# Senior Analyst, Security Risk

**Company:** [Twilio](https://hotfix.jobs/companies/twilio)
**Location:** Remote
**Role:** Security Engineering
**Salary:** $129k – $189k/yr
**Experience:** 5+ years
**Skills:** Risk Management, nist rmf, coso, iso 31000, risk analysis, risk register, compliance frameworks, grc tooling, ai for risk operations, Data Analytics, Cybersecurity, crisc, cisa, cissp
**Posted:** 2026-07-27

> Senior Security Risk Analyst responsible for maturing Twilio's cyber risk management program, maintaining risk registers, performing qualitative/quantitative analyses, automating operations, and reporting to stakeholders while ensuring compliance with frameworks like NIST and ISO 31000. Requires 5+ years in security risk management and strong cross-functional collaboration skills.

## Job Description

## Responsibilities
- Execute and improve upon daily operations of the One Twilio Risk Management program, including establishing automated operations for all areas of cyber risk.
- Manage and maintain risk register(s) to track key risk indicators (KRIs); ensure risks are identified, evaluated, and mitigated appropriately.
- Collaborate with cross-functional teams to ensure risks are clearly communicated and actionable.
- Review and assess the effectiveness of risk treatment strategies and recommend solutions when applicable.
- Prepare and deliver regular risk reports, dashboards, and presentations to internal and external stakeholders, highlighting key risk trends, issues, and mitigation efforts.
- Analyze risk data from various sources to assess trends and develop predictive models for potential risks.
- Use data analytics and risk modeling tools to assess the legal, financial, operational, and security impact of risks.
- Develop ad-hoc reports and presentations as required to support risk decision-making.
- Coordinate with internal and external auditors to support compliance assessments and resolve any risk-related findings.

## Requirements
- 5+ years of Risk Management experience, working with security-centric risk management and compliance frameworks.
- Experience maturing an industry accepted risk framework including but not limited to NIST Risk Management Framework, COSO Enterprise Risk Management, or ISO 31000.
- Excellent cross-functional collaboration leveraging relationships to establish strategic direction.
- Experience designing and executing qualitative and quantitative risk analyses to translate technical vulnerabilities into measurable business impact.
- Experience translating vulnerabilities, control gaps and systematic limitations into clear, actionable risk statements.
- Proven track record of managing large scale, heavily regulated, multi-entity, cross-functional risk assessments, risk registers, and compliance programs.
- Experience of working with technical security and Engineering / IT to implement technical risk/control solutions with the ability to interpret control requirements and relay those to different stakeholder groups with strong technical knowledge.
- Bias towards automation and tooling to scale program impact and reach.
- Experience leveraging AI to streamline risk operations.
- Excellent verbal, written, and interpersonal skills.
- Flexible and able to manage multiple projects under tight deadlines.
- Comfortable with ambiguity and adaptable to fast changing environments.
- Strategic thinker and problem solver with exceptional communication skills.

## Nice-to-Haves
- Bachelor’s degree in Risk Management, Business, Finance, Cybersecurity, or a related field.
- Professional certifications (e.g., CRISC, CISA, CISSP, FRM).
- Strong analytical and problem-solving skills with the ability to interpret complex data and present actionable insights.
- Excellent communication skills, with the ability to translate risk into clear, actionable recommendations for leadership.
- Strong proficiency with enterprise AI and GRC tooling.
- Experience with project management and working across multiple teams and departments.

## Compensation / Benefits
- Estimated pay ranges (varies by location):
  - Colorado, Hawaii, Illinois, Maryland, Massachusetts, Minnesota, Vermont or Washington D.C.: $128,560 - $160,700.
  - New York, New Jersey, Washington State, or California (outside of the San Francisco Bay area): $136,000 - $170,000.
  - San Francisco Bay area, California: $151,120 - $188,900.
- Eligible to participate in Twilio’s equity plan and corporate bonus plan.
- Benefits include health care insurance, 401(k) retirement account, paid sick time, paid personal time off, paid parental leave (offerings vary by location).

## Similar roles

- [Senior Security Engineer](https://hotfix.jobs/jobs/58cd9f20-ffb4-4e16-a7d0-e1001914a55f) - Chainguard - Remote - $130k – $150k/yr
- [Senior Security Engineer](https://hotfix.jobs/jobs/99e2a151-a656-4094-818f-979ecc125b37) - Chime - New York, NY - $130k – $250k/yr
- [Senior Software Engineer, Server Security](https://hotfix.jobs/jobs/b4220420-4d9c-4513-9c61-8eac97487464) - MongoDB - New York, NY - $126k – $248k/yr
- [Senior Security Automation Engineer](https://hotfix.jobs/jobs/2e4e1230-924e-4c2c-8df4-cdee5ef22cdb) - Clickhouse - Remote - $125k – $205k/yr
- [Senior vCISO / GRC Consulting Manager](https://hotfix.jobs/jobs/1eb33f19-585a-4597-9abd-d0a9ddce8874) - Agency - Richmond, VA - $125k – $125k/yr

**Apply:** https://hotfix.jobs/jobs/722306ee-c173-4bd6-b937-c6877997c626
**Canonical:** https://hotfix.jobs/jobs/722306ee-c173-4bd6-b937-c6877997c626