IT Risk and Compliance Analyst
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
IT Risk and Compliance Analyst: Evaluating, assessing, and monitoring the firm’s risk and compliance with information security standards and frameworks with an accent on security assessments, incident response, and policy maintenance. Focus on responding to client security questionnaires, conducting vendor risk assessments, and maintaining DR/BCP programs.
Washington, DC; New York, NY; Boston, MA; Chicago, IL
Salary Range: $90,000-$115,000
Company
BRG combines academic credentials with business expertise in economics, disputes, investigations, corporate finance, and performance improvement for clients across industries like healthcare, financial services, and government.
What you will do
- Provide IT security, risk, and compliance advice to business units and analyze gaps in operations, processes, controls, and policies.
- Maintain and update Information Security Program policies, procedures, and conduct yearly reviews.
- Coordinate security incident response, respond to escalated events, and govern the process documentation.
- Evaluate, develop, and implement security standards for multiple platforms and work with auditors on controls evidence.
- Complete client security questionnaires, assist with RFI responses, and vet vendors through risk assessments.
- Assist with complex security assessments, DR/BCP policies, and Security Awareness Training initiatives.
Requirements
- Candidate must be able to submit verification of legal right to work in the U.S., without company sponsorship
- Associate Degree or equivalent work experience
- 3 years of experience in two or more major IT functions (infrastructure, operations, datacenter, application support)
- 3 years IT security, IT compliance, or IT risk management experience desired
- 3 years of experience involving ISO27001 annual surveillance and recertification audits
- Knowledge of application/network security, risk management, DR/BCP programs; strong analytical, communication, and prioritization skills
- Position may require travel for short periods (up to 5+ days, expenses reimbursed)
Nice to have
- Familiarity with SOC2, HIPAA, HITRUST, GDPR, CCPA frameworks
- Familiarity using GRC tools
Culture & Benefits
- Culture centered on agility, connectivity, interdisciplinary relationships, and diverse perspectives
- Global reach with specialists, experts, academics, and data scientists
- Equal Opportunity Employer committed to inclusive hiring practices
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →