
Security Risk Analyst II
Posted 1 day ago

Posted 1 day ago
This is a fully remote position, open to applicants in California, +14 more states.
• Design, implement, and oversee IT controls for core applications and systems.
• Analyze IT data to evaluate risk and enhance processes and efficiency.
• Conduct risk assessments of information technology systems and internal procedures.
• Suggest controls to safeguard the confidentiality, integrity, and availability of sensitive information.
• Evaluate cybersecurity risks against HIPAA, NIST, ISO-27001, and other prevalent control frameworks and regulations.
• Utilize qualitative and quantitative analysis techniques to assess risk and deliver results to stakeholders.
• Develop, monitor, and assess controls for their effectiveness and efficiency.
• Prepare comprehensive risk reports, recommended controls, standard procedures, and protocols.
• Review and generate scheduled audit reports based on internal and external requests.
• Design application- and system-level controls following auditing and security best practices.
• Collaborate with business owners to pinpoint key controls and coordinate measurement efforts.
• Conduct optimization reviews and prepare reports related to scheduled audits.
• Assist in designing IT environments to meet ISO 27001, HIPAA, Sarbanes-Oxley, PCI-DSS, and state regulations.
• Act as the primary liaison between auditing bodies, IT security management, compliance, and business stakeholders.
• Support departmental strategy concerning information systems and technology architecture.
• Fulfill other assigned responsibilities while adhering to policies and standards.
• Bachelor's degree in IT, MIS, Accounting, Finance, Business Administration, or a related field, or equivalent experience.
• 3+ years of combined experience in auditing and the design of IT controls.
• Strong knowledge of IT systems and processes.
• Experience in evaluating internal technical control systems.
• Preferred certifications include CISSP, CRISC, CISA, CISM, FAIR, CPA, or CIA.
• Must be authorized to work in the U.S. without the need for employment-based visa sponsorship now or in the future.
• Employment-based visa sponsorship is not available, including H-1B, L-1, O-1, H-1B1, F-1, J-1, OPT, and CPT.
• Health insurance.
• 401K plan.
• Stock purchase plan.
• Tuition reimbursement.
• Paid time off plus holidays.
• Flexible work arrangements, including remote, hybrid, field, or office schedules.
• Additional incentives may be included in the total compensation package.
Zurich Insurance
Amgen
Rackner
Get handpicked remote jobs straight to your inbox weekly.