
Senior Technology Risk Analyst
Posted 22 hours ago

Posted 22 hours ago
This is a fully remote position, open to applicants in Michigan.
• Develop, maintain, evaluate, and report on threats, risks, and controls related to information technology and information security.
• Identify and document any potential vulnerabilities.
• Test and verify compliance with established controls.
• Propose and confirm strategies for risk mitigation.
• Conduct comprehensive cyber and technology risk assessments across the enterprise.
• Generate formal risk assessment reports and present them to senior leadership.
• Oversee and evaluate technology and security initiatives, encompassing policies, standards, controls, procedures, and testing obligations.
• Design, validate, monitor, and report on risk mitigation strategies in accordance with the organization's risk appetite.
• Communicate findings to stakeholders, including executive leadership.
• Map out threats and controls, identify vulnerabilities, and assess inherent and residual risk ratings in line with the enterprise Risk Governance Framework.
• Deliver formal risk assessment reports to executive leadership.
• Aid business-line and technology stakeholders in comprehending risk and control requirements.
• Support junior associates with intricate technical concepts and best practices.
• Undertake special projects and additional responsibilities as necessary.
• Analyze and resolve issues effectively.
• Utilize independent judgment and discretion in decision-making.
• High School diploma / High School Equivalency (GED, HiSET, TASC) / Foreign Equivalent.
• 4+ years of experience in Technology Audit, Information Technology, or Information Security.
• Security+, CISA, CRISC, CISSP, or equivalent certifications.
• Strong grasp of internal/external processes and deadlines.
• Expertise in technology and security risk mitigation strategies.
• Proficient in risk assessment and control development.
• Experience in designing risk and control programs that align with FFIEC, NIST 800-53, NIST 800-37, and financial services regulatory standards.
• Familiarity with technology organizational business processes and systems.
• Experience in creating and maintaining threat and risk registers, and articulating residual risk to non-technical audiences.
• Skilled in creating and sustaining KPIs and KRIs.
• Previous experience in implementing or overseeing cross-functional, enterprise-wide projects and technologies.
• Well-rounded knowledge of technology, operations, and essential business processes.
• Travel requirement is less than 10%.
• No unusual physical exertion is necessary.
• Consistent compliance with regulatory and compliance policies, standards, and relevant laws and regulations.
• Medical insurance.
• Dental insurance.
• Vision insurance.
• Life insurance.
• Disability insurance.
• Comprehensive leave program.
• Variable incentives, bonuses, commissions, or other awards may be included in total compensation.
• Reasonable accommodation support during the employment application process.
Keyrus
Riveron
Blue Cross NC
Sage Bionetworks
Get handpicked remote jobs straight to your inbox weekly.