IT Risk Analyst

Fordham University PortalRose Hill, VA
Onsite

About The Position

Reporting to the Senior Director of Security and Assurance, the IT Risk Analyst assists in designing and implementing disaster recovery and business continuity solutions, user security awareness, security access requests and authorizations, third-party risk management, and compliance monitoring. Additionally, this position collaborates with executive management to quantify acceptable levels of risk for the enterprise and the University’s Internal Audit department to perform audits of Information Technology published policies, processes, and compliance with relevant frameworks.

Requirements

  • Assists in designing and implementing disaster recovery and business continuity solutions
  • User security awareness
  • Security access requests and authorizations
  • Third-party risk management
  • Compliance monitoring
  • Collaborates with executive management to quantify acceptable levels of risk for the enterprise
  • Collaborates with the University’s Internal Audit department to perform audits of Information Technology published policies, processes, and compliance with relevant frameworks.

Nice To Haves

  • CRISC and/or CISA certification.

Responsibilities

  • Assists in identifying and addressing potential risks to the University’s information systems and operations.
  • Assists in the performance of IT Audits at the direction of the Senior Director, assisting Internal Audit where needed.
  • Manages the Disaster Recovery and Business Continuity Plans of the Office of Information Technology by coordinating with those responsible for systems related to Disaster Recovery planning, including developing, updating, and testing plans.
  • Contributes to the evaluation of the effectiveness of controls, identifies weaknesses, and proactively works with management to ensure conformity with laws, policies, and regulations.
  • Communicates unresolved security exposures, misuse, or noncompliance situations to management.
  • Conducts Disaster Recovery simulations, tabletop exercise(s), and conducts recovery test(s) in partnership with the Office of Information Technology.
  • Identifies areas of concern within contracts with third parties.
  • Analyzes application security needs based on the sensitivity or proprietary nature of the data to ensure all systems are utilized for management-approved purposes only.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service