Dice logo
Dice
Posted 5 days agoVerified live 1d ago

Risk Analyst

Brief overview

Remote
UndergradOr in progress
3+ yrsMinimum
Risk ManagementRisk AssessmentRisk RemediationRegulatory ComplianceInformation SecurityControl TestingAzure DevOpsSarbanes-Oxley (SOX)FFIECISO/IEC 27001NIST Risk Management Framework (RMF)Project Management

About the company

Dice is the go-to career marketplace for tech professionals.

Job description

Summary

Everforth Apex is an IT services company that supports clients across the globe. The Risk Analyst will support Information Technology and Cyber Security organizations with audit, compliance, risk remediation, and delivery of remediation initiatives. The role will coordinate with technical, security, business, risk, and internal audit teams to resolve risk issues and report progress to management.

Responsibilities

  • Lead and manage risk remediation projects from initiation through completion
  • Collaborate with business units, IT, Risk, and Internal Audit teams to drive risk evaluation and remediation processes
  • Build partnerships with key technology partners and IT areas
  • Evaluate and understand findings to help ensure proper planning of priorities and resources
  • Analyze risk findings, prioritize remediation efforts, and track progress against established metrics
  • Facilitate communication across teams to meet project requirements and deliverables
  • Work with subject matter experts to create and maintain remediation strategies, tasks, and documentation
  • Ensure alignment of remediation activities with organizational policies and regulatory requirements
  • Identify process improvements to enhance risk management and remediation effectiveness
  • Support audits, assessments, and regulatory reviews by providing evidence of remediation activities
  • Maintain knowledge of relevant regulations, frameworks, and emerging risks
  • Prepare and deliver status reports and presentations to management

Skills

  • Bachelor's degree in Risk Management, Business Administration, Information Security, or a related field
  • 3+ years in risk management, remediation, or related fields
  • Ability to analyze complex risk issues, synthesize data, and develop actionable remediation strategies
  • Proven track record of managing multiple projects and meeting deadlines
  • Verbal and written communication skills with the ability to present complex information to technical and non-technical audiences
  • Demonstrated ability to work effectively in cross-functional teams and build working relationships
  • Familiarity with risk assessment tools, GRC platforms, and IT security concepts
  • Understanding of key regulations and industry standards (e.g., SOX, GDPR, FFIEC, ISO 27001, NIST CSF, NIST RMF)
  • Preferably within a large organization or consulting environment
  • Experience using Azure DevOps or similar agile toolsets
  • Experience with technical writing
  • Experience with risk remediation in financial services, healthcare, or highly regulated industries
  • Knowledge of control testing and associated tests
  • Knowledge in Information Technology, Cybersecurity, Infrastructure, Cloud, Architecture, and Application Delivery
  • Professional certifications in risk management or cybersecurity (e.g., CISSP, CISM, CISA, CySA+, Security+, CRISC)

Qualifications

Must Haves

  • Bachelor's degree in Risk Management, Business Administration, Information Security, or a related field
  • 3+ years in risk management, remediation, or related fields
  • Ability to analyze complex risk issues, synthesize data, and develop actionable remediation strategies
  • Proven track record of managing multiple projects and meeting deadlines
  • Verbal and written communication skills with the ability to present complex information to technical and non-technical audiences
  • Demonstrated ability to work effectively in cross-functional teams and build working relationships
  • Familiarity with risk assessment tools, GRC platforms, and IT security concepts
  • Understanding of key regulations and industry standards (e.g., SOX, GDPR, FFIEC, ISO 27001, NIST CSF, NIST RMF)

Nice to Haves

  • preferably within a large organization or consulting environment
  • Experience using Azure DevOps or similar agile toolsets
  • Experience with technical writing
  • Experience with risk remediation in financial services, healthcare, or highly regulated industries
  • Knowledge of control testing and associated tests
  • Knowledge in Information Technology, Cybersecurity, Infrastructure, Cloud, Architecture, and Application Delivery
  • Professional certifications in risk management or cybersecurity (e.g., CISSP, CISM, CISA, CySA+, Security+, CRISC)

Benefits

  • Remote work, with residence within an hour of Columbus, Dallas, Charlotte, Atlanta, Akron, Chicago, Minneapolis, or Detroit
  • Medical, dental, vision, life, disability, and other insurance plans
  • Employee stock purchase program (ESPP)
  • 401(k) program, typically available for contributions within 30 days of starting, with a company match after 12 months of tenure
  • Health Savings Account (HSA) on the HDHP plan
  • SupportLinc Employee Assistance Program (EAP) with up to 8 free counseling sessions
  • Corporate discount savings program and other discounts
  • On-demand training program
  • Access to certification preparation and a library of technical and leadership courses, books, and seminars after 6+ months of tenure
  • Certification discounts and other perks for associations including CompTIA and IIBA
  • Dedicated customer service team for consultants to address questions about benefits and other resources
  • Certified Career Coach

More jobs like this