Skip to main content

Cybersecurity Risk Analyst

Security and resilience, an entry-level role

What does Cybersecurity Risk Analyst do?

Identifies threats, assesses security risk, evaluates controls, supports the risk register and helps the organization make risk-informed decisions, now including the AI systems inside the estate.

What it decides: The rating of a security risk and the control evidence behind it.

The competencies employers name

  • AI risk and impact assessmentcore, working knowledge

    Reviews purpose, data, affected people, accuracy, bias, security, oversight, vendors and law for a use case, scores likelihood and impact, and documents residual risk.

    14 graded topics teach this

  • AI risk register and treatment trackingcore, working knowledge

    Keeps the living record: each risk with a named owner, rating, treatment, residual risk, monitoring metric, threshold and review date.

    12 graded topics teach this

  • AI security fundamentalscore, working knowledge

    Understands prompt injection, data poisoning, model theft, insecure integrations and excessive agent privileges, and the controls that reduce each.

    17 graded topics teach this

  • Control design and operating-effectiveness testingrequired, working knowledge

    Maps risks to preventive, detective and corrective controls, then tests design and operation with samples, evidence and defensible findings.

    12 graded topics teach this

  • Shadow AI and data leakage controlrequired, working knowledge

    Finds unapproved AI use, sets which tools are approved and what may be pasted, and detects leakage without policing every keystroke.

    12 graded topics teach this

  • AI vendor due diligence and third-party riskrequired, working knowledge

    Tiers vendors by use and impact, requests evidence instead of promises, tests in the customer's context, and plans monitoring and exit.

    5 graded topics teach this

  • AI incident response and recoverypreferred, working knowledge

    Classifies AI incidents by severity, runs containment, preserves evidence, manages notification, and closes the loop with lessons learned.

    3 graded topics teach this

  • Working AI fluencyrequired, working knowledge

    Uses generative AI tools daily, knows what a model can and cannot do, and can say where an output should not be trusted.

    21 graded topics teach this

Where it is taught

Counted from the graded topics that teach this role's competencies. Your own path is shorter: it skips what you already cover.

Check your readiness for this role

Add what you already have (optional)
Signed in? Every topic you have passed already counts as proof.

Roles that feed into it

  • IT Analyst
  • Security Operations Analyst
  • Help Desk with security exposure
  • Recent graduate in information security

Where it leads

Backgrounds that reach it fastest

What postings tend to name

Frameworks: NIST CSF, ISO/IEC 27001, NIST AI RMF.

Credentials often listed: Security+, CRISC, CISA, CISSP. GAGE does not issue these and does not prepare for their exams; the record you earn here is your own graded evidence, which stands beside them.

Questions

How does AI change a cyber risk analyst's job?
New assets appear in the register: models, prompts, training data and agents, each with failure modes a firewall rule never covered. The method is the same; the objects are new.