Sr. Cybersecurity Risk Analyst

Posted 11 Days Ago
Grand Rapids, MI, USA
In-Office
Senior level
Retail
The Role
Lead and mature the enterprise cybersecurity risk program: build and maintain the risk register, conduct risk and third-party assessments, support CMMC and related compliance, partner with IT to implement secure standards, communicate risk to stakeholders, and mentor junior analysts.
Summary Generated by Built In

Job Summary

The Sr. Cybersecurity Risk Analyst is responsible for leading and maturing the organization's cybersecurity risk management program. This role is accountable for identifying, assessing, and communicating cybersecurity risks across the enterprise, while driving alignment with regulatory requirements, including CMMC. The position will play a key role in building and maintaining the enterprise risk register, developing a third-party risk management program, and partnering with IT teams to establish and maintain secure standards and practices.

The ideal candidate combines strong analytical skills with practical experience in governance, risk, and compliance, and can translate technical risk into actionable business decisions.

 

Location: Onsite out of our Grand Rapids, MI office.

Work Authorization: Applicants must be currently authorized to work.

Principal Duties and Responsibilities

Risk Management and Governance

  • Lead the development and ongoing maintenance of the enterprise cybersecurity risk register, including risk identification, classification, ownership, and tracking.

  • Conduct and lead risk assessments for systems, applications, projects, and business initiatives.

  • Develop and implement risk management processes, methodologies, and reporting metrics.

  • Facilitate risk review sessions with business and IT stakeholders to ensure accountability and transparency.

  • Develop and track risk mitigation and remediation plans to closure.

Regulatory Compliance (CMMC and Related Frameworks)

  • Support and maintain the organization’s CMMC compliance program, including control mapping, evidence collection, and audit readiness.

  • Partner with internal stakeholders (IT, Legal, HR, Plant Operations) to ensure alignment with CMMC and other regulatory requirements.

  • Assist in preparing documentation and responses for assessments, audits, and regulatory inquiries.

  • Monitor evolving compliance requirements and translate them into actionable internal controls.

Third-Party Risk Management

  • Develop and mature a third-party cybersecurity risk management program.

  • Conduct security risk assessments of vendors, SaaS providers, Software, and external partners.

  • Evaluate vendor security posture, shared responsibility models, and contractual security requirements.

  • Partner with procurement and legal teams to integrate security requirements into vendor onboarding and contracting processes.

Security Standards and IT Partnership

  • Collaborate with IT and engineering teams to develop, implement, and maintain cybersecurity standards and secure configuration baselines.

  • Ensure security requirements are embedded into system design, architecture, and operational processes.

  • Provide risk-based guidance on system hardening, segmentation, and control implementation.

  • Support the development of policies, standards, and procedures that are practical, enforceable, and auditable.

Reporting and Communication

  • Communicate risk findings, trends, and recommendations to technical and non-technical stakeholders, including leadership.

  • Develop reporting for executive audiences, including risk summaries, metrics, and program maturity updates.

  • Support audit committee and leadership reporting as needed.

Continuous Improvement

  • Stay current on cybersecurity threats, regulatory changes, and industry best practices.

  • Identify opportunities to improve risk visibility, coverage, and program efficiency.

  • Mentor junior analysts and contribute to the maturity of the GRC function.

 

Qualifications

Required

  • Bachelor’s degree in Information Security, Computer Science, or related field (or equivalent experience).

  • 5+ years of experience in cybersecurity risk, governance, or compliance roles.

  • Experience building or maintaining a cybersecurity risk register and risk management processes.

  • Strong understanding of security frameworks (e.g., NIST, CMMC, ISO 27001).

  • Experience conducting third-party/vendor risk assessments.

  • Strong analytical, problem-solving, and risk evaluation skills.

  • Ability to translate technical risks into business impact.

  • Strong written and verbal communication skills.

Preferred

  • Experience supporting CMMC assessments or similar regulatory compliance programs.

  • Familiarity with manufacturing or operational technology (OT) environments.

  • Experience developing security standards or working closely with infrastructure and engineering teams.

  • Professional certifications such as CISSP, CISM, CRISC, or similar.


The Company is an Equal Opportunity Employer.




Skills Required

  • Bachelor's degree in Information Security, Computer Science, or related field (or equivalent experience)
  • 5+ years of experience in cybersecurity risk, governance, or compliance roles
  • Experience building or maintaining a cybersecurity risk register and risk management processes
  • Strong understanding of security frameworks (NIST, CMMC, ISO 27001)
  • Experience conducting third-party/vendor risk assessments
  • Strong analytical, problem-solving, and risk evaluation skills
  • Ability to translate technical risks into business impact
  • Strong written and verbal communication skills
  • Applicants must be currently authorized to work
  • Experience supporting CMMC assessments or similar regulatory compliance programs
  • Familiarity with manufacturing or operational technology (OT) environments
  • Experience developing security standards or working closely with infrastructure and engineering teams
  • Professional certifications such as CISSP, CISM, CRISC, or similar

UFP Industries Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about UFP Industries and has not been reviewed or approved by UFP Industries.

  • Healthcare Strength Health coverage includes medical, dental, and vision, an HSA with a company contribution, company-paid life and disability, an EAP, and a health concierge service. The package is framed as a premium set of benefits supporting employees and their families.
  • Equity Value & Accessibility Employees can buy company stock through an Employee Stock Purchase Program at a discount. Additional ownership perks such as stock gifts tied to service milestones are highlighted in parts of the materials.
  • Retirement Support A 401(k) plan with a company match is available, including pre-tax and Roth options with various investments. Eligibility commonly begins within the first months of employment, encouraging earlier participation.

UFP Industries Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Grand Rapids, Michigan
2,870 Employees
Year Founded: 1955

What We Do

UFP Industries is a holding company whose operating subsidiaries – UFP Packaging, UFP Construction and UFP Retail Solutions – manufacture, distribute and sell a wide variety of products used in residential and commercial construction, packaging and industrial applications. Founded in 1955, the company has operations in North America, Europe, Asia and Australia.

Similar Jobs

Optum Logo Optum

Staff Pharmacist Per Diem

Artificial Intelligence • Big Data • Healthtech • Information Technology • Machine Learning • Software • Analytics
In-Office
Sturgis, MI, USA
160000 Employees
44-79 Hourly

CertifID Logo CertifID

Principal Product Manager

Legal Tech • Real Estate • Security • Software • Cybersecurity • PropTech
Easy Apply
Remote or Hybrid
3 Locations
130 Employees

Cox Enterprises Logo Cox Enterprises

Fraud Prevention Agent ( Autotrader/KBB)

Artificial Intelligence • Automotive • Greentech • Information Technology • Machine Learning • Software • Cybersecurity
Remote or Hybrid
United States
50000 Employees
22-33 Hourly

Domino Data Lab Logo Domino Data Lab

Staff Software Engineer

Artificial Intelligence • Machine Learning
Easy Apply
Remote or Hybrid
US
200 Employees
200K-250K Annually

Similar Companies Hiring

Grocery TV Thumbnail
Software • Retail • Marketing Tech • Hardware • Digital Media • AdTech
Austin, TX
56 Employees
Scotch Thumbnail
Artificial Intelligence • eCommerce • Fintech • Payments • Retail • Software • Analytics
US
35 Employees
Golden Pet Brands Thumbnail
Digital Media • eCommerce • Information Technology • Marketing Tech • Pet • Retail • Social Media
El Segundo, California
178 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account