Technology & Cybersecurity Risk Management Analyst
Toyota Tsusho Systems Plano, Texas, United States
Computer and Network Security · 201-500 employees
Applying here? Try the free cover letter tool — paste this posting and your résumé, no account needed.
About the role
The analyst will conduct technology and cybersecurity risk assessments using industry frameworks like NIST and COBIT to identify and mitigate potential threats. They are responsible for documenting risk statements, facilitating stakeholder discussions, and tracking remediation activities to ensure compliance.
What they look for
Requirements
Candidates must have a bachelor's degree in a relevant field and 1–3 years of experience in cybersecurity or technology risk management. Proficiency in risk assessment methodologies, security frameworks, and standard office software is required.
Full description
About TTS-US: Founded in 2011, Toyota Tsusho Systems US, Inc. (TTS-US) is a Toyota group company that develops IT, cybersecurity, and technology solutions to support Toyota’s global business operations. With eight TTS affiliates worldwide, TTS-US is helping establish a secure and resilient Toyota global value chain while continuing to expand its capabilities across cybersecurity, IT consulting, project support, and enterprise solutions.
The Technology & Cybersecurity Risk Management (T&CRM) Engineer supports the T&CRM program by analyzing technology and cybersecurity risks, conducting risk assessments, leading risk-related initiatives, and enhancing risk management processes. This role helps identify, visualize, and reduce technology and cybersecurity risks while guiding stakeholders through risk-based decision-making.
Core Responsibilities
- Conduct risk intake, assessments, triage sessions, and stakeholder risk discussions.
- Assess technology and cybersecurity risks using NIST, COBIT, and ISO frameworks.
- Identify, document, and evaluate inherent, residual, and emerging technology risks.
- Review controls and evaluate their effectiveness in mitigating identified risks.
- Map risks to controls and applicable framework and policy requirements.
- Facilitate control walkthroughs and risk discussions with control owners and stakeholders.
- Document risk statements, controls, evidence, and assessment results in governance tools and Word/Excel/PPT.
- Develop risk treatment recommendations and track remediation activities through closure.
- Escalate overdue actions, unresolved risks, and significant control or compliance concerns.
- Prepare executive-ready risk reports, dashboards, and governance presentation materials.
Required Knowledge and Skills
- Technology and Cybersecurity Fundamentals: Demonstrates a solid understanding of security controls, threats, and risk concepts. NIST, COBIT, and ISO 27001 framework knowledge.
- Risk Assessment & Analysis: Ability to identify, assess, and document technology and cybersecurity risks and control gaps. Understanding of control design, control effectiveness, and risk mitigation concepts.
- Project Management: Effectively plans, tracks, and executes work across multiple concurrent initiatives.
- Process Improvement: Identifies opportunities to streamline workflows and improve operational efficiency.
- Stakeholder Collaboration: Works effectively with cross‑functional teams and external partners.
- Communication: Clearly communicates technical risk information to both technical and non‑technical audiences.
- Attention to Detail: Produces accurate, well‑documented assessments and maintains reliable risk records.
- Tool proficiency: Microsoft Word, Excel, PowerPoint, and CoPilot. ServiceNow.
- Bachelor’s degree in Information Technology, Cybersecurity, Computer Science, Business, or a related field (or equivalent experience).
- 1–3 years of experience in cybersecurity or technology risk management, IT risk, cybersecurity, compliance, or related discipline.
- Foundational understanding of cybersecurity principles, risk assessment methodologies, and common security control frameworks.
- Experience supporting projects or initiatives that require coordination across multiple stakeholders.
- Strong written and verbal communication skills, with the ability to clearly document risks and recommendations.
Key Success Factors
- Comfortable navigating conversations with Control Owners and stakeholders.
- Clear and structured articulation of technology risks and controls.
- Strong attention to detail and documentation quality.
- Willingness to learn and grow within a Technology & Cybersecurity Risk Management function.
- Collaborative mindset across technical and non-technical teams.
Similar roles
-
Senior Cybersecurity Engineer, Product Security
CHAOS Industries El Segundo, California, United States
-
Infrastructure Security Engineer (Bare Metal & Platform)
SpaceXAI Palo Alto, California, United States · $100K–$258K/yr
-
Senior Consultant- CyberSecurity
Sia New York, New York, United States · $131K–$136K/yr
-
Senior Game Application Security Analyst
PlayStation Global United States · $177K–$266K/yr
-
Principal Technical Advisor for Cybersecurity Incident Response
Microsoft Irving, Texas, United States · $131K–$304K/yr
-
Senior Security Engineer, BAIP Cyber Defense (maternity cover)
SAP Careers Sofia, Sofia-City, Bulgaria