Description
At Twilio, we're shaping the future of communications, all from the comfort of our homes. We deliver innovative solutions to hundreds of thousands of businesses and empower millions of developers worldwide to craft personalized customer experiences.
As a Senior Analyst, Security Risk, you will be a key member of the One Twilio Risk Management program, focused on maturing our Security risk posture by facilitating risk identification and treatment. The team works closely with our Product and Engineering teams to ensure all areas of cyber risk are identified across Twilio and that risk methodologies are operationally effective and in compliance with regulations and industry best practice security measures.
Responsibilities:
- Execute and improve upon daily operations of the One Twilio Risk Management program which includes the further establishment of automated operations for all areas of cyber risk.
- Manage and maintain risk register(s) to track key risk indicators (KRIs) and ensure risks are identified, evaluated, and mitigated appropriately.
- Collaborate with cross-functional teams to ensure risks are clearly communicated and actionable.
- Review and assess the effectiveness of risk treatment strategies and recommend solutions when applicable.
- Prepare and deliver regular risk reports, dashboards, and presentations to internal and external stakeholders, highlighting key risk trends, issues, and mitigation efforts.
- Analyze risk data from various sources to assess trends and develop predictive models for potential risks.
- Use data analytics and risk modeling tools to assess the legal, financial, operational, and security impact of risks.
- Develop ad-hoc reports and presentations as required to support risk decision-making.
- Coordinate with internal and external auditors to support compliance assessments and resolve any risk-related findings.
Qualifications:
- 5+ years of Risk Management experience, working with security-centric risk management and compliance frameworks.
- Experience maturing an industry-accepted risk framework including but not limited to NIST Risk Management Framework, COSO Enterprise Risk Management, or ISO 31000.
- Excellent cross-functional collaboration leveraging relationships to establish strategic direction.
- Experience designing and executing qualitative and quantitative risk analyses to translate technical vulnerabilities into measurable business impact.
- Experience translating vulnerabilities, control gaps, and systematic limitations into clear, actionable risk statements.
- Proven track record of managing large-scale, heavily regulated, multi-entity, cross-functional risk assessments, risk registers, and compliance programs.
- Experience of working with technical security and Engineering / IT to implement technical risk/control solutions with the ability to interpret control requirements and relay those to different stakeholder groups with strong technical knowledge.
- Bias towards automation and tooling to scale program impact and reach.
- Experience leveraging AI to streamline risk operations.
- Excellent verbal, written, and interpersonal skills.
- Flexible and able to manage multiple projects under tight deadlines.
- Comfortable with ambiguity and adaptable to fast-changing environments.
- Strategic thinker and problem solver with exceptional communication skills.
Location: This role will be remote, but is not eligible to be hired in CA, CT, NJ, NY, PA, WA.
What We Offer: Working at Twilio offers many benefits, including competitive pay, generous time off, ample parental and wellness leave, healthcare, a retirement savings program, and much more. Offerings vary by location.
Compensation: The estimated pay ranges for this role are as follows:
- Based in Colorado, Hawaii, Illinois, Maryland, Massachusetts, Minnesota, Vermont or Washington D.C.: $128,560 - $160,700.
- Based in New York, New Jersey, Washington State, or California (outside of the San Francisco Bay area): $136,000 - $170,000.
- Based in the San Francisco Bay area, California: $151,120 - $188,900.