Identity Risk Analyst

Omm IT SolutionsWoodlawn, MD
Onsite

About The Position

This is a 100% Onsite position located in Woodlawn, MD, requiring the selected candidate to work on-site 5 days a week. The role involves analyzing documents and conducting intake and elicitation sessions with project teams. The analyst will decompose applications or services into analytical components for impact assessment, conduct initial impact assessments, and document the reasoning behind each determination. This includes documenting impact assessments, assurance level selections, and tailoring decisions for each application or service. The analyst will re-engage with project teams when service scope, user populations, transaction types, or threat conditions change, affecting prior risk and determinations. The position requires producing analytical written products such as risk assessments, impact assessments, security plan sections, and control assessment reports. A key aspect of the role is applying a normative framework (NIST SP 800-63, 800-30, 800-37, or equivalent) to specific services and producing written analyses that demonstrate the judgments made at each step.

Requirements

  • Bachelor’s or higher degree in Computer Science, Information Systems, Cybersecurity, Mathematics, Statistics, Philosophy, Law, Economics, or a related analytical discipline.
  • Working knowledge of NIST SP 800-63-4, especially the base volume, and the NIST Risk Management Framework (SP 800-37).
  • Experience in fraud prevention, identity verification, risk analysis, cybersecurity, financial crime, or a related field.
  • Direct experience conducting digital identity risk assessments under NIST SP 800-63 (Revision 3 or 4) for production online services
  • Experience with Analytical decomposition: Reliably breaks complex systems into the components required for the analysis.
  • Experience with Rubric application: Applies a written rating rubric to a specific case by identifying the rubric row that matches the case and recording the corresponding rating. Does not substitute personal judgment for the rubric where the rubric is determinative.
  • Experience with Categorical reasoning: Can determine whether an impact category applies to a given situation before rating its severity.
  • Experience with Source-and-direction tracking: Distinguishes information the system holds about a user from information the user provided to the system.
  • Experience with Elicitation: Obtains required information from stakeholders, particularly when the information initially received is incomplete or conflicting.
  • Experience with Written precision: Produces clear analytical prose. Reasoning is traceable. Conclusions are tied to evidence.
  • Experience with Critical thinking: Evaluates information and arguments for soundness, identifies unstated assumptions, and distinguishes claims that are supported from those that are not.
  • Experience with Self-direction: Manages a queue of assessments without daily supervision and surfaces blockers early.
  • Must be able to obtain and maintain a public trust clearance.

Nice To Haves

  • Professional certifications: CISSP, CISA, CIPP/G, or equivalent would be a plus.
  • Strong attention to detail and organizational skills.
  • Proficiency with Microsoft Excel and standard business applications.
  • Ability to manage multiple priorities in a fast-paced environment while maintaining accuracy.

Responsibilities

  • Analyze documents and conduct intake and elicitation sessions with project teams.
  • Decompose applications or services into the analytical components required for impact assessment.
  • Conduct initial impact assessments and document the chain of reasoning supporting each determination.
  • Document each application or service’s impact assessment, assurance level selections, and any tailoring decisions.
  • Re-engage with project teams when service scope, user populations, transaction types, or threat conditions change in ways that affect prior risk and determination.
  • Produce analytical written products — risk assessments, impact assessments, security plan sections, control assessment reports, or equivalent.
  • Applying a normative framework (NIST SP 800-63, 800-30, 800-37, or equivalent) to a specific service and producing a written analysis that shows the judgments made at each step.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service