As the first security risk analyst, you'll build the vendor risk function from scratch, conducting assessments and implementing a comprehensive TPRM program.
Risk Analyst
📜 Description
- Develop, implement, and maintain an effective IT risk management and compliance framework.
- Oversee the IT risk assessment process to identify, assess, and manage risks systematically.
- Ensure IT processes and systems are assessed for risk and compliance before implementation.
- Create, review, and update IT risk management and compliance policies and procedures.
- Execute vendor risk assessments and support client due diligence efforts.
- Work closely with sales and legal teams to meet client security and risk obligations.
🛠️ Requirements
- Bachelor's degree or equivalent experience.
- Experience in IT Risk Management, IT Audit/Compliance, or Information Security is desired.
- One or more security certifications such as CISSP, CRISC, CISA, or Security+ is desired.
- Demonstrated experience with risk management and compliance frameworks like ISO/IEC, NIST, or PCI-DSS.
- Excellent oral and written communication skills.
- Highly organized and able to work independently.
✨ Benefits
- Comprehensive health insurance coverage for employees, with options to extend coverage to dependents.
- Paid time off and company holidays, along with additional leave benefits.
- Flexible work arrangements, supporting work-life balance.
- Learning and development opportunities to support continuous growth.
- Employee wellness initiatives focused on physical and mental well-being.
- Retirement and statutory benefits in line with India regulations.
Full job description
Job Summary
The Risk Analyst supports the delivery of the design, implementation, and maintenance of the information technology risk management and compliance program. This role is crucial to ensuring the alignment of IT processes with business objectives, regulatory requirements, and industry best practices. This individual will work with leadership to monitor and instill trust in the security, compliance and reliability of AHEAD systems, services and programs.
Responsibilities
- Develop and oversee the IT risk assessment process to ensure that risks are identified, assessed, and managed in a controlled and systematic manner.
- Ensure that IT processes and systems are properly assessed for risk and compliance, and that they receive appropriate evaluation and authorization before implementation.
- Support creating, reviewing, and updating IT risk management and compliance policies and procedures to ensure they reflect current best practices, regulatory requirements, and organizational needs.
- Execute Vendor risk assessment and analysis efforts by developing, delivering, and evaluating vendor responses.
- Support Client due diligence efforts by reviewing, routing, and responding to client assessments, RFPs, and other inbound inquiries.
- Work closely with sales and legal teams to ensure that client security and risk obligations are understood and met.
- Support internal and external audits by providing necessary documentation and ensuring that findings are addressed in a timely manner.
- Develop and deliver training programs to raise awareness of IT risk management and compliance policies and procedures across the organization.
- Work closely with Management, Operations, Infrastructure, and Applications teams to establish processes, procedures, and documentation that ensure systems and resources meet necessary compliance requirements and obligations.
- Develop and execute metrics and KPIs for IT risk management and compliance.
Education and Experience
- Experience in IT Risk Management, IT Audit/Compliance, or Information Security is desired.
- One or more security certifications such as CISSP, CRISC, CISA or Security+ is desired.
- Demonstrated experience with the use and management of risk management and compliance frameworks such as ISO/IEC, NIST, COBIT, PCI-DSS, GDPR, or CMMI.
- Excellent oral and written communication skills are required.
- Highly organized and able to work independently.
Similar jobs
Search more Risk Analyst jobsAs a Risk Analyst for Vendor Risk Assessment (VRA), you will leverage your technical expertise to assess vendor security controls and support SentinelOne's Information Security GRC team.
The Enterprise Risk Analyst will enhance risk management frameworks, support risk assessments, and improve reporting processes across the organization.
Associate Risk Analyst, Economic Capital
The Associate Risk Analyst will support ERM's Economic Capital initiatives, focusing on modeling, analysis, and collaboration to assess capital adequacy and risk profile.
Join a dynamic team as a Fraud & Risk Analyst, where you'll investigate and develop strategies to prevent third-party fraud while ensuring a seamless user experience.
