Cyber Risk Analysts - what do you do?
I'm a SIEM Analyst/Engineer with a bit of BAU across PAM, DLP, Threat and Vuln. Basically, a bit of everything at high level. I've seen a role for a risk analyst. Judging from the description, it's document heavy - the closest thing I can relate to is documenting ServcieNow tickets so everyone knows how it's done and taking care of a risk register for CVEs; based off pen test reports. Is there a lot more to it? I'm not at a skill level where I can "yep, that's a gap - fix it" submitted by...