
Senior Enterprise Risk Analyst
Posted 14 hours ago

Posted 14 hours ago
This is a fully remote position, open to applicants in New York.
• Oversee and evaluate technology and security initiatives, including policies, standards, controls, procedures, and testing requirements.
• Develop, validate, monitor, and report on risk mitigation strategies that align with the company's risk appetite.
• Convey risk mitigation outcomes to stakeholders, including senior leadership.
• Conduct intricate enterprise-wide risk assessments by mapping threats and controls, pinpointing gaps, and assessing inherent and residual risk ratings.
• Produce formal risk assessment documents and deliver presentations to senior leadership.
• Aid business line and technology stakeholders in grasping risk and control obligations.
• Promote a comprehensive understanding and compliance with risk responsibilities across the enterprise.
• Support junior associates in comprehending complex technical concepts and best practices.
• Exercise independent judgment and discretion in decision-making.
• Evaluate and resolve issues effectively.
• Undertake special projects and additional responsibilities as necessary.
• Fulfill mandatory compliance training and adhere to regulatory and compliance standards.
• High School diploma or equivalent (GED, HiSET, TASC) or foreign equivalent.
• A minimum of 4+ years of experience in Technology Audit, Information Technology, or Information Security.
• Possession of Security+, CISA, CRISC, CISSP, or equivalent certification.
• Strong comprehension of internal and external processes and deadlines.
• Proficient in technology and security risk mitigation strategies.
• Specialized knowledge in Risk Assessment and Control development.
• Background in designing risk and control frameworks aligned with FFIEC, NIST 800-53, NIST 800-37, and financial services regulatory standards.
• Familiarity with business processes and systems within Technology organizations.
• Experience in creating and managing threat and risk registers and articulating residual risk to non-technical audiences.
• Expertise in developing and maintaining KPIs and KRIs.
• Previous involvement in implementing or overseeing cross-functional, enterprise-wide projects and technologies.
• Comprehensive understanding of technology, operations, and essential business processes.
• Travel requirement of less than 10%.
• Responsible for maintaining compliance with applicable federal, state, and local laws and regulations.
• Medical insurance
• Dental insurance
• Vision insurance
• Life insurance
• Disability insurance
• Comprehensive leave program
• Variable incentives, bonuses, commissions, or other awards may be included in total compensation
ICON plc
CBH
Sysco
International SOS
Get handpicked remote jobs straight to your inbox weekly.