Description
At Honda, we're looking for individuals with the skills, courage, persistence, and dreams to help us reach our future-focused goals. As an IT Governance and Risk Analyst, you will act as an IT risk quantification analyst in Cybersecurity Governance, Risk, and Compliance, evaluating and measuring the potential impact of cybersecurity threats on an organization using structured methodologies and industry frameworks.
Your key accountabilities will include:
- IT Third Party Risk Management: Monitor and improve IT risk processes, tools, and documentation, update risk scenarios, benchmarks, and mitigation strategies, maintain the Information Security Management System (ISMS), and advise on balancing security controls with business impact.
- Risk & Control Self Assessment (RCSA): Conduct cybersecurity risk assessments and identify control gaps, document results, prepare management reports, and drive remediation, support and train teams on RCSA standards and methodologies.
- Risk Modeling & Analysis: Develop and maintain data, process, and event-based risk models, quantify risk, validate models, and communicate findings to stakeholders.
- Data Collection & Reporting: Gather, analyze, and document cybersecurity risk data, maintain the risk register and data libraries.
- Collaboration & Domain Expertise: Partner cross-functionally to implement risk mitigation, stay current on cyber threats, regulations, and industry best practices.
As a successful candidate, you will have a Bachelor's level degree in IT/IS/Cybersecurity or equivalent level of relevant industry experience, and at least 5 years of demonstrable relevant experience in the industry, specifically in the cybersecurity space. You will also possess core skills including risk assessment, analytical thinking, communication, and strong knowledge of cybersecurity frameworks, regulatory obligations, and evolving threat landscapes.