Position Summary
The Cybersecurity Risk & Metrics Analyst supports JetBlue’s Cybersecurity Risk Management program by identifying, assessing, tracking, and reporting risks across the enterprise. This role contributes to the governance and execution of risk processes, including Enterprise Cybersecurity Risk Management (ECRM), Third-Party Risk Management (TPRM), and Risk Exception Management. The ideal candidate is a detail-oriented, analytical professional who can navigate complex environments and translate technical and business information into actionable insights.
Essential Responsibilities
- Perform qualitative and quantitative cybersecurity risk assessments across business units, systems, and projects in alignment with the Cybersecurity Risk Management Framework.
- Develop dashboards and reports for multiple audiences (e.g., CISO, senior leadership, operational teams), ensuring clarity, accuracy, and consistency across functions.
- Provide monthly and quarterly risk reporting inputs to the Enterprise Risk Management function and contribute cybersecurity perspectives to board-level or regulatory reporting.
- Working knowledge of data visualization tools such as Power BI, Tableau, Splunk, or ServiceNow Performance Analytics.
- Experience translating complex cybersecurity data into clear, actionable insights for business and technical audiences.
- Experience querying and transforming data using SQL and/or SPL (Splunk Processing Language) for use in dashboards, metrics, or reporting workflows.
- Support the identification and management of inherent and residual risk using defined control categories and compensating measures.
- Partner with business stakeholders, technology teams, and external partners to assess cyber risks associated with third-party relationships.
- Maintain and mature the Third-Party Risk Management lifecycle, including vendor onboarding, risk reviews, due diligence, and re-assessments.
- Monitor and track risk exceptions and compensating controls; ensure risk acceptance processes are documented and approved in accordance with governance policies.
- Develop and maintain risk metrics, dashboards, and executive-level reporting to communicate the risk posture of JetBlue’s cyber environment.
- Collaborate with Internal Audit, Compliance, and IT teams to ensure risks are accurately captured and aligned with enterprise risk practices.
- Maintain familiarity with emerging cybersecurity risks, regulatory requirements, and industry best practices.
- Share your knowledge and expertise with team members, fostering a collaborative and learning-oriented environment.
- Participates in Project Management activities and the enterprise architecture reviews to drive overall technology direction for JetBlue.
- Other duties as assigned.