External candidates: In order for your application to be correctly processed please sign-in before you apply
Internal candidates: Please go to Workday and click "Find Jobs" link under Career
Thank you for considering opportunities with us!
Job Title
Cybersecurity Analyst V - RemoteRequisition Number
R8025 Cybersecurity Analyst V - Remote (Open)Location
Arizona - Home TeleworkersAdditional Locations
Job Information
CSAA Insurance Group (CSAA IG), a AAA insurer, is one of the leading personal lines property and casualty insurance groups in the United States. Here, every employee shapes our mission. We build innovative, human-centered solutions that help AAA members prevent, prepare for, and recover from life's uncertainties. You will join a collaborative, inclusive culture where your strengths have room to grow and your ideas can drive real impact. Step into a role where you can contribute to our shared success through meaningful work.
We are actively hiring for a Cybersecurity Analyst V - Remote
Your Role: As a senior cybersecurity risk professional, you will serve as a strategic advisor to business and technology leaders, helping identify, assess, and manage complex cybersecurity and technology risks. You will lead cross-functional risk initiatives, influence security and risk management strategies, and help strengthen the organization's risk posture. This role requires the ability to translate technical risks into clear business impact, provide actionable recommendations, and guide decision-making related to cybersecurity investments, controls, and governance. Operating with a high degree of autonomy, you will build trusted partnerships across the organization and contribute to the continuous evolution of cybersecurity risk management practices.
Your Work: Risk advisory and assessment
- Lead cross-domain cybersecurity and technology risk assessments for complex initiatives, critical business processes, control environments, and emerging technologies, including cloud and artificial intelligence use cases.
- Define and improve risk assessment approaches, methodologies, standards, and supporting tools to promote consistent identification, analysis, documentation, and treatment of risk.
- Apply qualitative and quantitative analysis, including probability, impact, and scenario-based methods, to clarify exposure, compare response options, and support risk-informed decisions.
- Evaluate the design and effectiveness of cybersecurity controls and technologies, identify material gaps or systemic themes, and recommend proportionate mitigation, acceptance, transfer, or avoidance strategies.
Strategic guidance and cross-functional influence
- Serve as a strategic advisor to technology, cybersecurity, and business partners on risk, governance, control, and operational implications.
- Translate complex technical risk into concise business impact, options, trade-offs, and recommendations for leaders and non-technical audiences through briefings, presentations, whitepapers, and position papers.
- Lead workshops and team member discussions that establish shared understanding, resolve ambiguity, and drive alignment on risk ownership, treatment decisions, priority, and resource needs.
- Integrate risk considerations into the lifecycle of technology projects, capabilities, and business initiatives, translating technical risk into business impact and supporting informed decision-making aligned with organizational objectives.
Capability and program development
- Lead risk framework, reporting, tooling, capability-building, and maturity improvement efforts that span cybersecurity domains and functions.
- Identify trends and interdependencies across risks, controls, technologies, and business operations; communicate implications and recommend program-level improvements.
- Mentor analysts and risk professionals, share advanced analytical practices, and strengthen consistent application of cybersecurity risk management methods.
- Maintain awareness of emerging threats, evolving technologies, regulatory requirements, and industry trends, using these insights to strengthen and enhance cybersecurity risk advisory capabilities.
Required Experience, Education and Skills
- 8-10 years of progressive experience in cybersecurity, technology risk management, IT operations, IT audit, governance, compliance, or related technical fields.
- Demonstrated experience leading complex analyses or cross-functional initiatives, advising stakeholders on risk and control implications, and delivering major work products with a high degree of autonomy.
- Experience applying cybersecurity risk management methodologies, control frameworks, governance models, and supporting tools in an enterprise environment.
- Bachelor's degree in Cybersecurity, Information Systems, Computer Science, Information Technology, or a related field; or equivalent practical experience may be considered in place of a bachelor's degree.
What would make us excited about you?
- Recognized domain expertise in cybersecurity risk management, governance, control assessment, risk response, and capability or maturity models. Thorough knowledge of cybersecurity standards and frameworks such as NIST, ISO 27001, and CIS Controls, with the ability to advise on practical application.
- Broad understanding of cybersecurity domains and the technologies they protect, including cloud services, networks and infrastructure, applications, data, identity, databases, protocols, security tools, and emerging technologies. Understands how security capabilities and controls reduce cybersecurity risk.
- Exceptional problem analysis in complex, ambiguous, or novel scenarios. Identifies systemic issues and broader implications; develops defensible solution paths; and explains cost, benefit, uncertainty, and residual risk.
- Exceptional understanding of measurement, probability, statistics, metrics, and quantitative risk concepts, including cyber risk quantification, sufficient to develop or apply models and communicate limitations responsibly.
- Identifies and assesses business and technology challenges, performs root cause analysis, recommends risk-informed technology solutions, and drives implementation to support organizational objectives and mitigate risk.
- Connects cybersecurity and technology risk to business services, processes, strategic objectives, and industry context. Considers programmatic and organizational impacts when developing recommendations.
- Operates with a high degree of autonomy on complex initiatives, providing direction for high-impact work, leading cross-functional efforts, and mentoring team members while maintaining accountability for quality, timeliness, and outcomes.
- Actively shapes our company culture (e.g., supporting employee resource groups, mentoring employees, volunteering, joining cross-functional projects)
- Champions our cultural norms (e.g., willing to have cameras when it matters: helping onboard new team members, building relationships, etc.)
- Demonstrates a company ownership mindset, thinking beyond boundaries of their own area
- Travels as needed for role, including divisional / team meetings and other in-person meetings
- Fulfills business needs, which may include investing extra time, helping other teams, etc
Please note we are hiring for this role remote anywhere in the United States with the following exceptions: Hawaii and Alaska.
Why Choose a Career at CSAA IG?
At CSAA IG, we are a mission-driven organization proudly committed to empowering our members, our employees, and our communities to thrive.
Recognition: We offer a total compensation package, annual bonus eligibility for most roles, 401(k) with a company match, and so much more! Read more about what we offer and what it is like to be a part of our dynamic team at https://careers.csaainsurance.aaa.com/us/en/benefits.
Career Growth: We believe in growth for everyone. Here at CSAA IG, leaders and mentors partner with employees to align interests, unlock development opportunities, and support long‑term success.
Flexible Workplace: We embrace a remote-first culture through our Flexible Workplace. Most employees hold Home-Flex roles, working primarily from home, often with the flexibility to work from various locations including CSAA offices. Our flexible workplace empowers you to balance remote work with intentional in‑person moments that deepen connection and collaboration.
Inclusion and Belonging: An inclusive and welcoming workplace is the cornerstone of our success. By fostering an environment where people feel valued and heard, we deepen our ability to understand and meet the unique needs of our members. This strengthens innovation and enhances our products and services, giving us a competitive edge in the market.
Sustainability: As climate change leads to more frequent and severe weather events, we are taking bold action to build more resilient communities and reduce our environmental impact. Submit your application to be considered. We communicate via email, so check your inbox and/or your spam folder to ensure you don’t miss important updates from us.
CSAA is committed to providing reasonable accommodations to qualified applicants and employees with disabilities or other limitations. If you would like to request an accommodation to participate in the job application or interview process, please contact [email protected]
If you apply and are selected to continue in the recruiting process, we will schedule a preliminary call with you to discuss the role and will disclose during that call the available salary/hourly rate range based on your location. Factors used to determine the actual salary offered may include location, experience, or education.
CSAA does not provide visa sponsorship for this role. Applicants must have authorization to work indefinitely in the US. Please do not apply for this role if at any time (now or in the future) you will need immigration support (i.e., H-1B, TN, STEM OPT Training Plans, etc.).
CSAA Insurance Group is an equal opportunity employer.
#LI-SB1
The national average salary range for this position is $136,890.00-$152,100.00. However, we have a location-based compensation structure. Our salary ranges vary and are calculated based on work location. The starting pay range for this position across all the states we hire in is $136,890.00-$182,450.00. This role also includes an opportunity for a company-wide annual discretionary bonus, through our Annual Incentive Plan (AIP), of up to 12% of eligible pay.This job posting will be unposted on Fri, 23 Oct 2026.Skills Required
- 8-10 years of progressive experience in cybersecurity, technology risk management, IT operations, IT audit, governance, compliance, or related technical fields
- Experience leading complex analyses or cross-functional initiatives and advising stakeholders on risk and control implications
- Experience delivering major work products with a high degree of autonomy
- Experience applying cybersecurity risk management methodologies, control frameworks, governance models, and supporting tools in an enterprise environment
- Bachelor's degree in Cybersecurity, Information Systems, Computer Science, Information Technology, or a related field, or equivalent practical experience
- Expertise in cybersecurity risk management, governance, control assessment, risk response, and capability or maturity models
- Knowledge of NIST, ISO 27001, and CIS Controls
- Understanding of cybersecurity domains and technologies including cloud services, networks, infrastructure, applications, data, identity, databases, protocols, security tools, and emerging technologies
- Understanding of measurement, probability, statistics, metrics, quantitative risk concepts, and cyber risk quantification
- Experience with root cause analysis and developing risk-informed technology solutions
- Ability to connect cybersecurity and technology risk to business services, processes, strategic objectives, and industry context
- Ability to lead complex initiatives, provide direction, mentor team members, and maintain accountability for outcomes
- Willingness to travel as needed for divisional, team, and in-person meetings
CSAA Insurance Group Compensation & Benefits Highlights
The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about CSAA Insurance Group and has not been reviewed or approved by CSAA Insurance Group.
-
Fair & Transparent Compensation — Pay is considered good or competitive across many roles, with base compensation often viewed as solid for the work. Feedback suggests overall compensation feels stronger when flexibility and attainable bonuses are part of the package.
-
Retirement Support — 401(k) matching and annual profit sharing, with immediate vesting, are highlighted as meaningful strengths in total rewards. Tuition reimbursement and student‑loan support further reinforce the company’s financial well‑being focus.
-
Leave & Time Off Breadth — Flexible Time Off or PTO, multiple paid company holidays, and dedicated paid enrichment time create a robust time‑off mix. A largely remote, flexible workplace helps employees make practical use of these benefits.
CSAA Insurance Group Insights
What We Do
Why we're forever forward -- At CSAA IG, one thing will always endure: our commitment to excellence in everything we do for our members, employees and communities. As insurance industry leaders, we know things can change in an instant. It’s why we’re here. We’re not afraid of change. We welcome it and use it to advance the cause. For employees, our cause is to become ever more inclusive and supportive of their goals and contributions. For our AAA Members, it’s finding new ways to help them prevent, prepare for and recover from whatever comes. For our communities, it’s exploring new ways of helping them meet evolving challenges. Whatever may happen, change becomes progress at CSAA IG. Benefits for today and for your future -- Benefits at CSAA IG represent our commitment to protect our employees by providing for their needs today and helping them prepare for a more secure future. Our suite of benefits is designed to provide for your physical, mental, social and financial health. Our sense of belonging keeps us together -- Belonging is the feeling of being welcomed and accepted for who you are and the qualities you bring. It’s knowing you’re heard and valued as an individual and employee. At CSAA IG, we share a strong sense of purpose and a hunger for adventure. Change should always be expected, but can’t always be predicted. Whatever happens, we remain true to our beliefs and clear on our purpose. We meet change head on and grow from each experience. A promise to act -- Life is uncertain, but we are not. When our AAA Members need us, we know how to move with the speed, expertise and confidence they rely on.








