The Information Security Risk Analyst owns and executes the risk assessment activities that drive the ongoing maturity of the firm's information security risk program. This role independently performs risk assessments of vendors, applications, and internal systems, and maintains the supporting artifacts needed to track remediation and report risk in a consistent, repeatable way. The position also leads SOC 1 IT control evidence collection, audit coordination, due diligence questionnaires, and change management control validation. The Risk Analyst partners closely with IT, Legal, Compliance, IR, and business stakeholders to ensure security risks are identified, documented, communicated, and addressed through practical mitigation plans. This role helps improve audit readiness, supports investor and customer assurance needs, and enables the business to operate efficiently while meeting governance and security expectations.
Stand Out From the Crowd
Upload your resume and get instant feedback on how well it matches this job.
Job Type
Full-time
Career Level
Mid Level