Oct. 6, 2023, 8:31 p.m. | /u/cybcentra

cybersecurity www.reddit.com

I’ve recently joined an infosec team that is responsible for risk. Every now and then, we’re required to quickly risk assess a raised change, or new tech proposal and third parties on an adhoc basis.

However, I feel like the team is severely missing something here. Almost all job specs state “conduct risk assessments to identify threats and vulnerabilities”. We don’t seem to being doing that - getting out there proactively.

How does this work in your organisation? What does …

assessments change cybersecurity infosec job joined missing new tech quickly responsible risk risk assessments state team tech third third parties what is

Security Analyst

@ Northwestern Memorial Healthcare | Chicago, IL, United States

GRC Analyst

@ Richemont | Shelton, CT, US

Security Specialist

@ Peraton | Government Site, MD, United States

Information Assurance Security Specialist (IASS)

@ OBXtek Inc. | United States

Cyber Security Technology Analyst

@ Airbus | Bengaluru (Airbus)

Vice President, Cyber Operations Engineer

@ BlackRock | LO9-London - Drapers Gardens