高级分析师,安全风险
Senior Analyst, Security Risk
我们是谁
在 Twilio,我们正在塑造通信的未来,一切都在家中的舒适环境中进行。我们为数十万家企业提供创新解决方案,并赋能全球数百万开发者打造个性化的客户体验。
我们致力于远程优先的工作方式,以及紧密连接和全球包容的文化,这意味着无论你身处何地,你都是一个充满活力的团队的一员,每天用多样化的经验产生全球影响。随着我们继续革新世界互动的方式,我们不断学习新技能和经验,让工作真正令人满意。你的职业发展掌握在你自己手中。
招聘与我们的工作方式
我们使用人工智能(AI)来帮助提高招聘效率。但要说的是,每个招聘决定都是由真实的 Twilions 做出的!
此外,虽然我们是一家远程优先的公司,但你可能会被要求临时到现场参加团队聚会、部门会议或客户会议。
在 Twilio 看见自己
加入我们,成为 Twilio 下一任安全风险高级分析师。
职位简介
高级安全风险分析师将是 One Twilio 风险管理计划的关键成员,专注于通过促进风险识别和处理来提升我们的安全风险态势。该团队与我们的产品和工程团队密切合作,确保 Twilio 所有领域的网络风险都被识别,并且风险方法在操作上有效,并符合法规(例如网络安全和/或电信/行业特定法规)和行业最佳实践安全措施(例如 NIST RMF、AI RMF、COSO、ISO 31000)。这个职位为有经验的风险专业人士提供了激动人心的机会,他们热衷于风险管理,并准备为像 Twilio 这样动态组织内的风险实践的持续增长和成熟做出贡献。
职责
在这个职位上,你将:
- 执行并改进 One Twilio 风险管理计划的日常运营,包括所有网络风险领域的自动化操作的进一步建立。
- 管理和维护风险登记册,以跟踪关键风险指标(KRIs),并确保风险被正确识别、评估和缓解。
- 与跨职能团队合作,确保风险被清晰传达并可执行。
- 审查和评估风险应对策略的有效性,并在适用时推荐解决方案。
- 准备并进行汇报
查看英文原文
Who we are
At Twilio, we’re shaping the future of communications, all from the comfort of our homes. We deliver innovative solutions to hundreds of thousands of businesses and empower millions of developers worldwide to craft personalized customer experiences.
Our dedication to remote-first work, and strong culture of connection and global inclusion means that no matter your location, you’re part of a vibrant team with diverse experiences making a global impact each day. As we continue to revolutionize how the world interacts, we’re acquiring new skills and experiences that make work feel truly rewarding. Your career at Twilio is in your hands.
.
Hiring and how we work
We use Artificial Intelligence (AI) to help make our hiring process efficient. That said, every hiring decision is made by real Twilions!
Also, while we are a remote-first company, you may be asked to report in person on an ad-hoc basis for team gatherings, functional off-sites or customer meetings.
.
See yourself at Twilio
Join the team as Twilio’s next Security Risk Senior Analyst.
About the job
The Senior Security Risk Analyst will be a key member of the One Twilio Risk Management program, focused on maturing our Security risk posture by facilitating risk identification and treatment. The team works closely with our Product and Engineering teams to ensure all areas of cyber risk are identified across Twilio and that risk methodologies are operationally effective and in compliance with regulations (e.g. Cybersecurity and/or Telecom / sector-specific regulations) and industry best practice security measures (e.g. NIST RMF, AI RMF, COSO, ISO 31000). This role provides an exciting opportunity for experienced risk professionals who are passionate about risk management and ready to contribute to the continued growth and maturity of risk practices within a dynamic organization like Twilio.
Responsibilities
In this role, you’ll:
- Execute and improve upon daily operations of the One Twilio Risk Management program which includes the further establishment of automated operations for all areas of cyber risk.
- Manage and maintain risk register(s) to track key risk indicators (KRIs) and ensure risks are identified, evaluated, and mitigated appropriately.
- Collaborate with cross-functional teams to ensure risks are clearly communicated and actionable.
- Review and assess the effectiveness of risk treatment strategies and recommend solutions when applicable.
- Prepare and deliver regular risk reports, dashboards, and presentations to internal and external stakeholders, highlighting key risk trends, issues, and mitigation efforts.
- Analyze risk data from various sources to assess trends and develop predictive models for potential risks.
- Use data analytics and risk modeling tools to assess the legal, financial, operational, and security impact of risks.
- Develop ad-hoc reports and presentations as required to support risk decision-making.
- Coordinate with internal and external auditors to support compliance assessments and resolve any risk-related findings.
Qualifications
Twilio values diverse experiences from all kinds of industries, and we encourage everyone who meets the required qualifications to apply. If your career is just starting or hasn't followed a traditional path, don't let that stop you from considering Twilio. We are always looking for people who will bring something new to the table!
*Required:
- 5+ years of Risk Management experience, working with security-centric risk management and compliance frameworks. Experience maturing an industry accepted risk framework including but not limited to NIST Risk Management Framework, COSO Enterprise Risk Management, or ISO 31000.
- Excellent cross-functional collaboration leveraging relationships to establish strategic direction
- Experience designing and executing qualitative and quantitative risk analyses to translate technical vulnerabilities into measurable business impact
- Experience translating vulnerabilities, control gaps and systematic limitations into clear, actionable risk statements.
- Proven track record of managing large scale, heavily regulated, multi-entity, cross-functional risk assessments, risk registers, and compliance programs
- Experience of working with technical security and Engineering / IT to implement technical risk/control solutions with the ability to interpret control requirements and relay those to different stakeholder groups with strong technical knowledge.
- Bias towards automation and tooling to scale program impact and reach
- Experience leveraging AI to streamline risk operations
- Excellent verbal, written, and interpersonal skills.
- Flexible and able to manage multiple projects under tight deadlines.
- Comfortable with ambiguity and adaptable to fast changing environments.
- Strategic thinker and problem solver with exceptional communication skills.
Desired:
- Bachelor’s degree in Risk Management, Business, Finance, Cybersecurity, or a related field.
- Professional certifications (e.g., CRISC, CISA, CISSP, FRM) are a plus.
- Strong analytical and problem-solving skills with the ability to interpret complex data and present actionable insights.
- Excellent communication skills, with the ability to translate risk into clear, actionable recommendations for leadership.
- Strong proficiency with enterprise AI and GRC tooling
- Experience with project management and working across multiple teams and departments.
Location
This role will be remote and based in Ontario, British Columbia or Alberta, Canada.
Travel
We prioritize connection and opportunities to build relationships with our customers and each other. For this role, you may be required to travel occasionally to participate in project or team in-person meetings.
What We Offer
Working at Twilio offers many benefits, including competitive pay, generous time off, ample parental and wellness leave, healthcare, a retirement savings program, and much more. Offerings vary by location. Based on role, employees may also be eligible for additional compensation and benefits, including but not limited to incentive programs, commissions, equity grants, health and wellness benefits, retirement contributions, and paid time off.
The estimated pay ranges for this role are as follows:
- $99,760 - $124,700
- Target Bonus Percentage 12.5%
The successful candidate’s starting salary will be determined based on permissible, non-discriminatory factors such as skills, experience, and geographic location.
Twilio thinks big. Do you?
We like to solve problems, take initiative, pitch in when needed, and are always up for trying new things. That's why we seek out colleagues who embody our values — something we call Twilio Magic. Additionally, we empower employees to build positive change in their communities by supporting their volunteering and donation efforts.
So, if you're ready to unleash your full potential, do your best work, and be the best version of yourself, apply now! If this role isn't what you're looking for, please consider other open positions.
.
Stay alert to recruitment fraud
We care about your safety. Scammers sometimes impersonate Twilio recruiters through fake job postings, emails, websites, or messages. Please ensure you are engaging with an official @twilio.com email address. We will never ask for payment, gift cards, cryptocurrency, or banking information during the recruiting process. We do not make job offers without a formal interview process or conduct interviews exclusively through text-based messaging apps.
.
Twilio is proud to be an equal opportunity employer. We do not discriminate based upon race, religion, color, national origin, sex (including pregnancy, childbirth, reproductive health decisions, or related medical conditions), sexual orientation, gender identity, gender expression, age, status as a protected veteran, status as an individual with a disability, genetic information, political views or activity, or other applicable legally protected characteristics. We also consider qualified applicants with criminal histories, consistent with applicable federal, state and local law. Qualified applicants with arrest or conviction records will be considered for employment in accordance with the Los Angeles County Fair Chance Ordinance for Employers and the California Fair Chance Act. Additionally, Twilio participates in the E-Verify program in certain locations, as required by law.