Responsibilities
Support customer third‑party security due diligence assessments.
Support or lead mitigation workshops to translate penetration test and assessment findings into prioritized remediation workplans.
Analyze technical findings and map them to governance, risk, and control gaps.
Review Implementation of technical security controls.
Perform security maturity assessments, including reviews of organizational policies, standards, procedures, and governance practices, aligned with the NIST CSF 2.0 cybersecurity framework.
Produce clear, structured reports and executive‑ready summaries for technical and non‑technical audiences.
Qualifications
1–2 years in cybersecurity GRC, IT risk, compliance, audit/assurance, or related process‑oriented security roles.
Strong understanding of governance, risk management, and operational processes.
Familiarity with cybersecurity frameworks (NIST CSF, ISO 27001 concepts), risk assessment, mitigation planning, and third‑party risk management.
Basic conceptual understanding of cloud/SaaS shared responsibility models.
Ability to communicate technical issues in business‑aligned language.
Strong writing, communication, and facilitation skills.
Comfortable collaborating with internal stakeholders and external customers.
Skills Required
- 1-2 years in cybersecurity GRC, IT risk, compliance, audit/assurance, or related process-oriented security roles
- Strong understanding of governance, risk management, and operational processes
- Familiarity with cybersecurity frameworks (NIST CSF, ISO 27001 concepts), risk assessment, mitigation planning, and third‑party risk management
- Basic conceptual understanding of cloud/SaaS shared responsibility models
- Ability to communicate technical issues in business-aligned language
- Strong writing, communication, and facilitation skills
- Comfortable collaborating with internal stakeholders and external customers
What We Do
CYE’s optimized cyber risk quantification platform and expert guidance transform the way organizations manage cybersecurity. Using AI, machine learning, and innovative technology, CYE visualizes attack routes, quantifies, mitigates, and communicates cyber risk, and matures organizational cybersecurity posture. In doing so, CYE provides clear and relevant insights that empower companies to make effective cybersecurity decisions. The company serves organizations in multiple industries globally. Founded in 2012, with headquarters in Israel and operations around the world, CYE is funded by EQT Private Equity and 83North.







