IT Risk Analyst II
Core
Conduct end-to-end third-party risk management (TPRM) and security risk assessments for vendors, suppliers, internal systems, and projects, recommending controls based on deep system understanding.
Role type
Senior IC IT Risk Analyst (Third-Party Risk & Security)
Builds
Security risk assessments, control recommendations, and AI-enhanced risk workflows
Domain
Higher Education / Information Security / Third-Party Risk Management
Deliverable
production ML models | product features | dashboards & analysis | client delivery | infrastructure
Required skills
Third-party risk assessment, security risk assessment, NIST frameworks, OSINT research, control recommendation, risk communication, AI tool integration, regulatory compliance (FERPA, GLBA, GDPR, HIPAA)
Preferred skills
TPRM platforms, GRC tooling, higher education experience, CISSP/CISM/CRISC/CISA certifications
Technologies
NIST, SOC 2, AI agents, GRC tools
Responsibilities
Conduct third-party and supplier risk assessments including scoping, evidence review, and residual risk conclusions; Perform security risk assessments of internal systems using industry frameworks; Execute OSINT research to establish security profiles of targets; Collaborate with engineers and business units to understand system operations before recommending controls; Advise stakeholders on remediation of identified deficiencies; Measure and report on key risk indicators; Identify and build AI efficiencies in risk workflows; Contribute to security policies and assessment methodologies.
Seniority
Senior, hands-on IC