Cyber Governance and Risk Senior Analyst
Cohesity
- Location
- Dublin Ireland Office
- Work model
- On-Site
- Level
- Senior
- Posted
- Sep 17, 2026
Skills
About this role
Cohesity is the leader in AI-powered data security. Over 13,600 enterprise customers, including over 85 of the Fortune 100 and nearly 70% of the Global 500, rely on Cohesity to strengthen their resilience while providing Gen AI insights into their vast amounts of data. Formed from the combination of Cohesity with Veritas’ enterprise data protection business, the company’s solutions secure and protect data on-premises, in the cloud, and at the edge. Backed by NVIDIA, IBM, HPE, Cisco, AWS, Google Cloud, and others, Cohesity is headquartered in Santa Clara, CA, with offices around the globe. We’ve been named a Leader by multiple analyst firms and have been globally recognized for Innovation, Product Strength, and Simplicity in Design , and our culture . Want to join the leader in AI-powered data security? We are looking for a hands-on, technically capable Cyber Governance & Risk Senior Analyst to help change how security governance and risk work gets done at Cohesity. This is a builder role, alongside supporting our Security Governance and Cyber Risk programs, you'll identify where control monitoring and risk analysis can move from manual, point-in-time effort to continuous, automated monitoring and then build that cApability, using robotic process automation, agentic workflows, and AI-assisted development of in-house GRC capabilities. You'll partner directly with control owners and operators across Cohesity to drive security posture toward its targets, and you'll help prove that a governance and risk program can scale with a fast-growing company through automation rather than headcount. This role is ideal for someone who combines solid cybersecurity governance and risk fundamentals with a genuine appetite for building. HOW YOU’LL SPEND YOUR TIME HERE : Support both the Security Governance program (Common Controls Framework maintenance, policy and standards, KPI/SLA measurement) and the Cyber Risk program (findings intake, risk analysis through the Risk Management Lifecycle, Risk Register integrity). Identify which governance, control-testing, and risk-analysis work can move to continuous, automated monitoring, and build it using robotic process automation, agentic workflows, and in-house GRC tooling. Measure control effectiveness continuously against defined thresholds, so control drift surfaces when it happens rather than at the next assessment cycle. Codify control-effectiveness logic — what a control must prove, what evidence counts, what trips a finding, and where a human must decide so automation runs against clear logic with defined parameters and guardrails. Partner with control owners and control operators to deliver effectiveness drivers and prioritize remediation, ensure the evidence behind each control is available and trusted. Take individual or bundled findings through to risk and populate Risk Register entries ready for the risk owner's decision. Support the annual ISMS organizational risk assessment and produce continuous-monitoring evidence that meets certification and regulated-customer requirements. Build reusable monitoring and automation assets that can be shared across the Security Governance and Cyber Risk programs, and keep that automation itself under proper control governance. WE'D LOVE TO TALK TO YOU IF YOU HAVE MANY OF THE FOLLOWING : 4+ years of experience in cybersecurity governance, risk, or compliance (GRC), with hands-on control assessment or monitoring. Demonstrable experience building automation in a GRC, security, or compliance context — robotic process automation, scripting, or agentic workflows with concrete examples of what it replaced. Working knowledge of at least two control frameworks (e.g., SOC 2, ISO 27001, NIST CSF) and how control effectiveness is evidenced. Experience partnering with control owners or operators to drive remediation to closure, including where accountability sits outside the security team. Strong communication skills, with the ability to