Perform security risk assessments of third-party vendors including AI and mobile application reviews. * Lead the review, update, and communication of cybersecurity policies, standards, and procedures ...
Perform security risk assessments of third-party vendors including AI and mobile application reviews. * Lead the review, update, and communication of cybersecurity policies, standards, and procedures ...
Perform security risk assessments of third-party vendors including AI and mobile application reviews. * Lead the review, update, and communication of cybersecurity policies, standards, and procedures ...
Perform security risk assessments of third-party vendors including AI and mobile application reviews. * Lead the review, update, and communication of cybersecurity policies, standards, and procedures ...
Perform security risk assessments of third-party vendors including AI and mobile application reviews. * Lead the review, update, and communication of cybersecurity policies, standards, and procedures ...
Perform security risk assessments of third-party vendors including AI and mobile application reviews. * Lead the review, update, and communication of cybersecurity policies, standards, and procedures ...
The Senior Security Risk Management Consultant serves as a strategic advisor, liaison, and subject ... Responsibilities include leading complex risk assessments, guiding risk treatment strategies ...
The Senior Security Risk Management Consultant serves as a strategic advisor, liaison, and subject ... Responsibilities include leading complex risk assessments, guiding risk treatment strategies ...
The Senior Security Risk Management Consultant serves as a strategic advisor, liaison, and subject ... Responsibilities include leading complex risk assessments, guiding risk treatment strategies ...
The Senior Security Risk Management Consultant serves as a strategic advisor, liaison, and subject ... Responsibilities include leading complex risk assessments, guiding risk treatment strategies ...
The Senior Security Risk Management Consultant serves as a strategic advisor, liaison, and subject ... Responsibilities include leading complex risk assessments, guiding risk treatment strategies ...
The Senior Security Risk Management Consultant serves as a strategic advisor, liaison, and subject ... Responsibilities include leading complex risk assessments, guiding risk treatment strategies ...
The Manager, Information Security Risk and Consulting, operating under the direction of the ... This includes oversight of enterprise risk assessments across commercial off-the-shelf (COTS), open ...
The Manager, Information Security Risk and Consulting, operating under the direction of the ... This includes oversight of enterprise risk assessments across commercial off-the-shelf (COTS), open ...
The Manager, Information Security Risk and Consulting, operating under the direction of the ... This includes oversight of enterprise risk assessments across commercial off-the-shelf (COTS), open ...
The Manager, Information Security Risk and Consulting, operating under the direction of the ... This includes oversight of enterprise risk assessments across commercial off-the-shelf (COTS), open ...
The Manager, Information Security Risk and Consulting, operating under the direction of the ... This includes oversight of enterprise risk assessments across commercial off-the-shelf (COTS), open ...
The Manager, Information Security Risk and Consulting, operating under the direction of the ... This includes oversight of enterprise risk assessments across commercial off-the-shelf (COTS), open ...
Lead risk assessments across sites, personnel, supply chain, and external environment * Contribute to travel security, including risk and notification platforms, advisory and assistance, journey ...
Lead risk assessments across sites, personnel, supply chain, and external environment * Contribute to travel security, including risk and notification platforms, advisory and assistance, journey ...
Lead risk assessments across sites, personnel, supply chain, and external environment * Contribute to travel security, including risk and notification platforms, advisory and assistance, journey ...
Quick apply
Lead risk assessments across sites, personnel, supply chain, and external environment * Contribute to travel security, including risk and notification platforms, advisory and assistance, journey ...
Lead risk assessments across sites, personnel, supply chain, and external environment * Contribute to travel security, including risk and notification platforms, advisory and assistance, journey ...
Lead risk assessments across sites, personnel, supply chain, and external environment * Contribute to travel security, including risk and notification platforms, advisory and assistance, journey ...
Serve as a subject matter expert (SME) for performing vendor risk assessments to improve overall ... Define security configuration and operations standards for security system and applications ...
Serve as a subject matter expert (SME) for performing vendor risk assessments to improve overall ... Define security configuration and operations standards for security system and applications ...
... Vendor Assessments for the Vendor Risk Management team. This role will primarily focus on the following specific areas of responsibility: -Day-to-day management of Information Security risk ...
... Vendor Assessments for the Vendor Risk Management team. This role will primarily focus on the following specific areas of responsibility: -Day-to-day management of Information Security risk ...
Cybersecurity GRC Engineer (W2 Position)
Dearborn, MI · On-site
$60 - $65/hr
Risk Assessment, Risk Management, Compliance Professional, Auditing, Information Security * Risk Assessment - Candidates must be able to perform targeted risk assessments that compare the company ...
Quick apply
Cybersecurity GRC Engineer (W2 Position)
Dearborn, MI · On-site
$60 - $65/hr
Risk Assessment, Risk Management, Compliance Professional, Auditing, Information Security * Risk Assessment - Candidates must be able to perform targeted risk assessments that compare the company ...
Primary responsibilities include applications security, risk assessment, validation of security pen test results, problem resolution, system documentation, and system security management and support.
Primary responsibilities include applications security, risk assessment, validation of security pen test results, problem resolution, system documentation, and system security management and support.
Safety Manager
Detroit, MI · Hybrid
Conduct comprehensive safety, compliance, and security risk assessments of agency facilities, operations, and programs, and develop corrective action recommendations to mitigate identified risks.
Safety Manager
Detroit, MI · Hybrid
Conduct comprehensive safety, compliance, and security risk assessments of agency facilities, operations, and programs, and develop corrective action recommendations to mitigate identified risks.
IT Security Analyst
Lansing, MI · On-site
... the enterprise risk management process. * Assess the effectiveness of enterprise data security ... policies, processes, procedures and controls against established standards, guidelines and ...
IT Security Analyst
Lansing, MI · On-site
... the enterprise risk management process. * Assess the effectiveness of enterprise data security ... policies, processes, procedures and controls against established standards, guidelines and ...
Conduct regular physical security risk assessments and site audits * Oversee design, implementation, and maintenance of physical security systems, including: * CCTV / Video Surveillance (including AI ...
Quick apply
Conduct regular physical security risk assessments and site audits * Oversee design, implementation, and maintenance of physical security systems, including: * CCTV / Video Surveillance (including AI ...
Risk & Controls Manager
Detroit, MI · On-site
... Risk assessment experience (advisory or associate), private sector preferred Dealing with open issues and creating remediation plans. Knowledge of security related standards and guidelines ...
Risk & Controls Manager
Detroit, MI · On-site
... Risk assessment experience (advisory or associate), private sector preferred Dealing with open issues and creating remediation plans. Knowledge of security related standards and guidelines ...
Freelance Security Risk Assessment information
What is the difference between Freelance Security Risk Assessment vs Security Consultant?
| Aspect | Freelance Security Risk Assessment | Security Consultant |
|---|---|---|
| Credentials | Certifications like CISSP, CISA, or CEH often required | Similar certifications, often with additional experience requirements |
| Work Environment | Independent, project-based, often remote or on-site at client locations | Typically employed by firms or consulting agencies, may work on multiple projects |
| Industry Usage | Used by organizations seeking independent risk assessments | Engaged for broader security strategy, policy development, and consulting |
While both roles involve assessing security risks, Freelance Security Risk Assessments focus on independent, project-specific evaluations, whereas Security Consultants often provide ongoing security advice and strategy within organizations or consulting firms.
Full-time
Medical, Retirement, PTO
Posted 18 days ago
Job description
Amerisure creates exceptional value for its partners, policyholders, and employees. As a property and casualty insurance company, Amerisure's promise to our partner agencies and policyholders begins with a comprehensive line of insurance products designed to protect businesses, as well as the health and safety of every employee. With an A.M. Best "A" (Excellent) rating, Amerisure serves mid-sized commercial enterprises focused in construction, manufacturing and healthcare. Ranked as one of the top 100 Property & Casualty companies in the United States, we proudly manage nearly $1 Billion of Direct Written Premium and maintain $1.21 billion in surplus.
Amerisure is currently recruiting for a Senior IT Security Risk Analyst that can do a 3-day hybrid approach onsite in our Farmington Hills office. The ideal candidate will also possess the following skill set.
Summary Statement
The Senior IT Security Risk Analyst is responsible for leading the organization's cybersecurity governance, risk, and compliance initiatives. This role drives the design, implementation, and continuous improvement of the IT risk program, ensuring alignment with regulatory requirements (e.g., New York State Department of Financial Services, NIST CSF) and business objectives.
Essential Tasks/Major Duties
- Perform security risk assessments of third-party vendors including AI and mobile application reviews.
- Lead the review, update, and communication of cybersecurity policies, standards, and procedures to ensure alignment with global frameworks (e.g., NIST CSF, NYDFS, NIS2, PCI DSS).
- Lead and maintain the IT Risk Register including metrics which provides leadership an overall view of IT risk.
- Perform risk assessments of IT risks.
- Map regulations to policies and controls.
- Create risk and compliance metrics for management and compliance purposes.
- Perform control testing and validation to ensure proper control effectiveness.
- Support IT audits and controls around Model Audit Rule (MAR).
- Monitor threat intelligence to determine potential impact to environment and remediation urgency.
- Support vulnerability management program, daily security operations and identity tasks as needed.
- Be a key advisor to leadership, translating cybersecurity risk into business impact and enabling informed decision-making.
Knowledge, Skills & Abilities
- Bachelor's degree or equivalent combination of education and experience.
- 5 years cybersecurity experience.
- Advanced Cyber Risk Management domain specific professional certification required: Certified Information Systems Security Professional (CISSP); Certified Information Security Manager (CISM); Certified in Risk and Information Systems Control (CRISC); Certified Cloud Security Professional (CCSP); AWS Certified Security.
- 2 years experience performing IT security control testing.
- Experience reviewing SOC 2 Type 1 and Type 2 reports to articulate potential security risk.
- Expertise in conducting third-party cyber risk assessments.
- Proficient in NIST security domain frameworks and architectures.
- Experience in Logicgate or another GRC tool.
- Experience using AI driven tools to enhance automation and operational efficiency.
- Ability to quickly diagnose security control problems and propose/implement solutions.
- Clear and concise articulation of risk to both technical peers and non-technical stakeholders.
- Partner with IT teams, developers, and business leaders to support security initiatives, and mentor and develop members of the security team.
- Analyze data and security trends to anticipate and assess potential threats.
- Stay current with regulations, evolving threats, technologies, and security protocols.
#LI-BR1
Just as we are committed to creating exceptional value for our Partners For Success agencies and policyholders, Amerisure also remains committed to being an employer of choice. We reinforce this commitment by adhering to an Employee Value Proposition that, in part, is provided through a competitive total rewards package. This package includes competitive base pay, performance-based incentive pay, comprehensive health and welfare benefits, a 401(k) savings plan with profit sharing, and generous paid time off programs. We also offer flexible work arrangements to promote work-life balance. Recognized as one of the Best and Brightest Companies to Work For in the Nation and one of Business Insurance magazine's Best Places to Work in Insurance, we provide a workplace that fosters excellence and professional growth. If you are looking for a collaborative and rewarding career, Amerisure is looking for you.
Amerisure Mutual Insurance Company is an Equal Employment Opportunity employer. Amerisure provides equal employment opportunities to all employees and applicants without regard to race, color, religion, sex (to include sexual orientation and gender identity), national origin, age, disability, genetic information, veteran status, or any other protected characteristic under applicable federal, state, or local laws. Amerisure complies with all applicable laws governing nondiscrimination in employment in all locations where the company operates. This policy applies to all terms and conditions of employment, including recruiting, hiring, placement, promotion, termination, layoff, recall, transfer, leaves of absence, compensation, and training. Amerisure prohibits harassment or discrimination of any kind and is committed to maintaining a workplace free from unlawful harassment or discrimination. Amerisure prohibits retaliation against anyone who reports discrimination, participates in an investigation, or opposes unlawful practices. Any improper interference with an employee's ability to perform their job duties may result in disciplinary action, up to and including termination.
About Amerisure
Sourced by ZipRecruiter
Industry
Insurance services
Company size
501 - 1,000 Employees
Headquarters location
Farmington, MI, US
Year founded
1912