Supply Chain Cyber Risk Analyst

Posted 2 Days Ago
2 Locations
In-Office or Remote
Mid level
Automotive
The Role
Leads cybersecurity risk and compliance activities, including third-party vendor risk assessments, due diligence reviews, compliance monitoring, risk inventory maintenance, and mitigation planning. Partners with IT, Legal, Compliance, Privacy, and business teams to assess technology changes and embed risk awareness. Applies NIST, ISO, FAIR, and related frameworks, prepares executive reporting, provides technical risk guidance, and supports security awareness initiatives.
Summary Generated by Built In

Job Summary:

Leads the support of the organization's cybersecurity framework, including policy, standards and baselines. Understands and applies appropriate handling of risk and compliance from internal and external perspectives to assure that existing and new technology solutions meet the organization's cybersecurity risk requirements.

Key Responsibilities:

Understands and applies Cummins cybersecurity policies and industry data privacy principles. Leads cybersecurity risk identification utilizing identified Cummins risk management frameworks while providing guidance to the team to evaluate severity and mitigation plans. Coaches and develops less experienced team members. Understands and applies frameworks and standards (eg NIST, ISO, ITIL, Cobit) in a manner specific to Cummins processes and controls. Provides cybersecurity technical expertise for technology solutions. Collaborates with stakeholders on requests for new and changing technology solutions, acting as a trusted business partner and advisor. Maintain strong relationships to deliver business value using relevant Business Relationship Management practices. ResponsibilitiesCompetencies:
Action oriented - Taking on new opportunities and tough challenges with a sense of urgency, high energy, and enthusiasm.
Balances stakeholders - Anticipating and balancing the needs of multiple stakeholders.
Business insight - Applying knowledge of business and the marketplace to advance the organization’s goals.
Ensures accountability - Holding self and others accountable to meet commitments.
Manages complexity - Making sense of complex, high quantity, and sometimes contradictory information to effectively solve problems.
Organizational savvy - Maneuvering comfortably through complex policy, process, and people-related organizational dynamics.
Persuades - Using compelling arguments to gain the support and commitment of others.
Resourcefulness - Securing and deploying resources effectively and efficiently.
Tech savvy - Anticipating and adopting innovations in business-building digital and technology applications.
Training Delivery - Instructs learners in a manner that engages and adjusts to individual and group needs resulting in knowledge, skills and abilities that can be applied on the job.
Cybersecurity Risk Management - Identifies and assesses the potential impact of Cybersecurity risks against established Cybersecurity industry frameworks, regulations and organizational policies to develop and implement risk mitigation strategies in alignment with business objectives.
Regulatory Risk Compliance Management - Evaluates the design and effectiveness of controls against established industry frameworks and regulations to assess adherence with legal/regulatory requirements.
Values differences - Recognizing the value that different perspectives and cultures bring to an organization.
Education, Licenses, Certifications:
College, university, or equivalent degree in Cybersecurity, Computer Science, or Information Technology, or related subject, or relevant equivalent experience required. This position may require licensing for compliance with export controls or sanctions regulations.
Experience:
Intermediate level of relevant work experience required. 3-5 years of experience Qualifications

Key Responsibilities
Third-Party & Vendor Risk
•    Assess the cybersecurity risk profile of third-party vendors and partners through due diligence reviews and questionnaires
•    Monitor ongoing vendor compliance and escalate concerns appropriately
•    Maintain the third-party risk inventory and associated risk ratings
Cross-Functional Collaboration
•    Partner with IT, Legal, Compliance, Privacy, and business units to embed risk awareness into projects and initiatives
•    Provide risk-informed guidance during new technology adoption, system changes, and product launches
•    Support security awareness efforts related to risk management practices
________________________________________
Required Qualifications
•    Education: Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Risk Management, or a related field (or equivalent experience)
•    Experience: 3–5 years of experience in cybersecurity, IT risk management, or a related discipline
•    Demonstrated knowledge of cybersecurity risk frameworks and methodologies (NIST CSF, NIST RMF, ISO 27001/27005, FAIR)
•    Familiarity with regulatory requirements such as SOC 2, PCI-DSS, or GDPR
•    Strong analytical and problem-solving skills with the ability to translate technical risks into business language
•    Excellent written and verbal communication skills, including experience preparing executive-level reports
•    Proficiency with GRC tools (e.g., Venminder, Black Kite, OneTrust, or similar)
 

About UsCummins is an equal opportunity employer. Our policy is to provide equal employment opportunities to all qualified persons without regard to race, sex, color, disability, national origin, age, religion, union affiliation, sexual orientation, veteran status, citizenship, gender identity, or other status protected by law.

Skills Required

  • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Risk Management, or a related field, or equivalent experience
  • 3-5 years of experience in cybersecurity, IT risk management, or a related discipline
  • Knowledge of cybersecurity risk frameworks and methodologies, including NIST CSF, NIST RMF, ISO 27001/27005, and FAIR
  • Familiarity with SOC 2, PCI DSS, or GDPR regulatory requirements
  • Strong analytical and problem-solving skills, including the ability to translate technical risks into business language
  • Excellent written and verbal communication skills, including executive-level report preparation
  • Proficiency with GRC tools such as Venminder, Black Kite, OneTrust, or similar
  • College, university, or equivalent degree in Cybersecurity, Computer Science, Information Technology, or a related subject, or relevant equivalent experience
  • Licensing for compliance with export controls or sanctions regulations may be required

Cummins Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Cummins and has not been reviewed or approved by Cummins.

  • Retirement Support A 401(k) with company contribution/match and both defined contribution and defined benefit pension plans are offered, alongside profit sharing and an employee stock purchase plan. This mix supports long-term savings and financial security.
  • Healthcare Strength Multiple medical plan options (HSA, HSA Plus, PPO) with dental, vision, life and long-term disability coverage are provided, along with telehealth, mental-health support, and wellness tools. In-network protections and HSA/HSA Plus structures are described to help manage costs.
  • Parental & Family Support Paid maternity and paternity leave, family medical leave, and adoption assistance are offered. Reduced or flexible hours and unpaid extended leave options further support caregiving needs.

Cummins Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Columbus, IN
35,251 Employees
Year Founded: 1919

What We Do

At Cummins, we empower everyone to grow their careers through meaningful work, building inclusive and equitable teams, coaching, development and opportunities to make a difference. Across our entire organization, you'll find engineers, developers, and technicians who are innovating, designing, testing, and building. You'll also find accountants, marketers, as well as manufacturing, quality and supply chain specialists who are working with technology that's just as innovative and advanced.

Similar Jobs

BAE Systems, Inc. Logo BAE Systems, Inc.

PMO Instructional Developer

Aerospace • Hardware • Information Technology • Security • Software • Cybersecurity • Defense
Remote or Hybrid
Fort Walton Beach, FL, USA
40000 Employees
79K-135K Annually

BAE Systems, Inc. Logo BAE Systems, Inc.

Project Manager

Aerospace • Hardware • Information Technology • Security • Software • Cybersecurity • Defense
Remote or Hybrid
Fort Walton Beach, FL, USA
40000 Employees
109K-185K Annually

BAE Systems, Inc. Logo BAE Systems, Inc.

Director, IT Strategic Program Delivery

Aerospace • Hardware • Information Technology • Security • Software • Cybersecurity • Defense
Remote or Hybrid
Falls Church, VA, USA
40000 Employees
173K-294K Annually

Cloudflare Logo Cloudflare

Senior Director, R&D HR Business Partnering

Cloud • Information Technology • Security • Software • Cybersecurity
Remote or Hybrid
United States
4400 Employees

Similar Companies Hiring

Cox Enterprises Thumbnail
Artificial Intelligence • Automotive • Greentech • Information Technology • Machine Learning • Software • Cybersecurity
Atlanta, Georgia
30000 Employees
UL Solutions Thumbnail
Automotive • Professional Services • Software • Consulting • Energy • Chemical • Renewable Energy
Chicago, IL
15000 Employees
HERE Technologies Thumbnail
Artificial Intelligence • Automotive • Computer Vision • Information Technology • Internet of Things • Logistics • Software
Amsterdam, NL
6000 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account