Sr IT Risk Security Analyst
S
SymetraFinancial Services
United StatesFull-TimeSenior
Salary$79,900 - $133,200 plus eligibility for annual bonus program
Apply NowOpens the employer's application page
Job Details
- Experience
- 5-8 years
- Required Skills
- ComplianceRisk Management
Requirements
- Bachelor’s degree in information systems, Cybersecurity, Computer Science, Accounting, Business, or related field, or equivalent combination of education and experience.
- 5-8 years of experience in IT risk management, information security, IT audit, cybersecurity governance, compliance, or related disciplines.
- Experience with SOX ITGCs, ISO 27001, IT risk assessment methodologies, vendor risk management, security governance, and audit lifecycle management.
- Professional certifications such as CISA, CISSP, CRISC, CISM, CIA, or ISO 27001 Lead Implementer/Auditor.
- Analytical problem-solving skills with experience managing complex risk assessments and audit programs.
- Effective communication skills to influence executives, auditors, IT leaders, and business stakeholders.
- Strong organizational skills and ability to manage multiple priorities and maintain accurate documentation.
- Ability to thrive working independently while serving as a subject matter expert for cross-functional teams.
- Must meet internet speed requirements: minimum 100 Mbps download and 20 Mbps upload via Fiber, Cable, or DSL.
Responsibilities
- Serve as a trusted advisor to IT and business teams by identifying technology, security, and operational risks, recommending effective controls, and ensuring risks are properly assessed, documented, and mitigated.
- Lead enterprise IT risk management activities, including annual risk assessments, risk committee facilitation, risk reporting, policy development, risk register management, and continuous improvement of the organization's risk management framework.
- Support third-party technology risk management across the vendor lifecycle, including risk tiering, pre-contract due diligence, security assessments, and periodic monitoring.
- Manage and enhance IT audit and compliance programs, including SOX IT General Controls (ITGCs), ISO 27001 security controls, regulatory requirements, and internal/external audit activities.
- Partner with control owners, auditors, and business stakeholders to track audit findings, drive remediation efforts, provide training, and ensure sustainable compliance.
- Develop executive-level reporting and dashboards that communicate risk exposure, audit results, compliance status, and remediation progress.
- Conduct reviews of information systems, business applications, infrastructure, and operational processes to assess security posture, control effectiveness, and alignment with company objectives.
View Full Description & ApplyYou'll be redirected to the employer's site