Skip to content
TwilioTwilioUnited States

Senior Analyst, Security Risk

Senior Security Risk Analyst responsible for maturing Twilio's cyber risk management program, maintaining risk registers, performing qualitative/quantitative analyses, automating operations, and reporting to stakeholders while ensuring compliance with frameworks like NIST and ISO 31000. Requires 5+ years in security risk management and strong cross-functional collaboration skills.

129k – 189k/yr
Remote5+ YOESecurity Engineering

About the role

Responsibilities

  • Execute and improve upon daily operations of the One Twilio Risk Management program, including establishing automated operations for all areas of cyber risk.
  • Manage and maintain risk register(s) to track key risk indicators (KRIs); ensure risks are identified, evaluated, and mitigated appropriately.
  • Collaborate with cross-functional teams to ensure risks are clearly communicated and actionable.
  • Review and assess the effectiveness of risk treatment strategies and recommend solutions when applicable.
  • Prepare and deliver regular risk reports, dashboards, and presentations to internal and external stakeholders, highlighting key risk trends, issues, and mitigation efforts.
  • Analyze risk data from various sources to assess trends and develop predictive models for potential risks.
  • Use data analytics and risk modeling tools to assess the legal, financial, operational, and security impact of risks.
  • Develop ad-hoc reports and presentations as required to support risk decision-making.
  • Coordinate with internal and external auditors to support compliance assessments and resolve any risk-related findings.

Requirements

  • 5+ years of Risk Management experience, working with security-centric risk management and compliance frameworks.
  • Experience maturing an industry accepted risk framework including but not limited to NIST Risk Management Framework, COSO Enterprise Risk Management, or ISO 31000.
  • Excellent cross-functional collaboration leveraging relationships to establish strategic direction.
  • Experience designing and executing qualitative and quantitative risk analyses to translate technical vulnerabilities into measurable business impact.
  • Experience translating vulnerabilities, control gaps and systematic limitations into clear, actionable risk statements.
  • Proven track record of managing large scale, heavily regulated, multi-entity, cross-functional risk assessments, risk registers, and compliance programs.
  • Experience of working with technical security and Engineering / IT to implement technical risk/control solutions with the ability to interpret control requirements and relay those to different stakeholder groups with strong technical knowledge.
  • Bias towards automation and tooling to scale program impact and reach.
  • Experience leveraging AI to streamline risk operations.
  • Excellent verbal, written, and interpersonal skills.
  • Flexible and able to manage multiple projects under tight deadlines.
  • Comfortable with ambiguity and adaptable to fast changing environments.
  • Strategic thinker and problem solver with exceptional communication skills.

Nice-to-Haves

  • Bachelor’s degree in Risk Management, Business, Finance, Cybersecurity, or a related field.
  • Professional certifications (e.g., CRISC, CISA, CISSP, FRM).
  • Strong analytical and problem-solving skills with the ability to interpret complex data and present actionable insights.
  • Excellent communication skills, with the ability to translate risk into clear, actionable recommendations for leadership.
  • Strong proficiency with enterprise AI and GRC tooling.
  • Experience with project management and working across multiple teams and departments.

Compensation / Benefits

  • Estimated pay ranges (varies by location):
    • Colorado, Hawaii, Illinois, Maryland, Massachusetts, Minnesota, Vermont or Washington D.C.: $128,560 - $160,700.
    • New York, New Jersey, Washington State, or California (outside of the San Francisco Bay area): $136,000 - $170,000.
    • San Francisco Bay area, California: $151,120 - $188,900.
  • Eligible to participate in Twilio’s equity plan and corporate bonus plan.
  • Benefits include health care insurance, 401(k) retirement account, paid sick time, paid personal time off, paid parental leave (offerings vary by location).

Skills

Risk Managementnist rmfcosoiso 31000risk analysisrisk registercompliance frameworksgrc toolingai for risk operationsData AnalyticsCybersecuritycrisccisacissp
Chainguard

Senior Security Engineer

ChainguardUnited States

Senior Security Engineer on the Cyber Resiliency team designing detection controls, engineering SOAR/AI playbooks, leading incident response, and conducting threat hunts to strengthen Chainguard's security posture.

130k – 150k/yr
Remote5+ YOESecurity Engineering
Chime

Senior Security Engineer

ChimeNew York, NY +1

As a Senior Security Engineer, you will work across product, application, infrastructure, and enterprise security. This role involves hands-on work with code and cloud infrastructure, focusing on reducing security risks, performing security reviews, and building automation and tooling.

130k – 250k/yr
Hybrid5+ YOESecurity Engineering
MongoDB

Senior Software Engineer, Server Security

MongoDBNew York, NY

Senior Software Engineer builds and tests security features like cryptography, identity/access, and network security in MongoDB's C++ codebase. Requires 5+ years in distributed systems and proficiency in compiled languages like C++ or Rust.

126k – 248k/yr
Hybrid5+ YOESecurity Engineering
Clickhouse

Senior Security Automation Engineer

ClickhouseUnited States

Senior Security Automation Engineer building centralized security telemetry, universal identity provisioning, and agentic risk engines to enable continuous compliance, self-healing controls, and real-time risk visibility at ClickHouse. Requires strong IAM/IGA and automation experience with Python, JS/TS, or Go.

125k – 205k/yr
Remote5+ YOESecurity Engineering
Agency

Senior vCISO / GRC Consulting Manager

AgencyRichmond, VA

Lead client-facing vCISO and GRC consulting engagements for SOC 2, ISO 27001, NIST, and CMMC compliance. Manage a team of consultants while advising executives on security program design, risk prioritization, audit readiness, and control implementation.

125k – 125k/yr
On-site6+ YOESecurity Engineering