1

Cyber Risk Assessment Jobs in Colorado (NOW HIRING)

... in cyber risk assessment activities including threat modeling, vulnerability analysis and analysis of mitigation solutions. 9. Coordinate with Cyber, System Architects and Developers to provide ...

Conducting cyber risk assessment activities, vulnerability analysis, and analysis of mitigation solutions. Developing, evaluating, and analyzing design constraints, trade-offs, and detailed system ...

next page

Showing results 1-20

Cyber Risk Assessment information

What is the difference between Cyber Risk Assessment vs Cyber Security Analyst?

AspectCyber Risk AssessmentCyber Security Analyst
Primary FocusIdentifying and evaluating cybersecurity risks and vulnerabilitiesMonitoring, detecting, and responding to security threats
CertificationsCompTIA Security+, CISSP, CISACompTIA Security+, CEH, CISSP
Work EnvironmentRisk management teams, consulting firms, security departmentsSecurity operations centers, IT departments, incident response teams
ResponsibilitiesRisk analysis, vulnerability assessments, complianceThreat detection, incident response, security monitoring

While both roles involve cybersecurity, Cyber Risk Assessments focus on evaluating potential risks and vulnerabilities to inform security strategies, whereas Cyber Security Analysts actively monitor and respond to ongoing security threats. Understanding these differences helps organizations assign the right roles for comprehensive cybersecurity management.

What is a cyber risk assessment?

A cyber risk assessment is a process used to identify, evaluate, and prioritize potential threats and vulnerabilities in an organization's information systems. It helps organizations understand the potential impact of cyber threats and determine the likelihood of such events occurring. By conducting a cyber risk assessment, businesses can implement appropriate security controls and strategies to mitigate risks, comply with regulatory requirements, and protect sensitive data from cyberattacks. Regular assessments are essential to adapt to evolving threats and maintain a strong cybersecurity posture.

What are some common challenges faced by professionals in Cyber Risk Assessment, and how can they be addressed?

Professionals in Cyber Risk Assessment often encounter challenges such as rapidly evolving threat landscapes, keeping up with regulatory changes, and ensuring clear communication of technical risks to non-technical stakeholders. To address these, staying current with industry trends through continuous learning, leveraging robust risk assessment frameworks, and developing strong communication skills are essential. Additionally, collaborating closely with IT, compliance, and business units helps ensure comprehensive and effective risk management.

What are the key skills and qualifications needed to thrive as a Cyber Risk Assessor, and why are they important?

To thrive as a Cyber Risk Assessor, you need a strong understanding of cybersecurity principles, risk management frameworks, and relevant regulations, often backed by a degree in information security or related certifications like CISSP or CISA. Familiarity with security assessment tools, vulnerability scanners, and risk analysis platforms is typically required. Analytical thinking, attention to detail, and effective communication are vital soft skills for accurately identifying threats and conveying risks to stakeholders. These skills and qualities are crucial for protecting organizational assets and ensuring compliance in an evolving threat landscape.
What are popular job titles related to Cyber Risk Assessment jobs in Colorado? For Cyber Risk Assessment jobs in Colorado, the most frequently searched job titles are:
What job categories do people searching Cyber Risk Assessment jobs in Colorado look for? The top searched job categories for Cyber Risk Assessment jobs in Colorado are:
What cities in Colorado are hiring for Cyber Risk Assessment jobs? Cities in Colorado with the most Cyber Risk Assessment job openings:
Infographic showing various Cyber Risk Assessment job openings in Colorado as of June 2026, with employment types broken down into 2% As Needed, 78% Full Time, 16% Part Time, 1% Temporary, and 3% Contract. Highlights an 92% Physical, 3% Hybrid, and 5% Remote job distribution.
Senior Cyber Risk & Compliance Specialist

Senior Cyber Risk & Compliance Specialist

York Space Systems

Greenwood Village, CO • On-site

$150K - $170K/yr

Full-time

Medical, Dental, Vision, Retirement, PTO

Posted 9 days ago


Job description

York Space Systems was founded to radically improve spacecraft affordability and reliability, transforming, and enabling next- generation space mission operations worldwide. Today, York is one of the most innovative aerospace companies, specializing in end-to-end customer solutions and the rapid production of spacecraft platforms. York's complete Space Segment Solution includes spacecraft production, payload integration, system integration & test, launch services, ground segment services, and mission operations, enabling customers to leverage York's existing technology solutions to get to orbit rapidly and responsively. We're looking to expand our team across the board.
Position Summary
York Space Systems is seeking a Senior Cyber Risk & Compliance Specialist to support and mature the company's cybersecurity governance, risk, and compliance programs. This individual will serve as a senior member of the Cybersecurity organization and play a critical role in driving CMMC Level 2 certification readiness, enterprise cyber risk management, audit support, third-party risk management, and cybersecurity governance initiatives.
This role requires an experienced cybersecurity professional capable of independently leading projects, collaborating with technical and business stakeholders, and translating regulatory and security requirements into practical, scalable solutions that support York's business objectives and national security mission.
Why Join York?
• Opportunity to support one of the fastest-growing aerospace and defense companies in the industry
• Direct impact on cybersecurity, compliance, and risk management initiatives supporting national security missions
• Exposure to CMMC, NIST SP 800-171, GCC High, enterprise cybersecurity governance, and AI governance programs
• Opportunity to help build and mature a rapidly growing cybersecurity organization
• TS/SCI clearance sponsorship for qualified cybersecurity personnel
Key Responsibilities
• Lead CMMC Level 2 implementation, readiness activities, and assessment preparation
• Own control testing, validation, and compliance monitoring activities
• Manage and mature the Plan of Action & Milestones (POA&M) program
• Conduct enterprise cyber risk assessments and facilitate risk management activities
• Maintain and mature the enterprise cyber risk register
• Perform control gap analyses and develop remediation recommendations
• Lead cybersecurity vendor and third-party risk reviews
• Support SOX IT General Controls (ITGC) compliance activities and audit engagements
• Coordinate internal and external audit responses
• Develop, maintain, and improve cybersecurity policies, standards, baselines, and procedures
• Support enterprise AI governance and cybersecurity governance initiatives
• Partner with IT, Engineering, Security Operations, Legal, HR, and business stakeholders to drive compliance and risk reduction efforts
• Support governance and oversight of cybersecurity technologies and platforms including Microsoft GCC High, identity and access management solutions, endpoint security technologies, and compliance management platforms
• Mentor junior team members and provide guidance on cybersecurity governance and compliance best practices
• Independently manage cybersecurity projects and program initiatives from planning through execution
Required Qualifications
• 7+ years of cybersecurity, risk, compliance, audit, governance, or related experience
• Experience supporting one or more cybersecurity frameworks such as CMMC, NIST SP 800-171, NIST Cybersecurity Framework (CSF), RMF, ISO 27001, FedRAMP, SOC 2, or SOX
• Experience conducting risk assessments and control evaluations
• Experience supporting audits, assessments, or regulatory compliance initiatives
• Strong understanding of cybersecurity risk management principles
• Excellent written and verbal communication skills
• Ability to work effectively across technical and non-technical teams
• Strong project management and organizational skills
• Ability to obtain a US security clearance
• Willingness to work onsite at our Greenwood Village, CO location
• US Citizenship
Preferred Qualifications
Experience in the following areas:
• Supporting defense, aerospace, government contracting, or highly regulated environments
• Supporting Microsoft GCC High environments
• Hyperproof or similar GRC platforms
• Supporting cybersecurity governance initiatives in cloud and hybrid enterprise environments
• Supporting AI governance, data governance, or emerging technology governance programs
Preferred Certifications
• CISSP
• CRISC
• CISA
• CMMC CCP or CCA
• Security+
Benefits
In addition to compensation, York Space Systems is proud to offer a comprehensive benefits package including medical, dental, and vision insurance along with PTO and a 401K.
How To Apply
Interested candidates are encouraged to apply by clicking the "Apply" link at the top of the page. York Space Systems will be accepting applications on a rolling basis until the position is closed. York Space Systems provides equal employment opportunities to all employees and applicants for employment and prohibits discrimination and harassment of any type without regard to race, color, religion, age, sex, national origin, disability status, genetics, military or protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state, or local laws. Must have permanent authorization to work in the United States. This policy applies to all terms and conditions or employment, including recruiting, hiring, placement, promotion, termination, layoff, recall, transfer, leaves of absence, compensation and training. YORK SPACE SYSTEMS IS AN EEO EMPLOYER.