
Senior Information Security Risk Analyst
Posted 23 hours ago

Posted 23 hours ago
This is a fully remote position, open to applicants in Tennessee.
• Act as a technical authority in the field of application security risk management.
• Oversee and lead the governance of the SAST/DAST application security scanning program.
• Evaluate security vulnerabilities and analyze findings from application and infrastructure scans.
• Collaborate with application teams, incident management units, and business stakeholders to prioritize and address risks.
• Optimize the utilization of the SAST/DAST platform and enhance vulnerability management practices.
• Enhance risk visibility and convert technical findings into actionable insights for business risks.
• Contribute to a prominent Data Governance initiative.
• Work alongside business leaders, data owners, security, privacy, compliance, and technology teams.
• Set governance standards, evaluate risks, monitor compliance, and reinforce data stewardship practices.
• Manage SOC 2 audit activities, which include collecting evidence, validating controls, and engaging with auditors.
• Maintain documentation for controls, mappings, and narratives.
• Supervise audit findings, remediation actions, and resolution of issues.
• Create and revise NIST System Security Plans (SSPs).
• Design and implement security awareness training programs, phishing simulations, and targeted campaigns.
• Handle the lifecycle of security policies, standards, and procedures.
• Conduct enterprise and third-party risk assessments, keep risk registers up to date, carry out vendor risk evaluations, and oversee remediation efforts.
• Monitor vulnerability remediation in accordance with SLAs.
• Address RFPs and security questionnaires.
• Support various initiatives across Governance, Risk, and Compliance (GRC) areas while promoting collaboration and shared accountability.
• A Bachelor’s degree in a relevant discipline or equivalent experience of four years is mandatory.
• At least 5 years of professional experience in Information Security or related IT roles that involve security responsibilities.
• A minimum of 2 years dedicated to Governance, Risk, and Compliance (GRC) functions.
• Preference for candidates with experience in utilizing AI-enabled tools to automate and improve GRC processes.
• Possession of one or more of the following certifications is preferred: CISSP, CRISC, CISA, or CISM.
• Capability to assess and document organizational risks, identify potential impacts, and suggest mitigation strategies.
• Proficiency in interpreting and applying regulatory requirements and industry frameworks such as NIST, SOC 2, and HIPAA.
• Skill in analyzing security, compliance, and risk metrics.
• Ability to convey complex risk and compliance concepts to both technical and non-technical audiences.
• Strong collaborative skills for working within cross-functional teams.
• Excellent time management capabilities.
• Superior oral and written communication skills.
• Strong interpersonal skills with an ability to build relationships.
• Ability to engage with all levels of staff and management.
• Must be available to work during Eastern Time business hours.
• Participation in an on-call rotation is required for two weeks every 22 weeks.
• Sponsorship for this position is not available.
• This is a remote, work-from-home position.
• Employee worker type.
• Opportunity to shape enterprise-wide decisions and contribute to a mature Data Governance program.
Mercury
Public Partnerships | PPL
M&T Bank
Alliant Insurance Services
Get handpicked remote jobs straight to your inbox weekly.