Your Title: Cyber Risk Analyst - GRC
Job Location: Mexicali, Mexico Office
Our Department: Corporate Cyber Security
Trimble is transforming the way the world works by delivering products and services that connect the physical and digital worlds. Core technologies in positioning, modeling, connectivity and data analytics enable customers to improve productivity, quality, safety, and sustainability. From purpose built products to enterprise lifecycle solutions, Trimble software, hardware and services are transforming a broad range of industries such as agriculture, construction, geospatial and transportation and logistics.
What You Will Do
Operational
- Contribute to risk management processes to ensure business risk posture is properly calculated and proactively managed.
- Track and maintain corporate risk through Jira ticketing and contribute to producing regular risk metrics, dashboards and reports as needed.
- Perform support ticket analysis, triage and escalation
- Identify opportunities for risk management and process automation. Develop proposals and implement improvements through approved automations.
- Collaborate with cybersecurity team members and business unit staff across multiple international sites
- Produce and analyze information that will accurately demonstrate the risk posture of each business and drive actions to reduce and manage technical risks.
- Be able to understand and communicate technical risks to a broad set of stakeholders. Must be able to adjust delivery to the audience.
Communication
The Trimble Cybersecurity team serves the entire organization. Trimble is divided into several Business focused Sectors and Divisions. This role will communicate with:
- Cybersecurity, IT and GRC teams
- Cybersecurity leadership
- Divisional & Sector Cybersecurity representatives
- Software development staff
- Other staff as required
- No communication with Trimble customers required
Skills / Competencies
- Comprehensive understanding of risk management standards and guidelines.
- General IT knowledge (networking, cloud computing, software development)
- Familiarity with development security frameworks (e.g., SSDLC, OWASP, SSDF)
- A passion for user-centric information that is clear and actionable, attention to detail focused on delivering accurate and creative metrics.
- Ability to make effective, timely decisions with clear reasoning
- Ability to quickly establish a broad understanding of an issue with limited available information and outline the steps required to bring it to a successful conclusion
- Effective communication skills (verbal and written) and time management skills
- Flexible approach to working in a changing environment and can work well under pressure with dynamically changing priorities
- Ability to work as part of a collaborative global team, prepared to remain resilient to complete tasks to conclusion.
What Skills & Experience You Should Bring
- A relevant degree in Data Science, Computer Science or Engineering (Software or Electrical)
- Current general security certifications (e.g., SEC+, GSEC) encouraged but not required
- 2 years experience in a risk management role, information security role or systems engineer/administrator role in a large, international software company
- Hands-on experience with business and GRC tools such as: Jira Service Desk; Tenable; Whitesource; Crowdstrike; OneTrust; Splunk
- Demonstrated experience in collating information from disparate data sources
- Intermediate level experience with Windows and Linux/Unix operating systems
- Intermediate level scripting skills in powershell, python, bash, perl with proven examples of successful process automation.
- You must be familiar with security frameworks (e.g., CIS, NIST, CSF, BSIMM), software development practices, Quality Assurance (QA) and program practices including Agile, security control auditing, ticketing, vendor security assessments, vulnerability remediation, risk scoring, automation through scripting, system administration, data analysis, troubleshooting, event correlation and creative problem solving.
About Your Location
Mexicali, Mexico
About Our Division
In order to improve integrity between physical and digital worlds, Governance, Risk and Compliance (GRC) facilitates the integrated collection of capabilities necessary to support connected performance. GRC doesn't burden the business, it supports and improves it by adding value through establishing efficiencies, centralizing policy and creating metrics to reduce risk to maintain Trimble brand equity. GRC resides within the corporate Trimble Cybersecurity team.
Trimble's Inclusiveness Commitment
We believe in celebrating our differences. That is why our diversity is our strength. To us, that means actively participating in opportunities to be inclusive. Diversity, Equity, and Inclusion have guided our current success while also moving our desire to improve. We actively seek to add members to our community who represent ou