Senior Risk Management Analyst

Company: Cubic Corporation
Apply for the Senior Risk Management Analyst
Location: Surrey
Job Description:

Overview

In this role, you support security compliance for production transaction environments within Cubic. You evaluate security controls and operating environments to ensure policy alignment and risk mitigation. You plan and run IT compliance programs and coordinate with auditors to address PCI-DSS, ISO 27001, and related standards. You will work with cross-functional teams to drive timely remediation and stronger security posture. This position offers exposure to high‑impact, mission-critical environments with opportunities to influence company-wide security governance.

Responsibilities

  • Serve as SME for Security Risk Assessment methodology, policy, and processes
  • Facilitate security audits, including scheduling and stakeholder coordination
  • Coordinate with Internal/External Auditors and IT teams to complete audits
  • Lead design and control reviews to maintain ongoing compliance with security standards
  • Manage security reviews to ensure design/implementation meets PCI-DSS, ISO 27001, SOC 1/2, and other regional requirements
  • Document and communicate non-compliance areas and remediation steps
  • Identify and report security risks across applications, networks, data centers, cloud, and third parties
  • Escalate remediation gaps and track progress with stakeholders
  • Use OneTrust GRC to capture gaps and remediation plans, and monitor controls
  • Collaborate with customers and security teams to build positive outcomes
  • Educate Security Management on compliant IT processes and controls
  • Draft and maintain process/control documentation; support remediation with Operations/Engineering teams
  • Ensure adherence to Corporate Standards, SDLC, Change Management, and risk governance
  • Review vendor contracts and SOC reports for control impact and coordinate with vendors

Key requirements

  • Strong English communication skills; proficient with Microsoft Office
  • Ability to collaborate in a cross-functional, matrix IT organization
  • Familiarity with PCI DSS 4, ISO 27001-2022, and SOC I/II
  • Expert level experience in coordinating with stakeholders and solution providers across IT
  • Proven ability to influence and deliver through complex environments
  • Extensive experience applying security concepts to internal systems and services in mission-critical settings
  • Residence within commuting distance to CTS offices and ability to travel regionally
  • Collaborative and cross-functional teamwork
  • Effective communication and stakeholder management
  • Analytical and problem-solving mindset
  • PCI DSS 4
  • ISO 27001-2022
  • SOC 1 & SOC 2 audits

Posted: September 14th, 2026