À propos de ce poste Risk Analyst chez Thinkahead
Job Summary
The Risk Analyst supports the delivery of the design, implementation, and maintenance of the information technology risk management and compliance program. This role is crucial to ensuring the alignment of IT processes with business objectives, regulatory requirements, and industry best practices. This individual will work with leadership to monitor and instill trust in the security, compliance and reliability of AHEAD systems, services and programs.
Responsibilities
- Develop and oversee the IT risk assessment process to ensure that risks are identified, assessed, and managed in a controlled and systematic manner.
- Ensure that IT processes and systems are properly assessed for risk and compliance, and that they receive appropriate evaluation and authorization before implementation.
- Support creating, reviewing, and updating IT risk management and compliance policies and procedures to ensure they reflect current best practices, regulatory requirements, and organizational needs.
- Execute Vendor risk assessment and analysis efforts by developing, delivering, and evaluating vendor responses.
- Support Client due diligence efforts by reviewing, routing, and responding to client assessments, RFPs, and other inbound inquiries.
- Work closely with sales and legal teams to ensure that client security and risk obligations are understood and met.
- Support internal and external audits by providing necessary documentation and ensuring that findings are addressed in a timely manner.
- Develop and deliver training programs to raise awareness of IT risk management and compliance policies and procedures across the organization.
- Work closely with Management, Operations, Infrastructure, and Applications teams to establish processes, procedures, and documentation that ensure systems and resources meet necessary compliance requirements and obligations.
- Develop and execute metrics and KPIs for IT risk management and compliance.
Education and Experience
- Experience in IT Risk Management, IT Audit/Compliance, or Information Security is desired.
- One or more security certifications such as CISSP, CRISC, CISA or Security+ is desired.
- Demonstrated experience with the use and management of risk management and compliance frameworks such as ISO/IEC, NIST, COBIT, PCI-DSS, GDPR, or CMMI.
- Excellent oral and written communication skills are required.
- Highly organized and able to work independently.