Senior IRM Analyst

2 days ago
Full-time
Lead
Cybersecurity
MongoDB

MongoDB

MongoDB provides a developer data platform that simplifies data management and accelerates application development, enabling businesses to leverage modern database technology for innovative solutions across various industries.

Internet Software & Services
1K-5K
Founded 2007

Description

  • Lead the risk assessment methodology roadmap and integrate the risk matrix into the risk framework.
  • Ensure the risk program aligns with global regulatory requirements, including DORA and FedRAMP Rev 5 supply chain controls.
  • Maintain the Supply Chain Risk Management plan and oversee boundary protections for the Atlas for Government environment.
  • Own and maintain the Information Risk Management Procedure, keeping risk processes documented, updated annually, and consistently followed.
  • Conduct technical security risk assessments across infrastructure, cloud, and application environments.
  • Own the end-to-end risk assessment workflow from intake through final treatment decisions.
  • Apply and validate risk scoring methodology, including baseline scoring based on breach history and weighted impact.
  • Ensure risk acceptance decisions include the right information and stakeholders, and manage the process in Jira.
  • Conduct annual and ad-hoc enterprise security risk assessments triggered by material changes, incidents, or new initiatives.
  • Work with asset and risk owners to identify risk scenarios, assess inherent and residual risk, and produce executive-ready risk assessment memos and dashboard reporting.

Requirements

  • 10+ years of experience in Information Security or Governance, Risk & Compliance (GRC).
  • Hands-on experience conducting enterprise-level security risk assessments end-to-end, including scoping, threat modeling, control evaluation, and executive reporting.
  • Experience evaluating control effectiveness using technical evidence such as configurations, logs, and architecture diagrams.
  • Experience performing threat modeling using established methodologies such as STRIDE and MITRE ATT&CK.
  • Deep operational understanding of NIST SP 800-30 and control frameworks including NIST CSF, NIST SP 800-53, ISO 27001, SOC 2, SIG Core/Lite, and CAIQ.
  • Comprehensive knowledge of DORA, NIS2, FedRAMP Rev 5, GDPR, and PCI-DSS requirements.
  • Ability to write executive-level risk reports that translate technical issues into business risks.
  • Strong track record of collaborating across teams and levels to influence change.
  • Bachelor’s degree in a relevant field such as Cybersecurity, Business, or Information Systems.
  • Certifications such as CRISC, CCSP, CISSP, CISA, or relevant cloud certifications are preferred.

Benefits

  • Role can be based in MongoDB’s Dublin office or remotely in Ireland.
  • Supportive and enriching culture focused on employee growth and business impact.
  • Employee affinity groups.
  • Fertility assistance.
  • Generous parental leave policy.
  • Accommodation support during the application and interview process for individuals with disabilities.
  • Equal opportunities employer commitment.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Risk Intelligence Analyst

Signifyd 251-1K IT Services

Signifyd is hiring a Risk Analyst to join its Risk Intelligence team, focusing on detecting fraud patterns, monitoring risk, and improving payment risk decisioning for e-commerce merchants worldwide.

Looker Machine Learning SQL
1 hour, 6 minutes ago

Security Analyst I

Tactacam 51-250 Household Durables

Tactacam is seeking a Security Analyst to monitor and respond to security threats across its digital infrastructure while supporting vulnerability management, remediation, documentation, and employee security awareness.

Cybersecurity Network Security SIEM
3 hours, 51 minutes ago

FBS Information Security Analyst (Remote)

Capgemini 100K+ Internet Software & Services

Farmers Information Security’s External Vendor Risk Assessment team is hiring an Information Security Analyst to support cybersecurity assessments of vendors and third parties, manage security risk reviews, and help protect company systems and data.

Cybersecurity
9 hours, 24 minutes ago

Information Security Specialist

SymSoft Solutions Web Design, Development, and System Integration

Symsoft Solutions is seeking a remote, six-month contractor to support state and local government digital services for California state agencies on a large IT project.

17 hours, 10 minutes ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers