1

Cyber Risk Assessment Jobs in Orem, UT (NOW HIRING)

Showing results 41-42

Cyber Risk Assessment information

What is the difference between Cyber Risk Assessment vs Cyber Security Analyst?

AspectCyber Risk AssessmentCyber Security Analyst
Primary FocusIdentifying and evaluating cybersecurity risks and vulnerabilitiesMonitoring, detecting, and responding to security threats
CertificationsCompTIA Security+, CISSP, CISACompTIA Security+, CEH, CISSP
Work EnvironmentRisk management teams, consulting firms, security departmentsSecurity operations centers, IT departments, incident response teams
ResponsibilitiesRisk analysis, vulnerability assessments, complianceThreat detection, incident response, security monitoring

While both roles involve cybersecurity, Cyber Risk Assessments focus on evaluating potential risks and vulnerabilities to inform security strategies, whereas Cyber Security Analysts actively monitor and respond to ongoing security threats. Understanding these differences helps organizations assign the right roles for comprehensive cybersecurity management.

What is a cyber risk assessment?

A cyber risk assessment is a process used to identify, evaluate, and prioritize potential threats and vulnerabilities in an organization's information systems. It helps organizations understand the potential impact of cyber threats and determine the likelihood of such events occurring. By conducting a cyber risk assessment, businesses can implement appropriate security controls and strategies to mitigate risks, comply with regulatory requirements, and protect sensitive data from cyberattacks. Regular assessments are essential to adapt to evolving threats and maintain a strong cybersecurity posture.

What are some common challenges faced by professionals in cyber risk assessment, and how can they be addressed?

Professionals in Cyber Risk Assessment often encounter challenges such as rapidly evolving threat landscapes, keeping up with regulatory changes, and ensuring clear communication of technical risks to non-technical stakeholders. To address these, staying current with industry trends through continuous learning, leveraging robust risk assessment frameworks, and developing strong communication skills are essential. Additionally, collaborating closely with IT, compliance, and business units helps ensure comprehensive and effective risk management.

What are the key skills and qualifications needed to thrive as a cyber risk assessor?

To thrive as a Cyber Risk Assessor, you need a strong understanding of cybersecurity principles, risk management frameworks, and relevant regulations, often backed by a degree in information security or related certifications like CISSP or CISA. Familiarity with security assessment tools, vulnerability scanners, and risk analysis platforms is typically required. Analytical thinking, attention to detail, and effective communication are vital soft skills for accurately identifying threats and conveying risks to stakeholders. These skills and qualities are crucial for protecting organizational assets and ensuring compliance in an evolving threat landscape.

What are popular job titles related to Cyber Risk Assessment jobs in Orem, UT?

For Cyber Risk Assessment jobs in Orem, UT, the most frequently searched job titles are:

What cities near Orem, UT are hiring for Cyber Risk Assessment jobs?

Cities near Orem, UT with the most Cyber Risk Assessment job openings:

Infographic showing various Cyber Risk Assessment job openings in Orem, UT as of June 2026, with employment types broken down into 1% As Needed, 88% Full Time, 9% Part Time, and 2% Contract. Highlights an 93% Physical, 3% Hybrid, and 4% Remote job distribution.

Cybersecurity Red Team-Penetration Tester

Zions Bancorporation

Midvale, UT • On-site

Full-time

Medical, Dental, Vision, Life, Retirement, PTO

Posted 15 days ago


Zions Bancorporation rating

8.2

Company rating: 8.2 out of 10

Based on 45 frontline employees who took The Breakroom Quiz

51st of 171 rated banks


Job description

Zions Bancorporation is transforming what it means to work for a financial institution. With a commitment to technology and innovation, we have been providing our community, clients, and colleagues with the best experience possible for over 150 years. Help us transform our workforce of the future, today.
We are seeking a highly skilled and driven Cybersecurity Red Team-Penetration Tester to join our offensive security team. In this role, you will think like an adversary to proactively identify, exploit, and help remediate complex security vulnerabilities across our enterprise infrastructure, applications, and cloud environments.
Rather than just running automated scanners, you will design and execute sophisticated, real-world cyberattack simulations and manually dissect systems to identify deep-seated security flaws. As a critical partner to our Incident Response and development groups, your ultimate goal is not just to find weaknesses, but to collaboratively strengthen our overall security posture and educate internal stakeholders on emerging adversarial tactics.
Key Responsibilities
  • Emulate Advanced Adversaries: Execute comprehensive red team operations and objective-based testing to simulate real-world cyberattacks, testing both technical controls and incident response capabilities.
  • Conduct Multidisciplinary Testing: Perform manual and automated penetration testing across web applications, APIs, cloud environments (AWS/Azure/Kubernetes), internal/external networks, and operating systems (Windows, Active Directory, Linux).
  • Audit and Attack AI Systems: Design and execute adversarial simulations against Large Language Models (LLMs) and machine learning pipelines to identify enterprise vulnerabilities, verifying that deployed AI applications are resilient to manipulation and data exposure.
  • Develop Custom Exploits: Design, write, and modify custom scripts and tools to bypass modern endpoint detection and response (EDR) agents and navigate restrictive environments.
  • Deliver Clear Reporting: Translate complex technical findings into detailed, actionable remediation reports and present risk impact clearly to both technical developers and non-technical stakeholders.
  • Collaborate for Remediation: Partner closely with Cyber Threat Intelligence, Incident Response, Detection Engineering and development groups to provide post-assessment debriefs, validate remediation efforts, and continuously strengthen the overall security posture.

Qualifications:
  • Adversarial Frameworks: Deep practical knowledge of industry frameworks and standards, primarily the MITRE ATT&CK matrix, OWASP Top 10, and NIST.
  • AI & LLM Vulnerability Exploitation: Practical understanding of the OWASP Top 10 for LLMs and hands-on experience executing attacks such as prompt injection (direct and indirect), training data poisoning, model inversion, and API-based data exfiltration.
  • Commercial & Custom Tooling: Proficient hands-on experience with offensive security suites, including C2 frameworks (e.g., Cobalt Strike), proxy utilities (Burp Suite), scanners (Nessus, Nmap), exploitation platforms (Metasploit) and breach and attack simulation platforms (BAS).
  • Active Directory Domain Dominance: Proven experience exploiting AD environments, including Kerberoasting, AS-REP roasting, pass-the-hash, golden/silver ticket attacks, and domain delegation flaws.
  • Scripting & Automation: Strong programming capability in languages such as Python, PowerShell, Bash, or Go to automate tasks and build custom tooling.
  • Cloud Security: Experience identifying misconfigurations and exploiting cloud-native infrastructure within AWS, Microsoft Azure, or containerized environments (Kubernetes/Docker).
  • Professional Experience: 5+ years of dedicated professional experience focusing on network penetration testing, application security testing, or red teaming.
  • Educational Background: Bachelor's degree in Computer Science, Cybersecurity, Information Security, or a related field (or equivalent hands-on industry experience).
  • Industry Certifications (Highly Valued):
    • OSCP (Offensive Security Certified Professional) or OSCE / OSEP
    • SANS/GIAC certifications (e.g., GPEN, GXPN, GWAPT)
    • HTB Certified Penetration Testing Specialist (CPTS)

Work Location:
This position has a hybrid work from home schedule with a minimum of three days per week in the office at the new Zions Technology Center in Midvale, UT
The Zions Technology Center is a 400,000-square-foot technology campus in Midvale, Utah. Located on the former Sharon Steel Mill superfund site, the sustainably built campus is the company's primary technology and operations center. This modern and environmentally friendly technology center enables Zions to compete for the best technology talent in the state while providing team members with an exceptional work environment with features such as:
  • Electric vehicle charging stations and close proximity to Historic Gardner Village UTA TRAX station.
  • At least 75% of the building is powered by on-site renewable solar energy.
  • Access to outdoor recreation, parks, trails, shareable bikes and locker rooms.
  • Large modern cafe with a healthy and diverse menu.
  • Healthy indoor environment with ample natural light and fresh air.
  • LEED-certified sustainable building that features include the use of low VOC-emitting construction materials.

Benefits:
  • Medical, Dental and Vision Insurance - START DAY ONE!
  • Life and Disability Insurance, Paid Parental Leave and Adoption Assistance
  • Health Savings (HSA), Flexible Spending (FSA), and dependent care accounts
  • Paid Training, Paid Time Off (PTO) and 11 Paid Federal Holidays
  • 401(k) plan with company match, Profit Sharing, competitive compensation in line with work experience
  • Mental health benefits including coaching and therapy sessions
  • Tuition Reimbursement for qualifying employees
  • Employee Ambassador preferred banking products

What Zions Bancorporation employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom