Remotery

Senior Risk Analyst

Posted Jul 15

This is a fully remote position, open to applicants in India.

šŸ“‹ Description

• Develop and execute a comprehensive risk management program, incorporating risk taxonomy, scoring methodologies, risk appetite statements, and escalation thresholds.

• Create and sustain the enterprise risk register as a dynamic operational resource rather than a mere compliance document.

• Utilize AI technologies to oversee threat intelligence, detect patterns within risk data, expedite the drafting of risk narratives, and ensure the risk register is up to date between formal review periods.

• Assist the Third Party Risk Management (TPRM) function in collaboration with the designated TPRM lead.

• Identify and evaluate AI-related risks such as data privacy, model bias, explainability, security misuse, agentic system behavior, and dependencies on third-party AI.

• Generate concise, executive-level risk reports, dashboards, and regular risk summaries.

• Offer cross-departmental risk and control advice regarding process enhancements, the adoption of new technologies, post-implementation assessments, and remediation efforts.


ā›³ļø Requirements

• Over 6 years of experience in Governance, Risk Management, and Compliance (GRC), information security, risk management, or IT auditing, ideally within a SaaS or cloud-native context.

• In-depth knowledge of security and compliance frameworks such as SOC 2, ISO 27001, NIST CSF 2.0, and CIS Controls; familiarity with ISO 42001 and NIST AI RMF.

• AI-native mindset: proficient in utilizing AI tools—LLMs, agents, automation—for tangible tasks including analysis, drafting, evidence collection, and workflow automation, with discernment regarding when human oversight is necessary.

• Experience with GRC platforms for managing evidence and control testing (e.g., Drata, Vanta, AuditBoard, ServiceNow GRC, or similar).

• Knowledge of cloud environments (AWS, Azure, or GCP) and the security and compliance tools associated with them (CSPM, SIEM, identity management platforms).

• Experience in facilitating external audits in security or privacy areas, covering evidence collection, control walkthroughs, and interactions with auditors.

• Capability to interpret technical controls and convert findings into compliance, risk, and policy documentation that is comprehensible to both technical and non-technical stakeholders.

• Familiarity with risk registers, control libraries, and the lifecycle of policy governance.

• Understanding of privacy and data protection regulations (GDPR, CCPA/CPRA) and their relationship with security controls, in collaboration with Legal and Product teams.

• Excellent written communication, analytical abilities, and meticulous attention to detail; capable of producing clear audit responses, risk narratives, and control documentation within deadlines.

• At least 4 years of practical experience in information security risk management or a combined GRC/risk role responsible for establishing or significantly enhancing a risk register and scoring methodology.

• Proven ability to leverage AI or data tools to uncover risk insights, analyze trends, draft risk narratives, or automate risk register workflows—demonstrating sound judgment in validating AI outputs before they influence decisions.

• Established experience in advancing an organization's risk program from qualitative to quantitative risk measurement, including the implementation of scoring models, KRI frameworks, and data-driven risk reporting that influences leadership's risk decision-making.

• Knowledge of data warehousing principles, KRI development and tracking, and risk reporting pipelines that integrate live data sources with dashboards and executive reporting.

• Proficiency with GRC platforms for tracking risks, conducting control tests, and managing evidence (e.g., Drata, Vanta, AuditBoard, ServiceNow GRC, or equivalent).

• Strong analytical capabilities: comfortable with qualitative and quantitative risk scoring, heat maps, likelihood/impact matrices, and articulating risk appetite.

• Experience creating executive-level risk reports and translating technical findings into business impact language for non-technical audiences.

• Experience in supporting TPRM assessments and contributing to vendor risk documentation alongside a dedicated TPRM team.


šŸļø Benefits

• Health insurance

• 401(k) matching

• Flexible work hours

• Paid time off

• Remote work options

People also viewed

Advocate Aurora HealthJul 26

Lead Coder – Risk Management

US flagAlabama, +32 more statesFull-timeRisk$30 – $46/hour
ApplyView job
LeidosJul 26

Risk Assurance SME

US flagUnited States OnlyFull-timeRisk$87.1k – $157.4k/year
ApplyView job
Virtue HealthJul 25

Medical Risk Consultant, RN

US flagUnited States OnlyFull-timeRisk
ApplyView job
Kinetic AdvantageJul 25

Field Risk Director

US flagUnited States OnlyFull-timeRisk
ApplyView job
IKS HealthJul 25

Director, Risk Adjustment

US flagUnited States OnlyFull-timeRisk$130k – $150k/year
ApplyView job
CEX.IOJul 25

Risk Officer

BM flagBermuda OnlyFull-timeRisk
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers