Senior Analyst, Cybersecurity Risk & Compliance

3 Months ago • 5 Years + • Cyber Security • $100,000 PA - $140,000 PA

Job Summary

Job Description

The Senior Analyst, Cybersecurity Risk & Compliance will lead and support the Wind River Risk & Compliance function. This includes maintaining ISO 27001 certification and supporting obligations on NIST 800-171, including Governance Risk and Compliance (GRC) and Third Party Risk Management (TPRM). The role involves contributing to all ISO 27001 activities, supporting NIST 800-171 compliance efforts, and assisting in engagement with government compliance stakeholders. Furthermore, the role will be responsible for maintaining the Wind River Risk Register, coordinating the Security Exception process, and administering GRC/TPRM tooling. Additional responsibilities include preparing audit documentation, supporting customer assurance efforts, and implementing scalable governance processes.
Must have:
  • 5+ years of cybersecurity, compliance, or GRC experience.
  • Familiarity with ISO 27001, NIST 800-171 and GRC operations.
  • Strong writing skills, experience contributing to SSPs and POA&Ms.
  • Working knowledge of ZenGRC or similar tools.
  • Demonstrated ability to work across matrixed teams.
  • Experience with customer audit responses and regulatory compliance.
  • U.S. citizenship required.
Good to have:
  • Experience supporting government-mandated compliance frameworks.
  • Involvement in ISO 27001 recertification efforts or similar standards.
  • Experience with third-party risk tools.
  • Familiarity with Wind River or embedded systems companies.
Perks:
  • health, dental, vision insurance
  • life insurance
  • flex time off
  • eligibility to enroll in 401k
  • 12 paid holidays

Job Details

Description

Position at Wind River

Position Title: Senior Analyst, Cybersecurity Risk & Compliance (Hybrid)

Reports To: Director of Aptiv and Wind River Cybersecurity Risk, Compliance & Resilience

 Overview:

We are hiring a professional to support and help lead the Wind River Risk & Compliance function, with a primary focus on maintaining our ISO 27001 certification and supporting our obligations on NIST 800-171. The right candidate will support the Wind River Risk and Compliance program, which includes Governance Risk and Compliance (GRC), and Third Party Risk Management (TPRM), bring structure to our processes, and help stabilize and scale the function.

 

Key Responsibilities:

 

Regulatory & Standards Support:

  • Contribute to all ISO 27001 activities, including internal audit readiness, external recertification, and ongoing control maintenance.
  • Support NIST 800-171 compliance efforts, including maintenance of System Security Plans (SSPs), Plan of Action and Milestones (POA&Ms), and gap assessments.
  • Have working knowledge and able support GDPR, NIST CSF, CMMC, TISAX, ITAR, and AI related compliance as well as the ability to gain knowledge on future certification and regulation requirements.
  • Assist in engagement with government compliance stakeholders and maintain awareness of requirements.

 

Risk & Compliance Operations Governance Risk and Compliance (GRC) and Third-Party Risk Management (TPRM):

  • Maintain the Wind River Risk Register and track mitigation progress across all functional areas.
  • Coordinate the Security Exception process, ensuring proper documentation, approvals, and governance.
  • Including vendor assessments, reviews, remediation follow-up, and monitoring.
  • Write and update policy and standards and provide governance, oversight, and assurance.
  • Administer GRC/TPRM tooling (ZenGRC) and ensure evidence management and workflows are maintained and audit-ready. Have an understanding or ability to use ServiceNow and AuditBoard risk management products.

 

Audit & Customer Response:

  • Prepare audit documentation and assist with responses for internal and external audits.
  • Draft and maintain clear, consistent, and audit-ready documentation, including policies, control responses, and program updates.
  • Support customer assurance efforts related to ISO, NIST, and general cyber compliance.
  • Lead internal audits and assessments against Wind River.

 

Program Execution & Scalability:

  • Help implement scalable, repeatable governance processes for policy and standard creation and lifecycle management.
  • Assist in developing compliance procedures, checklists, and review frameworks.
  • Support workflows for User Access Reviews (UAR), TPRM, and continuous monitoring.

 

Collaboration:

  • Work cross-functionally with Aptiv Cybersecurity, IT, Legal, HR, and Engineering, across Aptiv, HellermannTyton, Winchester, and Intercable.
  • Support communication and coordination with external auditors and internal stakeholders (including Primary Security Officer, Aptiv Legal, WR and Aptiv leadership).
  • Support Cybersecurity Training at Wind River.

 

Required Qualifications:

  • 5+ years of cybersecurity, compliance, or GRC experience
  • Familiarity with ISO 27001, NIST 800-171, and enterprise GRC operations
  • Strong writing skills, with experience contributing to SSPs and POA&Ms
  • Working knowledge of ZenGRC or similar tools
  • Demonstrated ability to work across matrixed teams
  • Experience with customer audit responses and regulatory compliance
  • U.S. citizenship required due to regulatory requirements
  • Must be a local resident (or willing to relocate to) Alameda, CA or Boston, MA and agree to being on site three days per week in the office. 

 

Preferred Qualifications:

  • Experience supporting government-mandated compliance frameworks
  • Involvement in ISO 27001 recertification efforts or similar standards
  • Experience with third-party risk tools (e.g., BlueVoyant, BitSight)
  • Familiarity with Wind River or embedded systems companies is a plus

 

Why This Role Matters:

Wind River's ability to operate in national security and critical infrastructure markets depends on strong cybersecurity governance. This role helps ensure we maintain our certifications, deliver on regulatory and contractual obligations, and support internal and external stakeholders with confidence. It also supports balancing workloads currently spread across teams and positions the function for long-term stability.

Join us at Wind River, where we're not just shaping technology; we're shaping the future of a safer, more connected world. Your journey to make a meaningful impact begins here.   
 
APPLICANT PRIVACY NOTICE:  
Your privacy is of the utmost importance to us. At Wind River, we strictly adhere to all applicable data privacy laws. Please review Wind River's Applicant Privacy Notice, which can be found here.   
Wind River is an Equal Opportunity Employer with a commitment to diversity. We prohibit discrimination based on race, color, religion, gender, national origin, age, disability, veteran status, marital status, pregnancy, gender expression or identity, sexual orientation or any other legally protected status.
Compensation 
The annual base salary range for this role’s listed grade level is currently $100,000 to $130,00 plus a bonus for Boston, MA residents, and $110,000 to $140,000 plus a bonus for SF Bay Area residents. Salary ranges are determined through interviews and a review of the education, experience, knowledge, skills, location, and abilities of the applicant, and equity with other team members. Employees in this role are also eligible for the following benefits in accordance with the terms of the Company's plans: health, dental, vision insurance, life insurance, flex time off, eligibility to enroll in 401k, and 12 paid holidays.
 #LI-JP1

 

Similar Jobs

Capgemini - SAP Global Trade Services (GTS) Consultant

Capgemini

India (On-Site)
2 Months ago
Apollo - Senior Customer Success Engineer

Apollo

United Kingdom (Remote)
4 Months ago
London stock Exchange - Full-Stack C# Software Engineer

London stock Exchange

Toronto, Ontario, Canada (On-Site)
2 Months ago
Rackner - Assistant FSO

Rackner

Dayton, Ohio, United States (On-Site)
2 Months ago
perfect garbage studios - Senior Programmer

perfect garbage studios

(Remote)
8 Months ago
NCR Voyix - Information Security Engineer II

NCR Voyix

Chennai, Tamil Nadu, India (On-Site)
3 Months ago
Anavation - Information System Security Engineer

Anavation

Huntsville, Alabama, United States (On-Site)
1 Month ago
Cubic corporation - Principal Security Operations Engineer

Cubic corporation

Hyderabad, Telangana, India (On-Site)
1 Year ago
Optiv - Senior Cybersecurity Advisor

Optiv

Minneapolis, Minnesota, United States (Hybrid)
1 Year ago
Jane Street - Cybersecurity Engineering - Threat Modelling

Jane Street

London, England, United Kingdom (On-Site)
3 Months ago

Get notifed when new similar jobs are uploaded

Similar Skill Jobs

Anavation - Junior Information System Security Officer (ISSO)

Anavation

Washington, District Of Columbia, United States (On-Site)
3 Months ago
Riot Games - QA Engineer II - League of Legends, Cosmetics

Riot Games

Los Angeles, California, United States (On-Site)
4 Months ago
oportun - Senior Data Scientist

oportun

(Remote)
3 Months ago
Guardian - Audit Operations Senior

Guardian

Bethlehem, Pennsylvania, United States (Hybrid)
3 Months ago
Capgemini - Senior Change and Release Management

Capgemini

Mumbai, Maharashtra, India (On-Site)
2 Months ago
bytedance - Music Product Counsel - Global Legal

bytedance

San Jose, California, United States (On-Site)
9 Months ago
zoox - Senior Technical Program Manager - System Safety Clearance

zoox

Foster City, California, United States (Hybrid)
10 Months ago
Diligent Corporation - Senior Director, Product Marketing, Governance

Diligent Corporation

New York, New York, United States (On-Site)
3 Months ago
GameJobs - Senior Litigation Counsel

GameJobs

San Francisco, California, United States (Remote)
3 Months ago
Apple - Reliability Engineer

Apple

Sunnyvale, California, United States (On-Site)
1 Month ago

Get notifed when new similar jobs are uploaded

Jobs in Boston, Massachusetts, United States

Lambda - Engineering Manager - Inference Backend

Lambda

San Francisco, California, United States (Hybrid)
3 Months ago
WPI - Academic Advisor

WPI

Worcester, Massachusetts, United States (Hybrid)
1 Month ago
Shield AI - Senior Engineer, Software Autonomy Applications (R3694)

Shield AI

Washington, District Of Columbia, United States (On-Site)
3 Weeks ago
Pomelo - Data Scientist

Pomelo

United States (On-Site)
1 Month ago
Illumination - Creative Marketing Intern - Summer 2025

Illumination

Santa Monica, California, United States (Hybrid)
6 Months ago
Blinkhealth - Hub Relations Coordinator

Blinkhealth

Boise, Idaho, United States (On-Site)
2 Months ago
Polygon Labs - Product Manager - Fintech Labs

Polygon Labs

United States (Remote)
1 Month ago
HCL Tech - Angular Technical Lead with HTML/CSS

HCL Tech

Virginia, United States (On-Site)
2 Months ago
Salesforce - Business Development Representative - East

Salesforce

Atlanta, Georgia, United States (On-Site)
5 Months ago
Abridge - Payroll Analyst

Abridge

San Francisco, California, United States (Hybrid)
3 Months ago

Get notifed when new similar jobs are uploaded

Cyber Security Jobs

Optiv - Sr. Client Manager - Cybersecurity

Optiv

Winnipeg, Manitoba, Canada (On-Site)
3 Months ago
Lilith games - IT Engineer (Information Security)

Lilith games

Shanghai, China (On-Site)
3 Weeks ago
Jane Street - Cybersecurity Governance and Risk Specialist

Jane Street

London, England, United Kingdom (On-Site)
3 Months ago
endava - Senior Information Security Engineer

endava

Córdoba, Córdoba Province, Argentina (Remote)
2 Months ago
Qualcomm - Security Design Verification Engineer, Staff

Qualcomm

Cork, County Cork, Ireland (On-Site)
2 Months ago
Palo Alto Networks - Principal Site Reliability Engineer (Cortex Cloud Security Posture Management)

Palo Alto Networks

Santa Clara, California, United States (On-Site)
1 Month ago
Electronic Arts - Security Software Engineer

Electronic Arts

Vancouver, British Columbia, Canada (Hybrid)
2 Months ago
Optiv - Account Manager - Cybersecurity Sales

Optiv

Charlotte, North Carolina, United States (Hybrid)
1 Month ago
Alpha Sense - Senior Cloud Security Engineer

Alpha Sense

Mumbai, Maharashtra, India (On-Site)
2 Months ago
PayPal - Manager, Cybersecurity Risk

PayPal

San Jose, California, United States (On-Site)
1 Month ago

Get notifed when new similar jobs are uploaded

About The Company

Bengaluru, Karnataka, India (Hybrid)

Bengaluru, Karnataka, India (Hybrid)

Bengaluru, Karnataka, India (On-Site)

Bengaluru, Karnataka, India (On-Site)

Bengaluru, Karnataka, India (On-Site)

Bengaluru, Karnataka, India (Hybrid)

Bengaluru, Karnataka, India (On-Site)

Chennai, Tamil Nadu, India (On-Site)

Chennai, Tamil Nadu, India (On-Site)

Bengaluru, Karnataka, India (On-Site)

View All Jobs

Get notified when new jobs are added by Wind River

Level Up Your Career in Game Development!

Transform Your Passion into Profession with Our Comprehensive Courses for Aspiring Game Developers.

Job Common Plug