Sr IT Risk Security Analyst
Core
Senior IT Risk and Security Analyst acting as an interface between IT, Audit Services, and the business to manage, evaluate, and remediate IT risks and security issues.
Role type
Senior IC IT Risk and Security Analyst
Builds
Enterprise IT risk management framework, vendor risk assessments, audit compliance programs, and executive risk reporting.
Domain
Financial Services / IT Risk & Security
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
IT risk management, information security, audit methodologies, compliance frameworks, internal controls, vendor risk management, risk assessment, policy development, executive reporting
Preferred skills
CISA, CISSP, CRISC, CISM, CIA, ISO 27001 Lead Implementer/Auditor, SOX ITGCs experience, IT risk assessment methodologies
Technologies
SOC reports, ISO 27001 certifications, security questionnaires, penetration tests, encryption tools, data-handling practices, AI usage monitoring tools
Responsibilities
Lead enterprise IT risk management activities including annual risk assessments and risk committee facilitation; Support third-party technology risk management across the vendor lifecycle; Manage and enhance IT audit and compliance programs including SOX ITGCs and ISO 27001; Develop executive-level reporting and dashboards for risk exposure and compliance status; Conduct reviews of information systems and operational processes to assess security posture; Maintain ownership of risk management tools and processes.
Seniority
Senior, hands-on IC with mentorship responsibilities