Jobs · Information Technology · Ohio

Lead Cybersecurity Program Analyst

Kurv · Cleveland, OH · Yesterday
On-siteInformation TechnologyFull-time
Kurv is advancing its cybersecurity program in alignment with the NIST Cybersecurity Framework (CSF) while supporting and strengthening our existing PCI DSS 4.0 program through documentation, tracking, and operational coordination.We are seeking a motivated, detail-oriented Cybersecurity Program Analyst to support both cybersecurity program development and day-to-day security operations. This role will focus initially on asset inventory, ownership, and risk classification (NIST Identify) while contributing to ongoing security and compliance activities.This is a developmental role, designed to build foundational experience in cybersecurity governance, risk, and compliance, with mentorship from senior team members and exposure to real-world PCI and cloud security environments. Key ResponsibilitiesCybersecurity Program & Governance (Primary Focus)Build and maintain enterprise asset inventory (systems, applications, vendors, data flows)Document system ownership, classification, and risk tieringSupport ongoing PCI scope validation and data flow documentationSupport mapping and alignment of existing controls to NIST CSF and PCI DSS 4.0Assist in maintaining cybersecurity policies, standards, and documentationTrack updates to the cybersecurity risk register and governance activitiesContribute to reporting, metrics, and audit readiness Security Operations & Control SupportSupport execution of core security controls, including:Vulnerability scanning and remediation trackingLog monitoring and alert reviewFile integrity and change validationIdentify and escalate anomalies or control gaps Access, Cloud & Incident SupportSupport user access reviews and identity governance activitiesAssist with cloud security monitoring and configuration tracking (AWS)Maintain and support incident response documentation and exercises Compliance & Audit Support (High Visibility)Support ongoing PCI DSS compliance activities through documentation, evidence collection, and coordinationMaintain organized audit evidence repositories and supporting artifactsTrack audit requests, timelines, and deliverablesAssist in preparing standard evidence submissions for audits and reviews Security Awareness & CoordinationSupport security awareness and training trackingPartner cross-functionally with IT, Engineering, Compliance, and Operations teamsReinforce alignment between security controls and business processesWork under the guidance of senior team members to learn and contribute to PCI and cybersecurity program ownership over time Qualifications Required:Bachelor’s degree in Cybersecurity, Information Systems, Computer Science, Risk Management, or related fieldStrong analytical, organizational, and documentation skillsHigh attention to detail and accountabilityClear written and verbal communication skillsInterest in cybersecurity governance, risk, and compliancePreferred:Exposure to NIST, PCI DSS, SOC 2, or ISO 27001Familiarity with cloud environments (AWS preferred)Entry-level certification (or willingness to obtain) such as Security+ Professional DevelopmentKurv supports development in:NIST Cybersecurity FrameworkPCI DSS fundamentalsFoundational cybersecurity certifications (e.g., Security+)Governance, Risk, and Compliance (GRC) career path Why This Role MattersThis role strengthens the discipline, scalability, and audit readiness of our existing security and PCI program while supporting the build-out of a NIST-aligned cybersecurity framework—critical to enabling secure, compliant growth of the Kurv platform.

Similar jobs

Lead Cybersecurity Engineer

Ritchie Bros.Westchester, IL· 4 wk ago
Information Technologyapply on fa-exew-saasfaprod1.fa.ocs.oraclecloud.com