Sr. Cyber Risk Analyst

Levi Strauss
Mexico City
Workplace: OnsiteFull timeFunction: CybersecuritySkills: ["Analytical thinking","Problem-solving","Communication","Influencing","Data analysis"]

Implement the cyber risk operational strategy as part of the Cyber Risk team. Manage the OneTrust GRC tool, perform internal and third-party security risk assessments, and align governance to ISO 27005, the CIS Top 18 Controls, and the NIST Cybersecurity Framework. Own policy lifecycle management, exception handling, risk register maintenance, remediation tracking, and leadership reporting, including building KRIs and continuous control monitoring workflows using OneTrust and Power BI.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
Levi Strauss
Levi Strauss
2 months ago

Sr. Cyber Risk Analyst

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 2 hours agoStatus: Live

Job Summary

Implement the cyber risk operational strategy as part of the Cyber Risk team. Manage the OneTrust GRC tool, perform internal and third-party security risk assessments, and align governance to ISO 27005, the CIS Top 18 Controls, and the NIST Cybersecurity Framework. Own policy lifecycle management, exception handling, risk register maintenance, remediation tracking, and leadership reporting, including building KRIs and continuous control monitoring workflows using OneTrust and Power BI.
Location: Mexico City
Workplace: Onsite
Employment Type: Full time
Job Function: Cybersecurity
Seniority: Manager level

Key Responsibilities

  • •Implement the cyber risk operational strategy for the Cyber Risk team, including managing the OneTrust GRC tool and escalating strategic decisions to the risk manager.
  • •Perform internal and third-party security risk assessments; tier vendors and select/prioritize controls based on risk assessment frameworks.
  • •Drive policy lifecycle management and maintain governance of the Cyber Risk Policy, including attestation, communication, issue/action tracking, and revisions.
  • •Maintain and manage the enterprise cyber risk register and exception/remediation processes, ensuring risks are current with clear remediation tasks and tracked outcomes.
  • •Develop and deliver risk reporting for senior leadership; build cyber risk KRIs using OneTrust and Power BI and support continuous control monitoring workflows.

Key Requirements

  • •BS or MA in Business, Computer Science, Information Security, or a related field.
  • •Industry security certifications (e.g., CISSP, CISM, CRISC) or the intent to pursue one within a year.
  • •3+ years of experience in cybersecurity risk management, governance, and regulatory requirements focused on business outcomes and service delivery.
  • •3+ years performing internal and third-party risk assessments and conducting control selection based on risk assessment frameworks.
  • •Experience with compliance obligations such as PCI-DSS, HIPAA, and SOX, plus frameworks including ISO 27005, NIST Cybersecurity Framework, CIS Top 18, and MITRE ATT&CK.
Experience:CybersecurityRisk managementGRCThird-party risk
Education:
Skills:Analytical thinkingProblem-solvingCommunicationInfluencingData analysis
Certifications:CISSPCISMCRISC
Tech Stack:OneTrustPowerBIPower BIPCI-DSSHIPAASOXISO 27005NIST Cybersecurity FrameworkCIS Top 18MITRE ATT&CK

Company Brief

Levi Strauss
Designs, markets, and sells denim and casual apparel under the Levi's, Dockers, and related brands. The company operates globally through wholesale, retail, and direct-to-consumer channels.
Industry: Fashion & Apparel
Company Size: Enterprise (1,001+ employees)
Revenue: USD 5M to 10M
Growth: Public Company
Valuation: Public Company (Market Cap in USD)
Funding: IPO / Publicly Listed
Headquarters: San Francisco, United States
Founded: 1853
WebsiteLinkedIn