
Information Security Risk Analyst II
Posted 17 hours ago

Posted 17 hours ago
This is a fully remote position, open to applicants in Alabama, +31 more states.
• Perform qualitative and quantitative assessments of information security risks across systems, vendors, technologies, and business processes.
• Detect threats, vulnerabilities, and control deficiencies that impact the University’s information security risk posture.
• Keep precise risk records, artifacts, and supporting documentation within the University’s Governance, Risk, and Compliance (GRC) platform.
• Collaborate and document risk mitigation efforts with stakeholders in information security, privacy, compliance, audit, and business sectors.
• Monitor and report on remediation activities in accordance with regulatory demands, risk management frameworks, institutional policies, and organizational goals.
• Evaluate and track security risks, generating risk metrics and reports.
• Assist in the development, execution, and ongoing enhancement of information security risk management and compliance policies, standards, procedures, and operational models.
• Promote risk awareness and educational initiatives by identifying human and organizational risk factors and encouraging risk-informed behaviors.
• Keep abreast of changes in cybersecurity threats, regulatory obligations, and industry best practices.
• Report directly to the Senior Manager of Information Security Risk and Compliance.
• Undertake additional responsibilities as required.
• A minimum of 3 years of experience in a relevant field.
• Bachelor’s degree required.
• Proven experience supporting information security risk management activities within a large organization.
• Familiarity with the NIST Risk Management Framework (RMF) and other prevalent information security risk management methodologies and frameworks.
• Understanding of higher education industry standards and regulations, such as GLBA and FERPA.
• Experience in conducting or assisting with risk assessments, monitoring remediation efforts, and maintaining risk documentation.
• Skilled in analyzing cybersecurity risks, preparing risk-related documentation, and effectively communicating with both technical and non-technical audiences.
• Knowledge of information security governance, policies, standards, and industry best practices.
• Must reside in and work from one of the designated states: Alabama, Arizona, Arkansas, Delaware, Florida, Georgia, Hawaii, Idaho, Indiana, Iowa, Kansas, Kentucky, Louisiana, Maine, Maryland, Massachusetts, Michigan, Mississippi, Missouri, Nebraska, New Hampshire, New Mexico, North Carolina, North Dakota, Ohio, Oklahoma, South Carolina, South Dakota, Tennessee, Texas, Utah, Vermont, Virginia, West Virginia, Wisconsin, or Wyoming.
• Comprehensive, low-deductible medical insurance.
• Affordable or no-cost dental and vision coverage.
• Five weeks of paid time off, in addition to nearly a dozen paid holidays.
• Employer-funded retirement plan.
• Tuition-free program for employees.
• Parental leave benefits.
• Resources for mental health and well-being.
• Reliable internet connection and a dedicated, well-equipped workspace are required for remote work.
Zurich Insurance
Amgen
Rackner
Get handpicked remote jobs straight to your inbox weekly.