPM Phishing, AzureSSO, Dragos, CrowdStrike, Proofpoint, Cyware, Rubrik, XLS Files) directly with domain SMEs, since several sources are currently mapped as draft assumptions requiring confirmation.

· Escalate and document any data gaps discovered between confirmed metric definitions and available Gold-layer data before dashboard build begins.

Backlog & Sprint Support

· Work with the Product Owner and Scrum Master to translate approved requirements into Jira-ready user stories with clear, testable acceptance criteria.

· Support sprint planning, backlog grooming, and PI-to-PI scope transitions, ensuring changes to draft metrics are captured as tracked backlog items rather than undocumented scope drift.

Stakeholder & Governance Liaison

· Support UAT coordination and domain-level stakeholder sign-off alongside the Product Owner and QA Engineer.

· Contribute to the published metric catalog and data governance documentation delivered at program closeout, ensuring requirements traceability from workshop to production dashboard.

Requirements

· Bachelor's degree in information systems, Computer Science, Business Administration, or a related field.

· 5+ years of experience as a Business Analyst on data, BI, or cybersecurity programs, ideally within a large enterprise or Fortune 500 engagement.

· Demonstrated experience planning and facilitating structured requirements or metric-definition workshops with both technical and business/executive stakeholders.

· Working knowledge of layered data warehouse architectures (Bronze/Silver/Gold or equivalent Raw/Integrated/Semantic models) and BI tools such as Power BI.

· Experience operating within Agile/SAFe delivery - Program Increments, sprints, epics/features/stories, backlog grooming.

· Strong written documentation skills - able to produce clear, unambiguous business requirement documents, metric catalogs, and acceptance criteria that a development team can build against without rework.

· Excellent stakeholder management and facilitation skills; comfortable running workshops with senior domain SMEs and CISO-office stakeholders.

Preferred Qualifications

· Prior exposure to one or more cybersecurity domains: vulnerability management, GRC, IAM, security architecture, or cyber resiliency.

· Familiarity with Jira and Confluence for backlog and documentation management.

· CBAP, CCBA, or equivalent Business Analysis certification.

Apply for this position