Associate Security Risk Management Specialist
United States, Chesterfield, MO, RGA HQ, United States
Full Time Mid-level / Intermediate USD 54K - 77K
Reinsurance Group of America
You desire impactful work.
You’re RGA ready
RGA is a purpose-driven organization working to solve today’s challenges through innovation and collaboration. A Fortune 500 Company and listed among its World’s Most Admired Companies, we’re the only global reinsurance company to focus primarily on life- and health-related solutions. Join our multinational team of intelligent, motivated, and collaborative people, and help us make financial protection accessible to all.
Position Overview
The Security Risk Analyst will be responsible for identifying, assessing, reporting, and monitoring security risks across RGA’s enterprise security and business functions. This role involves collaborating with various departments to ensure compliance with security policies and standards, while additionally recommending security measures to protect RGA’s assets from potential threats.
Principal Duties
• Conduct comprehensive security risk assessments of enterprise systems and processes, as well as provide recommendations for risk mitigation.
• Review, analyze, and provide recommendations for policy, standard, and baseline configuration exceptions.
• Perform vendor risk assessments to include inherent & residual risk identification, analysis, and mitigation, and additionally track risk remediation to completion.
• Provide recommendations for vendor contractual requirements stemming from vendor risk assessment outcomes.
• Serve as a project security advisor including risk analysis gate checks in the secure SDLC process.
• Conduct thorough threat modeling exercises to identify potential security vulnerabilities and risks.
• Stay current on security trends, threats, and best practices to continuously improve the organization's security posture.
• Perform other duties as assigned.
Requirements
Education
Required: High School Diploma, industry experience or degree in progress
Preferred: Bachelor’s degree or equivalent experience
Required Experience
• 0-2 years IT security, privacy, audit, controls and regulatory compliance, or related experience.
• Basic understanding of IT domains: infrastructure, networking, storage, databases, operating systems, cloud, applications, etc.
• Basic understanding of security technologies and domains, including: SSO, IAM, DLP, EDR, SIEM, firewalls, gateways, IDS/IPS, CASB, antivirus, SSDLC, cryptography, PKI, etc.
• General knowledge of business and technology operations; ability to work well within a team setting and maintain a high level of confidentiality.
• Developing knowledge of global standards and regulations regarding security, privacy, and fraud.
• Willingness to learn and stay current on data privacy, data security, and fraud threats and vulnerabilities.
• Basic organizational, planning and task management skills with high attention to detail; ability to adjust to changing priorities and work under tight timelines.
• Excellent customer service skills; ability to balance multiple priorities, deadlines and deliverables while maintaining a positive attitude.
• Oral and written communication skills; ability to convey information in a clear and concise manner and provide regular proactive updates to team members and key stakeholders.
• Quick to adapt to new methods; ability to be flexible when needed, take initiative and demonstrate accountability.
Preferred Experience
• Knowledge of risk and control frameworks/standards (e.g., NIST CSF, NIST 800-53, ISO/IEC 27001, NIST 800-30, ISO/IEC 27005, etc.).
• Insurance/Reinsurance industry knowledge/experience
• Information security, compliance, risk, or audit professional certifications, such as: Security+, SSCP, CCSK
• Project management skills/experience
Preferred Technical Experience
• Cloud assessment experience (AWS, Azure, Google Cloud, etc.)
• Cyber Risk Quantification (CRQ) experience (e.g., FAIR)
• Automation experience: Python, REST API, PowerShell, etc.
• Previous experience as a Systems Administrator, IT Auditor, Developer, Security Engineer, Penetration Tester, Cloud Engineer
#LI-CW1
#LI-hybrid
What you can expect from RGA:
Gain valuable knowledge from and experience with diverse, caring colleagues around the world.
Enjoy a respectful, welcoming environment that fosters individuality and encourages pioneering thought.
Join the bright and creative minds of RGA, and experience vast, endless career potential.
Compensation Range:
$54,435.00 - $77,755.00 AnnualBase pay varies depending on job-related knowledge, skills, experience and market location. In addition, RGA provides an annual bonus plan that includes all roles and some positions are eligible for participation in our long-term equity incentive plan. RGA also maintains a full range of health, retirement, and other employee benefits.
RGA is an equal opportunity employer. Qualified applicants will be considered without regard to race, color, age, gender identity or expression, sex, disability, veteran status, religion, national origin, or any other characteristic protected by applicable equal employment opportunity laws.
Tags: Antivirus APIs Automation AWS Azure CASB CCSK Cloud Compliance Cryptography EDR Firewalls GCP IAM IDS IPS Monitoring NIST NIST 800-53 PKI PowerShell Privacy Python REST API Risk analysis Risk assessment Risk management SDLC SIEM SSCP SSDLC SSO Vulnerabilities
Perks/benefits: Equity / stock options Flex hours Health care Insurance Salary bonus
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.