Jobs Companies Fried Frank Business Services Opportunities Information Governance Risk and Compliance Analyst

Über diese Information Governance Risk and Compliance Analyst Stelle bei Fried Frank Business Services Opportunities

Fried Frank Business Services Opportunities · Vor Ort · New York, New York, United States

At Fried Frank, we’re a community of 800 lawyers and 500 business services professionals across New York, Washington, DC, London, Frankfurt, and Brussels. We advise leading corporations, investment funds, and financial institutions on high-stakes M&A, securities, regulatory matters, real estate, and litigation. Our culture is grounded in our core values — excellence, integrity and collaboration — and is designed to foster continuous learning, meaningful mentorship, and lasting professional growth. We are firmly committed to pro bono service and social justice, building on a proud legacy in civil rights. Our inclusive talent strategy is a core part of our broader talent management efforts and we remain steadfast in fostering a workplace where everyone has the opportunity to grow, thrive, and become their best professional and personal selves. Our business services professionals are integral to the firm’s success, driving innovation, operational excellence and exceptional client service across all areas of the firm. We offer competitive compensation and a comprehensive benefits package, including comprehensive medical coverage, retirement plans and health and wellness initiatives designed to support your personal and professional wellbeing. We welcome passionate, driven individuals to join us, and be part of a team where you’ll be supported, inspired and empowered to build an exceptional career.

Position Summary:

As an Information Governance (IG), Risk, and Compliance Analyst, you will test, evidence, and report on the controls behind the firm's IG, risk, compliance, and information security programs. You will run recurring control audits, build the queries and scripts that generate the evidence, and produce the artifacts relied upon in client audits and internal assurance work.

Duties & Responsibilities:

Information Governance:

  • Develop IG policies and procedures, and translate them into enforceable technical configurations and measurable controls.
  • Maintain an auditable inventory of data assets across Microsoft 365 and other approved information repositories, capturing classification, ownership, location, and retention state.

Risk Management:

  • Contribute to enterprise-wide risk assessments, quantifying exposure from overprovisioned access, stale data, and sensitive data sprawl from platform reporting rather than self-attestation.
  • Develop risk mitigation strategies and control requirements, and track findings and remediation to verified closure.

Compliance:

  • Support compliance with client contractual obligations (including outside counsel guidelines), regulations, and data protection laws by implementing and evidencing the corresponding controls.
  • Serve as technical respondent for client audits, security questionnaires, and regulatory inquiries, mapping requests to implemented controls and assembling the evidence; familiarity with control frameworks (ISO, SOC 2, NIST) helps, though the emphasis is technical testing over certification work.

Audit, Control Testing, and Evidence Collection:

  • Plan and execute recurring control audits across Microsoft 365, Entra ID, Active Directory, and approved information repositories, and maintain the audit calendar, evidence library, and exception record.
  • Collect evidence programmatically with PowerShell, Microsoft Graph, and KQL, querying audit trails across identity, mail, file, and endpoint platforms to show a control operated over a defined period.
  • Perform entitlement reviews and access recertification covering nested group membership, privileged roles, service and shared accounts, dormant objects, and broadly permissioned repositories.
  • Test control effectiveness rather than assuming it, validating classification and DLP detection, retention and disposition execution, and alerting coverage.

Information Security:

  • Oversee of the information security program, including periodic review of security tooling configuration against approved baselines and hardening against exfiltration and insider risk.
  • Perform incident response and recovery tasks, including log review, containment and scoping queries, evidence preservation, and post-incident remediation tracking.

Vendor and Third-Party Management:

  • Assess third-party vendor risk in data handling, reviewing questionnaires, audit reports, and penetration test summaries against observable configuration.
  • Collaborate with procurement and legal teams on contractual security, audit rights, and data handling requirements.

Reporting and Communication:

  • Communicate risk, compliance, and security findings to technical and non-technical stakeholders, and maintain recurring reporting on control testing and access review results.

Education:

  • Bachelor's degree in a relevant field; certifications in IT audit (e.g., CISA), Microsoft security and compliance administration (e.g., SC-400, SC-200), or in risk management are a plus.

Experience:

  • Mid-level position; 3-5 years of hands-on experience in IG, compliance, IT audit, or information security, including demonstrable work running control tests or access reviews.

Skills & Abilities:

  • Strong analytical, problem-solving, and communication skills, with working proficiency in PowerShell and KQL and experience querying platform audit logs.
  • Practical familiarity with Microsoft 365, Entra ID, Active Directory, and permissions models across approved information repositories, plus audit logging on those platforms and the ability to collaborate cross-functionally.
The actual salary offered will be based on a number of factors including but not limited to the qualifications of the applicant, years of relevant experience, level of education attained, certifications or other professional licenses held, and if applicable, the location in which the applicant lives and/or from which they will be performing the job.
New York Salary Range
$110,000$125,000 USD
Bereit, sich bei Fried Frank Business Services Opportunities zu bewerben?
Bei Fried Frank Business Services Opportunities bewerben

Wie sich dieses Gehalt für Compliance vergleicht

Diese Stelle zahlt $117,500/yrunter der üblichen Spanne für Compliance Stellen.

$84,000 dem Median $165,450 $220,500

Übliche Spanne $128,600–$202,375/yr, aus 20 vergleichbaren Compliance Anzeigen auf JobsRadar (Vergütung auf USD hochgerechnet). Gehaltseinblicke für Compliance ansehen →

Über Fried Frank Business Services Opportunities

Our firm provides challenging and exciting career opportunities. We strive to foster an inclusive work environment where everyone can grow and embrace a successful career. We seek talent, passion and creativity to help support our firm in providing quality service to our clients.

Alle Jobs bei Fried Frank Business Services Opportunities ansehen →

Ähnliche Jobs

Diligent Corporation
Product Compliance Requirements Analyst
Diligent Corporation
⚡ Früh bewerben New York, New York, United Sta... Hybrid
● Neu 👁 Gesehen ✓ Beworben vor 4 Tg.
Mercury
Senior Compliance Risk Manager - Securities Compliance
Mercury
⚡ Früh bewerben San Francisco, CA, New York, N... · standortgebunden $163,000–$203,800
● Neu 👁 Gesehen ✓ Beworben vor 6 Tg.
Emigrant Bank
Deputy Chief Compliance Officer
Emigrant Bank
⚡ Früh bewerben New York, New York, United Sta... Vor Ort $200,000–$225,000
● Neu 👁 Gesehen ✓ Beworben vor 6 Tg.
Iberdrola
Senior Analyst - Compliance
Iberdrola
⚡ Früh bewerben United States Of America, New... Vor Ort
● Neu 👁 Gesehen ✓ Beworben vor 1 Wo.
Garda Capital Partners
Deputy Chief Compliance Officer (DCCO)
Garda Capital Partners
⚡ Früh bewerben New York, New York, United Sta... Vor Ort $200,000–$250,000
● Neu 👁 Gesehen ✓ Beworben vor 1 Wo.
FanDuel
Senior Technology Governance, Risk & Compliance (GRC) Analyst
FanDuel
⚡ Früh bewerben Atlanta, Georgia, United State... Vor Ort $138,000–$173,000
● Neu 👁 Gesehen ✓ Beworben vor 1 Wo.
Oscar Health
Sr. Manager, People Compliance
Oscar Health
⚡ Früh bewerben New York, New York, United Sta... Hybrid $135,792–$178,227
● Neu 👁 Gesehen ✓ Beworben vor 1 Wo.
tarte cosmetics
Global Trade Compliance Analyst
tarte cosmetics
⚡ Früh bewerben New York, New York, United Sta... Vor Ort $70,000–$80,000
● Neu 👁 Gesehen ✓ Beworben vor 1 Wo.
XR Extreme Reach
Legal & Compliance Operations Manager
XR Extreme Reach
⚡ Früh bewerben New York, New York, United Sta... Hybrid $160,000–$170,000
● Neu 👁 Gesehen ✓ Beworben vor 1 Wo.

Registrieren für Vorschläge, die auf die von Ihnen geöffneten Jobs und gespeicherten Suchen zugeschnitten sind.

Mehr Jobs bei Fried Frank Business Services Opportunities

Alle Jobs bei Fried Frank Business Services Opportunities ansehen →

Jetzt bewerben
🤖

Moment — langsam

JobsRadar wurde für echte Menschen gebaut, die eine schwere Zeit bei der Jobsuche haben — nicht für automatisierte Anfragen. Sie klicken viel zu schnell und sind jetzt vorübergehend blockiert.

Kommen Sie später wieder. Wenn Sie wirklich auf Jobsuche sind, stehen wir hinter Ihnen — verhalten Sie sich einfach wie ein Mensch.

Catch your next role the second it’s posted.

Create a free account and we’ll watch the boards for you — the instant a job matches your search, it lands in your inbox or Telegram. No digging, no refreshing.

Create free account

Free forever · takes 30 seconds · already have one?

Verschaffe dir einen Vorsprung bei der Jobsuche.

Tritt unserem Telegram-Kanal bei für das, was dir hilft, die Stelle zu bekommen — Gehaltsbenchmarks, den wöchentlichen Marktpuls und neue Feature-Drops. Kein Spam, nur Signal.

Dem Kanal beitreten — kostenlos