Jobs › Companies › Audax Group › Security Risk Analyst

Über diese Security Risk Analyst Stelle bei Audax Group

Audax Group · Vor Ort · Boston, MA

Founded in 1999, Audax Group is a leading alternative investment manager with offices in Boston, New York, San Francisco, London and Hong Kong. With approximately $42 billion of assets under management and more than 475 employees, Audax is a leading capital partner for middle market companies, operating through three business lines: Audax Private Equity, Audax Private Debt, and Audax Strategic Capital. 

For more information, visit www.audaxgroup.com or follow Audax Group on LinkedIn.

POSITION SUMMARY:

The Information Security Risk Analyst owns and executes the risk assessment activities that drive the ongoing maturity of the firm's information security risk program. This role independently performs risk assessments of vendors, applications, and internal systems, and maintains the supporting artifacts needed to track remediation and report risk in a consistent, repeatable way. The position also leads SOC 1 IT control evidence collection, audit coordination, due diligence questionnaires, and change management control validation.

The Risk Analyst partners closely with IT, Legal, Compliance, IR, and business stakeholders to ensure security risks are identified, documented, communicated, and addressed through practical mitigation plans. This role helps improve audit readiness, supports investor and customer assurance needs, and enables the business to operate efficiently while meeting governance and security expectations.

RESPONSIBILITIES:

  • Risk Assessment & Remediation
    • Perform independent information security risk assessments for vendors, applications, systems, and business processes.
    • Conduct application security vetting, including architecture reviews, control validation, and risk documentation.
    • Apply consistent risk rating methodology (likelihood, impact, inherent, residual) and document scoring rationale.
    • Partner with control owners to define practical remediation plans, including interim compensating controls.
    • Facilitate recurring risk review check-ins with control owners to validate progress on remediation plans.
    • Support risk exception and risk acceptance workflows (evidence collection, summaries, and tracking).
  • Governance, Policy & Strategy
    • Maintain and update risk registers, remediation tracking, and control mappings.
    • Map assessment results to common security and control frameworks (e.g., NIST CSF, ISO 27001, SOC 1 & SOC 2).
    • Contribute to policy, standard, and control development initiatives.
    • Identify process improvements and support continuous improvement of GRC tooling.
    • Contribute to documentation of SOPs, templates, and playbooks.
    • Develop risk narratives that translate technical controls into business-relevant language.
    • Support business continuity and resilience efforts (BIA input and tracking).
    • Partner with business stakeholders to reduce onboarding cycle time through repeatable processes.
  • Audit, Assurance & Investor Relations
    • Lead SOC 1 IT control evidence gathering across business units.
    • Coordinate internal and external audit requests and evidence collection.
    • Validate change management controls and ensure documentation supports audit requirements.
    • Improve audit preparedness and reduce last-minute evidence collection efforts.
    • Manage and respond to due diligence questionnaires (DDQs) from investors, customers, and partners.
    • Support initiatives that increase investor confidence in the security posture.
  • Monitoring & Investigations
    • Perform departing employee forensic reviews in collaboration with IT and HR.
    • Monitor and triage at-risk employee email and activity alerts.
    • Coordinate and track PII removal management activities, working with third-party providers and internal stakeholders.
    • Monitor and triage threat intelligence, digital risk protection (DRP) alerts, including brand impersonation, data exposure, and reputational threats, to identify new risks for assessment.

TECHNICAL QUALIFICATIONS:

  • Strong understanding of risk management frameworks (NIST CSF, ISO 27001, SOC 1/2 controls).
  • Experience performing third-party, application, and internal technology risk assessments using a consistent methodology (likelihood, impact, inherent, residual).
  • Working knowledge of control frameworks and mapping (e.g.: NIST CSF, ISO 27001, SOC 1 ITGC, SOC 2).
  • Familiarity with application security concepts, including architecture patterns and common control areas (IAM, logging, encryption, vulnerability management), and documenting security risks clearly.
  • Experience maintaining risk registers, remediation tracking, control mappings, and supporting evidence repositories.
  • Understanding of change management controls and how to validate required documentation and approvals.
  • Strong written risk documentation skills, including drafting risk narratives that translate technical control details into business impact.
  • Comfort handling security questionnaires and assurance requests (DDQs), including collecting inputs and validating supporting artifacts.
  • Baseline familiarity with security monitoring concepts and sources (SIEM alerts, EDR context, vulnerability scan outputs, threat intel summaries) to support triage and risk translation.

REQUIREMENTS:

  • Bachelor’s degree in Information Security, Computer Science, Risk Management, or equivalent practical experience.
  • 3+ years of experience in information security risk, GRC, third-party risk, audit support, or security compliance.
  • Strong communication skills (written and verbal) with the ability to work across IT, Legal, Compliance, Privacy, HR, and business teams.
  • Demonstrated ability to manage multiple priorities, meet deadlines, maintain high-quality documentation, and follow through.
  • High attention to detail and comfort working with structured evidence, audit artifacts, and repeatable processes.
  • Ability to handle sensitive information with discretion and sound judgment.
  • Availability for on-call incident response outside of normal working hours including nights, weekends, and holidays.
  • Some domestic travel is required.
  • Preferred Certifications (not required): Security+, CRISC, CISA, ISO 27001 Foundation / Lead.

 

LOCATION: Boston, MA – Hybrid 4 days in-office. These in-office requirements may be adjusted based on the needs of the business.

For Massachusetts: The base salary range for this position is $110,000 - $130,000. The base salary range represents the estimated low and high end for this position at the time of this posting. Consistent with applicable law, compensation may vary and will be determined based on but not limited to, the skills, qualifications, and experience of the applicant along with the requirements of the position, and Audax reserves the right to modify this pay range at any time. An employee may also be eligible for annual discretionary incentive compensation based on performance. 

Audax offers a wide range of employee benefits, including health insurance, life insurance, disability insurance, paid time off (including sick leave, parental leave, volunteer leave, and vacation), charitable donation match, family support services (including Bright Horizons and Benefit Advocate Center), and a 401(k) in addition to other benefits.

This job description is not designed to cover or contain a comprehensive listing of activities, duties or responsibilities that are required of the employee. Duties, responsibilities and activities may change or new ones may be assigned at any time with or without notice. 

Audax Management Co. is an equal opportunity employer.

Please note that Audax Group and its affiliated entities do not accept unsolicited resumes from a third-party recruiting agency not currently under a signed agreement. Any unsolicited resume that is sent to directly to Audax Group or one of its affiliated entities, or its employees, including those submitted to hiring managers by a third-party recruiting agency not currently under a signed agreement, will be considered property of Audax Group. If a third-party recruiting agency submits a resume without an agreement, Audax Group or its affiliated entities explicitly reserves the right to pursue and hire those candidate(s) without any financial obligation to the third-party recruiting agency. Any third-party recruiting agency should contact either a member of the Talent Acquisition or Human Resource team at Audax Group, in conjunction with a valid, fully executed contract for service based upon a specific job opening.

 

 

Bereit, sich bei Audax Group zu bewerben?
Bei Audax Group bewerben

Wie sich dieses Gehalt für Risk Analyst vergleicht

Diese Stelle zahlt $120,000/yr — unter der üblichen Spanne für Risk Analyst Stellen.

$120,960 dem Median $162,850 $206,250

Übliche Spanne $136,300–$165,500/yr, aus 18 vergleichbaren Risk Analyst Anzeigen auf JobsRadar (Vergütung auf USD hochgerechnet). Gehaltseinblicke für Risk Analyst ansehen →

Ähnliche Jobs

PwC
Risk & Regulatory- Government Contract Consulting- Manager
PwC
⚡ Früh bewerben NY-New York Vor Ort $99,000–$232,000
● Neu 👁 Gesehen ✓ Beworben vor 1 Tg.
American Family Insurance
Senior Security & Risk Analyst (Hybrid)
American Family Insurance
⚡ Früh bewerben MA Boston Hybrid $111,000–$189,000
● Neu 👁 Gesehen ✓ Beworben vor 4 Tg.
PwC
Security Risk & Engineering- Cloud Security- Manager
PwC
⚡ Früh bewerben IL-Chicago Vor Ort $99,000–$232,000
● Neu 👁 Gesehen ✓ Beworben vor 6 Tg.
Voya Financial
Sr, Operational Risk Analyst, Business Risk Management
Voya Financial
⚡ Früh bewerben MN-Work@Home, Minnesota Vor Ort
● Neu 👁 Gesehen ✓ Beworben vor 6 Tg.
The Hartford
Senior Catastrophe Risk Modeling Analyst
The Hartford
⚡ Früh bewerben Coral Gables, FL Hybrid $109,040–$163,560
● Neu 👁 Gesehen ✓ Beworben vor 2 Wo.
GM
Quantitative Research Analyst, Investment Risk and Capital Markets Research (Grantham, Mayo, van Otterloo & Co. LLC)
Gmo
⚡ Früh bewerben Boston, MA Hybrid $170,000–$185,000
● Neu 👁 Gesehen ✓ Beworben vor 3 Wo.
Wellington Management
Investment Risk Analyst, Fixed Income
Wellington Management
⚡ Früh bewerben London, United Kingdom Vor Ort $90,000–$180,000
● Neu 👁 Gesehen ✓ Beworben vor 1 Mon.
Starr Insurance
Claims Manager, Risk Management
Starr Insurance
⚡ Früh bewerben Philadelphia, PA Vor Ort
● Neu 👁 Gesehen ✓ Beworben vor 1 Mon.
Starr Insurance
Claims Manager, Risk Management
Starr Insurance
⚡ Früh bewerben Chicago, IL Vor Ort
● Neu 👁 Gesehen ✓ Beworben vor 1 Mon.

Registrieren für Vorschläge, die auf die von Ihnen geöffneten Jobs und gespeicherten Suchen zugeschnitten sind.

Mehr Jobs bei Audax Group

Alle Jobs bei Audax Group ansehen →

Jetzt bewerben
🤖

Moment — langsam

JobsRadar wurde für echte Menschen gebaut, die eine schwere Zeit bei der Jobsuche haben — nicht für automatisierte Anfragen. Sie klicken viel zu schnell und sind jetzt vorübergehend blockiert.

Kommen Sie später wieder. Wenn Sie wirklich auf Jobsuche sind, stehen wir hinter Ihnen — verhalten Sie sich einfach wie ein Mensch.

Catch your next role the second it’s posted.

Create a free account and we’ll watch the boards for you — the instant a job matches your search, it lands in your inbox or Telegram. No digging, no refreshing.

Create free account

Free forever · takes 30 seconds · already have one?

Verschaffe dir einen Vorsprung bei der Jobsuche.

Tritt unserem Telegram-Kanal bei für das, was dir hilft, die Stelle zu bekommen — Gehaltsbenchmarks, den wöchentlichen Marktpuls und neue Feature-Drops. Kein Spam, nur Signal.

Dem Kanal beitreten — kostenlos