Senior Risk Analyst
Core
Designing and maturing a quantitative security risk management program spanning information security, AI, and operational risk for an AI-driven market intelligence platform.
Role type
Senior IC Security Risk Analyst (GRC)
Builds
Enterprise risk register, risk scoring methodologies, executive risk dashboards, and AI-augmented risk workflows.
Domain
Information Security / GRC / AI Governance
Deliverable
production ML models | dashboards & analysis | infrastructure
Required skills
GRC frameworks (ISO 27001, NIST CSF, SOC 2), AI-native risk analysis, GRC platform proficiency (Drata, Vanta, AuditBoard), cloud security posture (CSPM, SIEM), data warehousing concepts, KRI development, risk scoring models, executive communication, privacy regulations (GDPR, CCPA)
Preferred skills
AI governance frameworks (ISO 42001, NIST AI RMF), third-party risk management (TPRM), quantitative risk measurement, automation workflow design
Technologies
LLMs, agents, automation tools, AWS/Azure/GCP, ServiceNow GRC, Drata, Vanta, AuditBoard
Responsibilities
Design and implement structured risk management programs and taxonomies; own and maintain the enterprise risk register as a live operational tool; leverage AI tools to monitor threats and automate risk analysis; support third-party and vendor risk assessments; assess AI-specific risks (bias, privacy, agentic behavior); produce executive-ready risk reports and dashboards; provide cross-functional risk advisory on technology adoption and process improvements.
Seniority
Senior, hands-on IC building a new function
