Senior Security Risk Analyst
About the Role
Muon seeks a Senior Security Risk Engineer to join our Security Engineering & IT team. The ideal candidate brings deep expertise across multiple security domains and can operate independently to protect Muon’s infrastructure, data, and people. You will focus on security risk — identifying, assessing, and helping address risks across our environment and every company function, from engineering and IT to operations, finance, and the supply chain. You will run risk assessments, prioritize what matters most, drive remediation with the teams that own it, and give leadership a clear, current picture of Muon's risk posture, including compliance efforts such as NIST 800-171 and ITAR/EAR.
This position may be fully on-site at our San Jose office, hybrid, or fully remote from an approved U.S. location.
Responsibilities
Lead security risk assessments across the company — identify, analyze, and prioritize risks across engineering, IT, operations, and business functions
Maintain a risk register and a clear, current view of Muon's risk posture for leadership
Partner with teams across the company to drive remediation of identified risks and track them to closure
Assess the security risk of new tools, vendors, third parties, and architectural or process changes before adoption
Define and apply a consistent risk framework and methodology — likelihood and impact scoring, risk acceptance, and exceptions
Map risks and controls to compliance requirements such as NIST 800-171 and CMMC, and support audits and assessments
Report risk trends and metrics to leadership and recommend where to invest to reduce the most risk
Help teams build risk-aware processes and take ownership of the risks they hold
Qualifications
5+ years in information security, security engineering, or security risk/GRC roles
Hands-on experience running security risk assessments and managing a risk register
Strong understanding of security risk frameworks and methodologies (e.g., NIST RMF / 800-30, FAIR, or similar)
Familiarity with compliance frameworks such as NIST 800-171, CMMC, SOC 2, or ISO 27001
Excellent written and verbal communication skills — able to convey risk and priorities to both engineers and leadership
Nice-to-Have Skills
Relevant certifications (CISSP, CRISC, CISA, or similar)
Background in environments subject to ITAR/EAR export control requirements
Salary
The salary range for this role is $154,000 - $207,000, plus a competitive equity grant and comprehensive benefits package. Final compensation will be determined based on skills, qualifications, experience, and geographic location as assessed during the interview process.