Security Risk Analyst

Audax Group•Boston, MA
•$110,000 - $130,000•Hybrid

About The Position

The Information Security Risk Analyst owns and executes the risk assessment activities that drive the ongoing maturity of the firm's information security risk program. This role independently performs risk assessments of vendors, applications, and internal systems, and maintains the supporting artifacts needed to track remediation and report risk in a consistent, repeatable way. The position also leads SOC 1 IT control evidence collection, audit coordination, due diligence questionnaires, and change management control validation. The Risk Analyst partners closely with IT, Legal, Compliance, IR, and business stakeholders to ensure security risks are identified, documented, communicated, and addressed through practical mitigation plans. This role helps improve audit readiness, supports investor and customer assurance needs, and enables the business to operate efficiently while meeting governance and security expectations.

Requirements

  • Bachelor’s degree in Information Security, Computer Science, Risk Management, or equivalent practical experience.
  • 3+ years of experience in information security risk, GRC, third-party risk, audit support, or security compliance.
  • Strong communication skills (written and verbal) with the ability to work across IT, Legal, Compliance, Privacy, HR, and business teams.
  • Demonstrated ability to manage multiple priorities, meet deadlines, maintain high-quality documentation, and follow through.
  • High attention to detail and comfort working with structured evidence, audit artifacts, and repeatable processes.
  • Ability to handle sensitive information with discretion and sound judgment.
  • Availability for on-call incident response outside of normal working hours including nights, weekends, and holidays.
  • Some domestic travel is required.

Nice To Haves

  • Security+, CRISC, CISA, ISO 27001 Foundation / Lead.

Responsibilities

  • Perform independent information security risk assessments for vendors, applications, systems, and business processes.
  • Conduct application security vetting, including architecture reviews, control validation, and risk documentation.
  • Apply consistent risk rating methodology (likelihood, impact, inherent, residual) and document scoring rationale.
  • Partner with control owners to define practical remediation plans, including interim compensating controls.
  • Facilitate recurring risk review check-ins with control owners to validate progress on remediation plans.
  • Support risk exception and risk acceptance workflows (evidence collection, summaries, and tracking).
  • Maintain and update risk registers, remediation tracking, and control mappings.
  • Map assessment results to common security and control frameworks (e.g., NIST CSF, ISO 27001, SOC 1 & SOC 2).
  • Contribute to policy, standard, and control development initiatives.
  • Identify process improvements and support continuous improvement of GRC tooling.
  • Contribute to documentation of SOPs, templates, and playbooks.
  • Develop risk narratives that translate technical controls into business-relevant language.
  • Support business continuity and resilience efforts (BIA input and tracking).
  • Partner with business stakeholders to reduce onboarding cycle time through repeatable processes.
  • Lead SOC 1 IT control evidence gathering across business units.
  • Coordinate internal and external audit requests and evidence collection.
  • Validate change management controls and ensure documentation supports audit requirements.
  • Improve audit preparedness and reduce last-minute evidence collection efforts.
  • Manage and respond to due diligence questionnaires (DDQs) from investors, customers, and partners.
  • Support initiatives that increase investor confidence in the security posture.
  • Perform departing employee forensic reviews in collaboration with IT and HR.
  • Monitor and triage at-risk employee email and activity alerts.
  • Coordinate and track PII removal management activities, working with third-party providers and internal stakeholders.
  • Monitor and triage threat intelligence, digital risk protection (DRP) alerts, including brand impersonation, data exposure, and reputational threats, to identify new risks for assessment.

Benefits

  • health insurance
  • life insurance
  • disability insurance
  • paid time off (including sick leave, parental leave, volunteer leave, and vacation)
  • charitable donation match
  • family support services (including Bright Horizons and Benefit Advocate Center)
  • 401(k)
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service