Job Details

ID #54059475
Estado Virginia
Ciudad Henricocounty
Tipo de trabajo Full-time
Salario USD TBD TBD
Fuente ZILLION TECHNOLOGIES, INC
Showed 2025-06-23
Fecha 2025-06-23
Fecha tope 2025-08-22
Categoría Etcétera
Crear un currículum vítae
Aplica ya

Sr. Security Risk Analyst

Virginia, Henricocounty 00000 Henricocounty USA
Aplica ya

Job Title: Sr. Risk Analyst Location: Remote Position Description: Reporting to the Business Information Security Officer (BISO), the Senior Information Security Risk Analyst will lead specific information security risk management related activities that protect its clients while complying with applicable regulations and policies. The Senior Information Security Risk Analyst provides subject matter expertise and leadership to improve the organization’s security policies and security risk management processes by establishing a framework of controls so that the Bank can manage risk, meet regulatory compliance and maintain governance over all aspects of IT. The Senior Information Security Risk Analyst will have responsibilities to ensure that identifies risks and treats them in a timely manner while reporting the current level of exposure to known threats. The role includes implementation and maintenance of policies, as well as training and awareness plus vendor risk management responsibilities. The position requires experience of information security risk management in a regulated environment using industry standard risk and control frameworks. This role will work closely with Enterprise Risk Management (ERM) leaders. Position AccountabilitiesLead all audit prep and response across InfoSec and IT. Coordinate response to Internal Audit document requests, stage content and conduct reviews for completeness.Support Controls, Policy, Standards and Procedures maturity program for InfoSec and IT to meet mandatory FFIEC, SOX requirements and a threat/risk-based controls program buildout.Perform security risk analysis with the goal of identifying risk and elevating the company’s security posture.Serve as a subject matter expert and trusted advisor as part of establishing relationships to support risk-based decision making across business, IT and the broader stakeholder community at the Bank.Contribute to Information Security reports for Technology and Third-Party Risk Committee (TTRC), Cybersecurity Working Group (CSWG), and Operational Risk Committee as necessary.Lead efforts to track and remediate risk when those risks are determined to have a threat to the Bank’s safety, soundness, or reputation. Track risks and issues and ensure their on-schedule remediation in alignment with the ERM issues management process.Establish and maintain processes for managing security-related audits, control assessments, compliance checks and external assessments across Business, IT and Information Security. Ensure timely and complete responses to evidence requests and compile management responses and remediation plans as needed.Emphasize the application of privacy, security, business resiliency and compliance frameworks including but not limited to, FFIEC (Federal Financial Institutions Examination Council), Sarbanes-Oxley (SOX), Gramm-Leach-Bliley Act (GLBA), Service Organization Controls (SOC) 2, PCI-DSS, and ITIL V3/4 processes.Evaluate risk and controls by executing targeted testing of processes.Develop and publish policy, standards and procedures for implementation based on the Bank’s risk appetite, industry best practice guidance and based on a detailed knowledge of the regulatory and stakeholder requirements.Track and ensure all policies, standards and procedures are updated timely.Collaborate with the ERM team to design and maintain a risk and controls matrix mapped to applicable regulatory and selected framework controls and in alignment with the agreed risk appetite.Participate in the vendor risk assessment process and provide security risk assessment services and contract reviews to ensure that third parties meet the Bank’s information security control requirements.Support cyber training and awareness program, Cyber Tabletop exercises, Red Team Exercises, penetration testing and ensure all findings are addressed timely via the risk issue management process.Establish and lead a metrics program designed to track key risks and key performance indicators across the cyber security program and report them regularly to information security management and business leadership.Lead the configuration, integration, and optimization of Governance, Risk, and Compliance (GRC) platforms such as RSA Archer, ServiceNow, and similar tools to support risk assessments, control monitoring, issue tracking, and regulatory reporting.Organizational RelationshipThis assignment reports to the Business Information Security Officer (BISO).

Aplica ya Reportar trabajo

Puestos de trabajo relacionados