Trouvez un emploi qui compte. Travaillez avec des personnes
qui se sentent concernées.

Principal Cyber Risk Analyst - Remote

Détails de l’offre d’emploi

Réf. de l’offre d’emploi:
178563
Lieux:
Providence, RI 02903
Flexibilité géographique:
À distance
Catégorie:
IT
Type d’emploi:
Temps plein
Statut de l’emploi :
Exempté
Date de clôture prévue:
16 octobre 2026
Base de rémunération
Annuel
Échelle salariale
$107700.00 - $195500.00 Annually ($51.78 - $93.99 Hourly)
Marque
UNFI

Job Overview: 

The Principal Cyber Risk Analyst is responsible for leading the organization's enterprise cyber risk management program by identifying, assessing, prioritizing, and reporting technology and cybersecurity risks across the enterprise. This role serves as a strategic advisor to technology, cybersecurity, and business leadership by providing risk insights that support decision-making, risk treatment strategies, regulatory compliance, and organizational resilience.

The position partners closely with cybersecurity, infrastructure, application, cloud, data, privacy, compliance, audit, and business stakeholders to establish a sustainable risk management framework, drive remediation efforts, measure risk reduction, and communicate risk posture to executive leadership and governance committees.

Job Responsibilities: 

Core Responsibilities 

  • Lead the identification, assessment, analysis, and prioritization of technology and cybersecurity risks across infrastructure, applications, cloud environments, operational technology, data platforms, and third-party ecosystems

  • Establish and maintain an enterprise-wide cyber risk register, ensuring risks are accurately documented, quantified, monitored, and reported

  • Provide expert guidance on emerging technology risks, threat trends, and control weaknesses that may impact organizational objectives

  • Translate complex technical risks into business-focused risk narratives, impacts, and mitigation strategies.

  • Lead risk review meetings and challenge sessions with technology and business leaders to ensure risks are understood, accepted, mitigated, or escalated appropriately

  • Partner with security, technology, and business teams to validate remediation plans and monitor progress toward risk reduction objectives

  • Facilitate discussions to remove barriers to remediation and ensure risk treatment activities align with enterprise priorities

  • Provide oversight of cybersecurity risk assessments associated with vendors, service providers, and strategic technology partners

  • Lead initiatives to enhance the organization's cyber risk management framework, methodology, tools, and reporting capabilities

  • Mentor junior analysts and provide thought leadership across the cyber risk management function

  • Act as a trusted advisor to senior technology leaders, cybersecurity leadership, risk officers, and business executives

  • Performs other duties as assigned

Job Requirements: 

Education/ Certifications: 

  • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Risk Management, Business Administration, or related field

  • One or more preferred certifications: 

    • CISSP

    • CRISC

    • CISM

    • CGEIT

    • CISA

    • FAIR Certification

Experience: 

  • 10+ years of progressive experience in cybersecurity, information security, technology risk management, governance, risk and compliance (GRC), audit, or related disciplines

  • Experience leading enterprise cyber risk assessments and facilitating risk evaluations across infrastructure, cloud platforms, applications, data, operational technology, and third-party environments

  • Demonstrated experience developing and managing cyber risk registers, issue management processes, risk treatment plans, and executive risk reporting

  • Experience partnering with technology owners and business leaders to prioritize remediation activities based on risk exposure and business impact

  • Experience supporting or leading regulatory, compliance, and audit initiatives including SOX, HIPAA, PCI-DSS, NIST, ISO 27001, and other relevant frameworks

  • Experience presenting cybersecurity risks, trends, and remediation status to executive leadership, governance committees, and internal audit stakeholders

  • Demonstrated success leading strategic cybersecurity initiatives and influencing cross-functional teams without direct authority

  • Experience developing and maturing cybersecurity governance, risk assessment, risk quantification, and reporting methodologies

  • Prior experience mentoring analysts and leading enterprise-scale risk programs preferred

Knowledge/Skills/Abilities:

  • Expert understanding of cybersecurity and risk management frameworks including NIST CSF, NIST RMF, COBIT, ISO 27001, CIS Controls, FAIR, and regulatory requirements

  • Strong knowledge of cybersecurity domains including identity management, network security, cloud security, application security, vulnerability management, data protection, disaster recovery, and third-party risk management

  • Ability to assess technical control deficiencies and translate findings into business risk statements understandable by executive leadership

  • Advanced understanding of risk governance, risk quantification, risk treatment planning, issue management, and control effectiveness measurement

  • Experience designing and implementing cyber risk metrics, key risk indicators (KRIs), and executive reporting dashboards

  • Strong facilitation and stakeholder management skills with demonstrated ability to drive consensus across technical and business teams

  • Exceptional written and verbal communication skills with experience presenting risk information to senior leadership and executive committees

  • Ability to influence Director, VP, and executive-level stakeholders through data-driven risk analysis and recommendations

  • Strong business acumen with the ability to align cybersecurity investments and remediation activities to enterprise objectives

  • Ability to lead large-scale risk and governance initiatives with minimal direction.

  • Strong analytical, critical thinking, and prioritization skills

  • Ability to establish risk-based decision frameworks that support remediation prioritization and resource allocation

  • Good judgment is required for this position as there may be times when direct supervision may not be immediately available

Work Environment: 

Remote Role: 

  • This position is classified as remote where the associate will perform remote work from their primary residence. Remote associates are welcome to work from the office but are not required to do so. While remote associates are not required to work from an office on a regular basis, they may be required to come to the office or other UNFI locations for necessary business reasons or if directed to do so by their manager.

Physical Environment/Demands: 

Office Roles:

  • Most work is performed in a temperature-controlled office environment. 

  • Incumbent may sit for long periods of time at a desk or computer terminal. 

  • While performing the duties of this job, the employee is regularly required to sit; use hands to finger, handle, or feel; reach with hands and arms; and talk or hear.   

  • Incumbent may use calculators, keyboards, telephones, and other office equipment in the course of a normal workday. 

  • Stooping, bending, twisting, and reaching may be required in the completion of job duties.

The above statements are intended to describe the general nature of the work performed by the employees assigned to this job. All employees must comply with Company policy and applicable laws. The responsibilities, duties and skills required of personnel so classified may vary within each department and/or location.

UNFI is an Equal Opportunity employer committed to creating an inclusive and respectful environment for all. All qualified applicants will receive equal consideration for employment without regard to race, color, age, religion, sex, sexual orientation, gender identity or expression, national origin, disability, protected veteran status, or other protected ground. Accommodation is available upon request for candidates taking part in all aspects of the job selection process. - Veteran/Disability. VEVRAA Federal Contractor.

Société:
United Natural Foods Inc.

Rémunération:

UNFI prévoit de payer le taux de rémunération mentionné ci-dessus (ou dans la fourchette de rémunération mentionnée ci-dessus) pour ce poste. La rémunération réelle, le cas échéant, dépendra d’un certain nombre de facteurs, y compris, mais sans s’y limiter, l’éducation, l’expérience, la formation et toute exigence en vertu des conventions collectives applicables. UNFI s’engage à faire preuve de transparence en matière de paie, conformément aux lois applicables des États/provinces et locales en vigueur.

Avantages:

Pour les postes à Washington (ou les postes pouvant être exercés à distance depuis Washington), cliquez ICI pour connaître les détails concernant les congés payés de l’État de Washington.

Les candidats embauchés pour ce poste seront également admissibles aux programmes d’avantages suivants : congé payé ; congé de maladie ; vacances et congé parental ; programme 401K (ou régime d'épargne-retraite au Canada) ; assurance médicale, soins dentaires, soins de la vue, assurance vie et assurance décès/démembrement accidentel ; programme d’assurance invalidité à court et à long terme, allocation de dépenses flexible et/ou compte d’épargne santé (États-Unis uniquement), sous réserve de satisfaire aux conditions d’admissibilité et aux modalités de ces programmes, et sous réserve de toute exigence en vertu des conventions collectives applicables.

Emplois dans le domaine de la vente uniquement : Pour les postes de vente rémunérés à la commission, la fourchette ci-dessus est une estimation de la rémunération totale potentielle à la commission au cours de la première année de l’employé, mais UNFI offre une période d’introduction d’un montant minimum de 680 $ par semaine. Après la période d’introduction, comme il s’agit d’un poste basé à 100 % sur les commissions, il n’y a pas de salaire fixe. Les plans de commission de UNFI ne sont pas plafonnés et les revenus moyens varient en fonction du territoire et des ventes réalisées, ainsi que d’autres facteurs.

Les politiques de UNFI en matière de rémunération, de prestations ou avantages sociaux et de congés payés sont susceptibles d’être modifiées à la seule discrétion de la société, dans le respect de la législation en vigueur. Cette offre d’emploi ne doit pas être interprétée comme une offre d’emploi comprenant certaines modalités ni comme une garantie de revenu minimum.

Joignez-vous à notre réseau de talents

Trouvez l’emploi qui vous convient
chez UNFI