Role Summary :
The Security Risk and Compliance Analyst I is responsible for executing control assessments, maintaining compliance with regulatory and industry mandates, supporting policy documentation, managing the risk register, and assisting in continuous improvement of the organization's security and compliance posture.
Key Responsibilities :
- Conduct control assessments to identify and evaluate IT and information security risks
- Maintain documentation for policies, standards, procedures, and risk assessments
- Coordinate penetration tests, vulnerability scans, and track remediation actions to closure
- Assist in continuous improvement and maturation of the Information Security GRC program
- Maintain the risk register and track risk response plans for timely closure
- Perform audits and assessments of third parties including vendors and service providers
- Collaborate with Technology and Security teams to develop remediation action plans
Minimum Requirements :
2+ years of experience in information security, IT audit, or IT risk and complianceKnowledge of compliance frameworks such as COSO, COBIT, NIST, ISO 27001Understanding of IT general controls and compliance initiatives including SOC1, SOC2, HIPAA, HITRUST, GDPR, FEDRAMPFamiliarity with IT and information security technologies such as IAM, vulnerability management, encryption, logging and monitoring, and application securityKnowledge of cloud and SaaS-based environments and auditing methodologiesRelevant certifications like CISSP, CISA, CRISC, ISO 27001 Lead Auditor / Implementer are desirableSkills Required
Risk Assessment, It Compliance, Vulnerability Management, Cloud Security