Information Security Risk & Compliance Analyst

Wright-Patt Credit UnionBeavercreek, OH
$84,427 - $126,568Onsite

About The Position

The Information Security Risk & Compliance Analyst is responsible for the day-to-day tactical support of WPCU’s Information Security Risk program and Third-Party Risk Management (TPRM) program. The position performs risk assessments for products and technologies following industry recognized frameworks such as CIS, NIST, MITRE ATT&CK and OWASP Top 10. This role is required to work closely with business units, Information Technology, and Enterprise Risk Management. They serve as the Information Security Subject Matter Expert (SME) for vendor risk management and will conduct evaluations of new and existing third-party relationships including but not limited to: conducting document due diligence; supporting contract reviews; and identifying risks associated with vendors. They are responsible for ensuring all risks identified either through Information Security Risk Assessments or TPRM program are properly documented in the Issue Management, seeking regular updates towards resolution, and escalating concerns when needed.

Requirements

  • Information Security Risk program knowledge
  • Third-Party Risk Management (TPRM) program knowledge
  • Risk assessments for products and technologies
  • Familiarity with industry recognized frameworks such as CIS, NIST, MITRE ATT&CK and OWASP Top 10
  • Collaboration with business units, Information Technology, and Enterprise Risk Management
  • Subject Matter Expert (SME) for vendor risk management
  • Conduct evaluations of new and existing third-party relationships
  • Conducting document due diligence
  • Supporting contract reviews
  • Identifying risks associated with vendors
  • Documenting identified risks in Issue Management
  • Seeking regular updates towards resolution
  • Escalating concerns when needed
  • Understanding business impacts of risks
  • Ensuring contract terms are commensurate with vendor due diligence requirements
  • Identifying Service Level Agreements (SLA), Data Residency requirements, and Data Breach
  • Documenting findings, residual risks, and recommendations within TRPM tools and Issue Management platform
  • Developing new risk assessments for emerging technologies (e.g., AI)
  • Risk Assessment methodology based on industry standards (MITRE, NIST CSF)
  • Execution of existing risk assessments
  • Identifying new risks, updating existing risks, or identifying new/changed/removed controls
  • Developing and maintaining a consistent process for identifying inherent likelihood, inherent impact, and control effectiveness
  • Process applicable to individual assets, groups of assets, or processes
  • Identifying where changes in control effectiveness impact existing risks
  • Building and maintaining a control library
  • Ensuring proper policies, procedures, risk mitigation activities, and operating controls are followed
  • Reporting gaps in policies, procedures, and operating controls
  • Ensuring risks exceeding enterprise risk appetite are properly entered into Issue Management
  • Completing timely and recurring reviews of risk mitigation or remediation plans
  • Ensuring risks identified during projects or Control Effectiveness Reviews are properly tracked in Issue Management
  • Providing thought leadership on monitoring/reporting of Issue Management

Responsibilities

  • Evaluate technology and cybersecurity risks presented by new and existing vendors, disaster recovery, or business continuity.
  • Collaborate with Vendor Risk Management under Enterprise Risk to determine required risk tiers and execute workflows to capture corresponding due diligence requirements.
  • Review and assess due diligence documents for adequacy, control effectiveness, and gaps.
  • Coordinate with business units to understand business impacts of risks identified during the vendor due diligence process.
  • Collaborate with Legal to ensure contract terms are commensurate with vendor due diligence requirements such as identifying Service Level Agreements (SLA), Data Residency requirements, and Data Breach.
  • Document findings, residual risks, and recommendations within the TRPM tools and Issue Management platform.
  • Provide thought leadership on maturing the Information Security components of TPRM.
  • Development of new risk assessments that address emerging technologies such as Artificial Intelligence (AI). Risk Assessment methodology must be based on industry standards such as MITRE and NIST CSF.
  • Execution of existing risk assessments on their assigned basis to determine drift or changes from previous assessments. This may include identification of new risks, updating existing risks, or identifying new / changed / removed controls.
  • Develop and maintain a consistent process for identifying the inherent likelihood, inherent impact, and control effectiveness. Process must be applicable to individual assets, groups of assets, or process.
  • Collaborate with the Information Security team to identify where changes in control effectiveness impact existing risks.
  • Collaborate with Information Security Analysts to build and maintain a control library that properly documents all active/available controls.
  • Ensures proper policies, procedures, risk mitigation activities, and operating controls are followed. Reports gaps in policies, procedures, and operating controls to leadership to ensure member impact and risk is mitigated.
  • Ensure risks exceeding enterprise risk appetite are properly entered into the Issue Management system in a timely fashion.
  • Complete timely and recurring reviews of risk mitigation or remediation plans identified during the risk assessment.
  • Ensure risks identified during projects or Control Effectiveness Reviews are properly tracked in Issue Management.
  • Provide thought leadership on monitoring / reporting of Issue Management.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service