External candidates: In order for your application to be correctly processed please sign-in before you apply
Internal candidates: Please go to Workday and click "Find Jobs" link under Career
Thank you for considering opportunities with us!
Job Title
Cybersecurity Analyst V - RemoteRequisition Number
R8025 Cybersecurity Analyst V - Remote (Open)Location
Arizona - Home TeleworkersAdditional Locations
Job Information
CSAA Insurance Group (CSAA IG), a AAA insurer, is one of the leading personal lines property and casualty insurance groups in the United States. Here, every employee shapes our mission. We build innovative, human-centered solutions that help AAA members prevent, prepare for, and recover from life's uncertainties. You will join a collaborative, inclusive culture where your strengths have room to grow and your ideas can drive real impact. Step into a role where you can contribute to our shared success through meaningful work.
We are actively hiring for a Cybersecurity Analyst V - Remote
Your Role: As a senior cybersecurity risk professional, you will serve as a strategic advisor to business and technology leaders, helping identify, assess, and manage complex cybersecurity and technology risks. You will lead cross-functional risk initiatives, influence security and risk management strategies, and help strengthen the organization's risk posture. This role requires the ability to translate technical risks into clear business impact, provide actionable recommendations, and guide decision-making related to cybersecurity investments, controls, and governance. Operating with a high degree of autonomy, you will build trusted partnerships across the organization and contribute to the continuous evolution of cybersecurity risk management practices.
Your Work: Risk advisory and assessment
- Lead cross-domain cybersecurity and technology risk assessments for complex initiatives, critical business processes, control environments, and emerging technologies, including cloud and artificial intelligence use cases.
- Define and improve risk assessment approaches, methodologies, standards, and supporting tools to promote consistent identification, analysis, documentation, and treatment of risk.
- Apply qualitative and quantitative analysis, including probability, impact, and scenario-based methods, to clarify exposure, compare response options, and support risk-informed decisions.
- Evaluate the design and effectiveness of cybersecurity controls and technologies, identify material gaps or systemic themes, and recommend proportionate mitigation, acceptance, transfer, or avoidance strategies.
Strategic guidance and cross-functional influence
- Serve as a strategic advisor to technology, cybersecurity, and business partners on risk, governance, control, and operational implications.
- Translate complex technical risk into concise business impact, options, trade-offs, and recommendations for leaders and non-technical audiences through briefings, presentations, whitepapers, and position papers.
- Lead workshops and team member discussions that establish shared understanding, resolve ambiguity, and drive alignment on risk ownership, treatment decisions, priority, and resource needs.
- Integrate risk considerations into the lifecycle of technology projects, capabilities, and business initiatives, translating technical risk into business impact and supporting informed decision-making aligned with organizational objectives.
Capability and program development
- Lead risk framework, reporting, tooling, capability-building, and maturity improvement efforts that span cybersecurity domains and functions.
- Identify trends and interdependencies across risks, controls, technologies, and business operations; communicate implications and recommend program-level improvements.
- Mentor analysts and risk professionals, share advanced analytical practices, and strengthen consistent application of cybersecurity risk management methods.
- Maintain awareness of emerging threats, evolving technologies, regulatory requirements, and industry trends, using these insights to strengthen and enhance cybersecurity risk advisory capabilities.
Required Experience, Education and Skills
- 8-10 years of progressive experience in cybersecurity, technology risk management, IT operations, IT audit, governance, compliance, or related technical fields.
- Demonstrated experience leading complex analyses or cross-functional initiatives, advising stakeholders on risk and control implications, and delivering major work products with a high degree of autonomy.
- Experience applying cybersecurity risk management methodologies, control frameworks, governance models, and supporting tools in an enterprise environment.
- Bachelor's degree in Cybersecurity, Information Systems, Computer Science, Information Technology, or a related field; or equivalent practical experience may be considered in place of a bachelor's degree.
What would make us excited about you?
- Recognized domain expertise in cybersecurity risk management, governance, control assessment, risk response, and capability or maturity models. Thorough knowledge of cybersecurity standards and frameworks such as NIST, ISO 27001, and CIS Controls, with the ability to advise on practical application.
- Broad understanding of cybersecurity domains and the technologies they protect, including cloud services, networks and infrastructure, applications, data, identity, databases, protocols, security tools, and emerging technologies. Understands how security capabilities and controls reduce cybersecurity risk.
- Exceptional problem analysis in complex, ambiguous, or novel scenarios. Identifies systemic issues and broader implications; develops defensible solution paths; and explains cost, benefit, uncertainty, and residual risk.
- Exceptional understanding of measurement, probability, statistics, metrics, and quantitative risk concepts, including cyber risk quantification, sufficient to develop or apply models and communicate limitations responsibly.
- Identifies and assesses business and technology challenges, performs root cause analysis, recommends risk-informed technology solutions, and drives implementation to support organizational objectives and mitigate risk.
- Connects cybersecurity and technology risk to business services, processes, strategic objectives, and industry context. Considers programmatic and organizational impacts when developing recommendations.
- Operates with a high degree of autonomy on complex initiatives, providing direction for high-impact work, leading cross-functional efforts, and mentoring team members while maintaining accountability for quality, timeliness, and outcomes.
- Actively shapes our company culture (e.g., supporting employee resource groups, mentoring employees, volunteering, joining cross-functional projects)
- Champions our cultural norms (e.g., willing to have cameras when it matters: helping onboard new team members, building relationships, etc.)
- Demonstrates a company ownership mindset, thinking beyond boundaries of their own area
- Travels as needed for role, including divisional / team meetings and other in-person meetings
- Fulfills business needs, which may include investing extra time, helping other teams, etc
Please note we are hiring for this role remote anywhere in the United States with the following exceptions: Hawaii and Alaska.
Why Choose a Career at CSAA IG?
At CSAA IG, we are a mission-driven organization proudly committed to empowering our members, our employees, and our communities to thrive.
Recognition: We offer a total compensation package, annual bonus eligibility for most roles, 401(k) with a company match, and so much more! Read more about what we offer and what it is like to be a part of our dynamic team at https://careers.csaainsurance.aaa.com/us/en/benefits.
Career Growth: We believe in growth for everyone. Here at CSAA IG, leaders and mentors partner with employees to align interests, unlock development opportunities, and support long‑term success.
Flexible Workplace: We embrace a remote-first culture through our Flexible Workplace. Most employees hold Home-Flex roles, working primarily from home, often with the flexibility to work from various locations including CSAA offices. Our flexible workplace empowers you to balance remote work with intentional in‑person moments that deepen connection and collaboration.
Inclusion and Belonging: An inclusive and welcoming workplace is the cornerstone of our success. By fostering an environment where people feel valued and heard, we deepen our ability to understand and meet the unique needs of our members. This strengthens innovation and enhances our products and services, giving us a competitive edge in the market.
Sustainability: As climate change leads to more frequent and severe weather events, we are taking bold action to build more resilient communities and reduce our environmental impact. Submit your application to be considered. We communicate via email, so check your inbox and/or your spam folder to ensure you don’t miss important updates from us.
CSAA is committed to providing reasonable accommodations to qualified applicants and employees with disabilities or other limitations. If you would like to request an accommodation to participate in the job application or interview process, please contact TalentAcquistion@csaa.com
If you apply and are selected to continue in the recruiting process, we will schedule a preliminary call with you to discuss the role and will disclose during that call the available salary/hourly rate range based on your location. Factors used to determine the actual salary offered may include location, experience, or education.
CSAA does not provide visa sponsorship for this role. Applicants must have authorization to work indefinitely in the US. Please do not apply for this role if at any time (now or in the future) you will need immigration support (i.e., H-1B, TN, STEM OPT Training Plans, etc.).
CSAA Insurance Group is an equal opportunity employer.
#LI-SB1
The national average salary range for this position is $136,890.00-$152,100.00. However, we have a location-based compensation structure. Our salary ranges vary and are calculated based on work location. The starting pay range for this position across all the states we hire in is $136,890.00-$182,450.00.  This role also includes an opportunity for a company-wide annual discretionary bonus, through our Annual Incentive Plan (AIP), of up to 12% of eligible pay.This job posting will be unposted on Fri, 23 Oct 2026.Learn more about this Employer on their Career Site
