Denver , Colorado
|Onsite
|Contract
Denver, Colorado
|Onsite
|Contract
Join a global information security team helping protect complex business operations through thoughtful cybersecurity risk management. This role focuses on assessing third-party security controls, identifying and mitigating risk, and partnering with stakeholders to support secure business decisions.
Responsibilities
- Evaluate external party security controls and compare them against internal information security requirements.
- Work with technology and business teams to identify cybersecurity risks tied to current and upcoming projects.
- Assess vendor and partner risk using questionnaires, industry standards, and internal policies.
- Recommend practical risk mitigation options and communicate findings to internal and external stakeholders.
- Guide teams on applicable security, regulatory, and policy requirements.
- Document assessment activity, findings, and related communications in the risk management platform.
- Provide status updates to security leadership, project managers, and other stakeholders.
- Support security policy enforcement and review exception requests with recommendations.
- Research emerging technologies, architectures, and tools that support enterprise security needs.
- Complete additional cybersecurity risk management tasks as assigned.
Skills
- 3+ years of experience in cybersecurity risk management, IT security control design, or security control audit work.
- Bachelor’s degree in information systems, computer science, or a related field preferred.
- Working knowledge of security and compliance frameworks such as SOC 1, SOC 2, ISO 27000, SIG, CAIQ, NIST Cybersecurity Framework, SOX, PCI-DSS, GDPR, and privacy laws.
- Strong communication skills with the ability to explain security topics clearly to technical and non-technical audiences.
- Ability to influence decisions, support balanced risk-based outcomes, and handle complex discussions professionally.
- Self-directed approach with a proactive mindset and strong judgment.
- Comfort working across vendors, IT teams, and business stakeholders.
Preferred Skills
- CISSP, CISM, CISA, or CRISC certification preferred.
- GSEC, Security+, or a similar credential considered a plus.
- Experience with vendor risk reviews or external party assessments.
- Familiarity with documentation and workflow in an online risk management platform.
- Strong relationship-building skills and the ability to collaborate effectively across teams.
Horizontal is committed to fostering a diverse, equitable, and inclusive workplace where different perspectives are valued and respected. We encourage candidates from all backgrounds to apply and bring their unique experiences to the team.
By applying for this position, you acknowledge and agree that Horizontal Talent may contact you regarding your application using automated technology, including phone calls, SMS/text messages, or email, which may be delivered by our virtual AI recruiter, Alex.Horizontal is committed to taking affirmative action to employ and advance in employment qualified individuals with disabilities and protected veterans. If you are an individual with a disability and require a reasonable accommodation to complete any part of the application process or participate in the interview process, click here to request accommodation assistance.
All applicants applying must be legally authorized to work in the country of employment.