Technical Security Business Analyst required to translate technical SME input across Cyber Exposure/TVM domains into clear capabilities, requirements, processes, operating models, RACIs and measurable outcomes.
You'll work across Platforms, Operating Systems, Code, Repositories, SBOM, Identity & Entitlement and Suppliers, partnering with Security Operations, Product Groups, Cyber Assurance and Architecture.
Key Skills & Experience
- Strong Cyber Security/Exposure/Security Assurance BA experience.
- Experience translating security capabilities into requirements, processes, operating models, RACIs and outcomes.
- Good technical understanding of TVM, attack surface, configuration, endpoint and cloud security.
- Working knowledge of SSDLC, DevSecOps and security tooling - technically credible without needing to be the deep technical SME.
- Strong requirements and process engineering, including independently facilitating SME workshops and defining current/future-state processes.
- Experience designing cross-functional security processes, dependencies, hand-offs, ownership and escalation paths.
- Ability to assess capability maturity, gaps, priorities and integrations to support an effective Exposure Management roadmap.
- CTEM knowledge is highly desirable.