Jobs · Information Technology · Michigan

Cybersecurity Assurance Analyst

Cummins Inc. · Lansing, MI · Today
On-siteInformation TechnologyFull-time

About the role

We are looking for a talented Cybersecurity Assurance Analyst to join our team specializing in Systems/Information Technology for our Corporate organization in Columbus, IN.

Responsibilities

  • Lead cybersecurity risk assessments by identifying, evaluating, and prioritizing threats using Cummins risk management frameworks to protect critical business assets.
  • Drive effective risk mitigation strategies by providing expert guidance on risk severity, control effectiveness, and remediation planning.
  • Ensure compliance with Cummins cybersecurity policies and industry data privacy principles, helping safeguard sensitive information and maintain regulatory alignment.
  • Apply cybersecurity frameworks and standards such as NIST, ISO, ITIL, and COBIT to strengthen security controls and support consistent governance practices.
  • Provide technical cybersecurity expertise for new and existing technology solutions, enabling secure design, implementation, and operation of business systems.
  • Partner with business and technology stakeholders to evaluate evolving technology needs, delivering secure, scalable solutions that support organizational objectives.
  • Mentor and develop less experienced team members by sharing knowledge, fostering professional growth, and strengthening overall team cybersecurity capabilities.

Requirements

  • Action oriented - Taking on new opportunities and tough challenges with a sense of urgency, high energy, and enthusiasm.
  • Balances stakeholders - Anticipating and balancing the needs of multiple stakeholders.
  • Business insight - Applying knowledge of business and the marketplace to advance the organization’s goals.
  • Holds accountability - Holding self and others accountable to meet commitments.
  • Manages complexity - Making sense of complex, high quantity, and sometimes contradictory information to effectively solve problems.
  • Organizational savvy - Maneuvering comfortably through complex policy, process, and people-related organizational dynamics.
  • Persuades - Using compelling arguments to gain the support and commitment of others.
  • Resourcefulness - Securing and deploying resources effectively and efficiently.
  • Tech savvy - Anticipating and adopting innovations in business-building digital and technology applications.
  • Training Delivery - Instructs learners in a manner that engages and adjusts to individual and group needs resulting in knowledge, skills and abilities that can be applied on the job.
  • Cybersecurity Risk Management - Identifies and assesses the potential impact of Cybersecurity risks against established Cybersecurity industry frameworks, regulations and organizational policies to develop and implement risk mitigation strategies in alignment with business objectives.
  • Regulatory Risk Compliance Management - Evaluates the design and effectiveness of controls against established industry frameworks and regulations to assess adherence with legal/regulatory requirements.

Qualifications

  • College, university, or equivalent degree in Cybersecurity, Computer Science, or Information Technology, or related subject, or relevant equivalent experience required.
  • This position may require licensing for compliance with export controls or sanctions regulations.
  • Experience: Intermediate level of relevant work experience required. 3-5 years of experience.
  • Cybersecurity Control Assessment & Validation: Perform cybersecurity control assessments to evaluate control design and operating effectiveness across IT systems and processes. Execute structured assessments aligned to Cummins frameworks and industry standards (e.g., NIST, ISO). Analyze control implementations and identify gaps relative to regulatory and policy requirements. Document assessment results, including control narratives, test procedures, and findings. Provide objective, evidence-based evaluations of cybersecurity controls.
  • IT Audit & Assurance Support: Support internal audits, external audits, and third-party certification assessments (e.g., CMMC, ISO 27001, NIS2). Conduct control walkthroughs, interview stakeholders, and gather supporting documentation. Perform evidence validation and traceability checks to confirm control execution. Prepare audit-ready documentation, including control descriptions, test results, and evidence packages. Ensure all audit artifacts meet quality, completeness, and consistency standards.
  • Regulatory Compliance, Continuous Improvement & Collaboration: Assist in supporting compliance with CMMC/NIST 800-171, ISO 2700, NIS2, and UK Cyber Essentials. Collaborate with IT, Cybersecurity, Compliance, and business stakeholders to support assessments and audits. Identify opportunities to improve efficiency, consistency, and quality of cybersecurity assurance processes. Support enhancements to tools, templates, and methodologies used for assessments and audits.
  • Documentation, Metrics, and Reporting: Maintain documentation and records to support repeatable and scalable assurance activities. Communicate status updates on assessments, audits, risks, and remediation tracking. Prepare audit and compliance reporting materials and support certification readiness activities. Track control deficiencies and remediation progress.

Similar jobs

Cyber Information Assurance Analyst

The Applied Research Laboratory at Penn State UniversityUniversity Park, PA· 3 wk ago
Information Technology$69k–$132k/yrapply on psu.wd1.myworkdayjobs.com

Cyber Information Assurance Analyst

The Applied Research Laboratory at Penn State UniversityReston, VA· 6 mo ago
Information Technology$69k–$132k/yrapply on psu.wd1.myworkdayjobs.com

Cybersecurity Analyst

TDI (Tetrad Digital Integrity)Suffolk, VA· 2 wk ago
Information Technology$85k–$95k/yr