Senior Security Risk Analyst

1 month ago


New York, New York, United States Justworks Full time
Who We Are

At Justworks, you'll enjoy a welcoming and casual environment, great benefits, wellness program offerings, company retreats, and the ability to interact with and learn from leaders in the startup community. We work hard and care about our most prized asset - our people.

We're helping businesses get off the ground by enabling them to focus on running their business. We solve HR issues. We're data-driven and never stop iterating. If you'd like to work in a supportive, entrepreneurial environment, are interested in building something meaningful and having fun while doing it, we'd love to hear from you.

We're united by shared goals and shared motivations at Justworks. These are best summed up in our company values, which are reflected in our product and in our team.

Our Values

If this sounds like you, you'll fit right in.


Who You Are

Justworks is seeking an exceptional Senior Security Risk Analyst to join our Governance Risk & Compliance (GRC) team. The Senior Security Risk Analyst will work cross-functionally with all areas of the company to develop security safeguards and countermeasures. As a Senior Security Risk Analyst, you will report to the Senior Manager, Governance Risk & Compliance and liaise with other teams across Digital Security, providing guidance and solutions to protect Justworks' products, customers, and employees.

Your Success ProfileWhat You Will Work On

  • Contribute to building GRC strategy and multi-year roadmaps to mature Justwork's GRC function, defining Justworks' risk management framework, and developing Justworks' compliance programs, policies, and standards.
  • Be part of the development of GRC's capabilities such as cyber risk management, third-party risk management, security training and communications, and our compliance program.
  • Play a key role in the Third-Party Risk Management program. Conduct vendor risk assessment independently. Partner with stakeholders to ensure adequate controls are available and enabled in production. Continuously monitor vendor risk profiles. Work with the team to enhance Third-Party Governance and improve the TPRM process.
  • Support TPRM lead on the effort to obtain the comprehensive vendor inventory. This includes the development of a catalog of software components, including endpoints, APIs, and open-source libraries by collaborating with Security Architects, Product, and Engineering.
  • Work with the team to apply the risk management framework to day-to-day work. Conduct security assessments to enable the global Justworks to identify, assess, treat, and monitor cybersecurity risks. Maintain risk registry, track and monitor risk mitigation. Collaborate with all stakeholders across the company to provide risk visibilities, and drive the mitigation of cyber risks.
  • Assist in the selection and implementation of GRC solutions. Be the expert on all GRC tools.
  • Monitor and analyze changes in relevant regulations and industry standards such as CCPA, and GDPR, adapting company policies and procedures as needed.
  • Partner with Engineering, IT, People, and Finance on control requirements and evidence production proactively in anticipation of SOC2/SOX and customer audits.
  • Support GRC's training, communication and other activities to support a security-aware Justworks culture.
  • Build a risk-aware culture by maturing existing risk management processes to monitor, track, measure and report cyber risks.
  • Drive timely & effective communication via collaboration with various stakeholders including IT, Cyber Defense Operations, Security Architecture & Engineering, People Operations, Customer Service and Marketing.
  • Provide mentorship and day-to-day support to GRC analysts to enable the team to deliver best work and develop their professional skills.
  • Perform other related duties as assigned.

How You Will Do Your Work

As a Senior Security Risk Analyst, how results are achieved is paramount for your success and ultimately result in our success as an organization. In this role, your foundational knowledge, skills, abilities and personal attributes are anchored in the following:

  • Good judgment - the exercise of critical thinking, analyzing and assessing problems and implications, identifying patterns, making connections of underlying issues, understanding risks and developing mitigation strategies, and taking ownership of the outcome.
  • Resourcefulness - taking a can-do approach, even in the face of obstacles and constraints by assessing what's in front of you and effectively and efficiently optimizing what you have, whether it's working on something new or thinking about how to do something better.
  • Teamwork and communication - putting our collective best together through documentation, collaboration, relationship-building, listening, empathy, recruiting, and evangelism.
  • Influence and leadership - fostering a community of knowledge-sharing, collaboration, mentorship, and forward-thinking.
  • Skills and knowledge - the capacity to actively learn and apply specific domain knowledge, know-how, and best practices to continually enhance and improve.

In addition, all Justworkers focus on aligning their behaviors to our core values known as COGIS. It stands for:

  • Camaraderie - Day to day you can be seen working together toward a higher purpose. You like to have fun. You're an active listener, treat people respectfully, and have a strong desire to know and help others.
  • Openness - Your default is to be open. You're willing to share information, understand other perspectives, and consider new possibilities. You're curious, ask open questions, and are receptive to thoughts and feedback from others.
  • Grit - You demonstrate grit by having the courage to commit and persevere. You're committed, earnest, and dive in to get the job done well with a positive attitude.
  • Integrity - Simply put, do what you say and say what you'll do. You're honest and forthright, have a strong moral compass, and strive to match your words with your actions while leading by example.
  • Simplicity - Be like Einstein: "Everything should be made as simple as possible, but no simpler."

Qualifications

  • 5+ years' experience directly in cybersecurity fields, with a demonstrated track record of leading third-party risk management, plus one of the following areas: cyber risk management, policy & compliance, security awareness, and communication
  • Well-versed in risk assessment methodology, NIST 800-53, CIS, and associated security and privacy rules
  • Strong analytical skills and using data/facts for decision-making
  • Solid experience in either software development or infrastructure other than risk management experience
  • Ability to develop scripts/queries to pull data from different tools
  • Strong knowledge and experience with operational risk management, covering the full lifecycle of activities, including risk identification, assessment, mitigation, monitoring, and reporting
  • Functional knowledge of security domains and information security industry standard and best practices
  • Ability to identify and recommend tools, processes, and software to automate and continuously improve security and compliance practices.
  • Previous experience with GRC solutions - Archer, ServiceNow, LogicGate etc
  • Technical understanding of cloud-based security in an AWS environment
  • Proven track record as a strong communicator both in written and oral presentations; capable of rapidly creating detailed, yet concise documentation
  • Exceptional organizational skills with the ability to prioritize and manage multiple projects at the same time.
  • A self-motivated person who can influence and drive cross-functional teams, promoting timely and effective communication
  • Good organizational skills, proactive and self-sufficient with a proven ability to work independently and prioritize deliverables
  • Security Certifications of CISSP, CISM, CRISC, CISA a plus

The base wage range for this position based in our New York City Office is targeted at $167,500.00 to $184,250.00 per year.

#LI-AD1 #LI-Hybrid #LI-JS1


Actual compensation is based on multiple factors that are unique to each candidate, including and not limited to skill set, level of relevant experience, and specific work location. Salary ranges for positions based in other locations may differ based on the cost of labor in that location.

For more information about Justworks' Total Reward Philosophy, including all of the perks and benefits we are proud to offer our team members, please visit Total Rewards @ Justworks.

Diversity At Justworks

Justworks is committed to maintaining a workplace where diversity of identity, culture, and life experience is the norm and is celebrated authentically and respected consistently. Diversity in our work, our people, and our product drives creativity and innovation, entrepreneurial leadership and integrity, competitiveness, and collaboration throughout our business and in the market. We depend on our differences to make our team stronger, our workplace more dynamic, and our product accessible to all of our customers.

We're proud to be an equal opportunity employer open to all qualified applicants regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, citizenship, marital or familial status, disability, pregnancy, gender identity or expression, veteran status, genetic information, or any other legally protected status. Justworks is fully dedicated to providing necessary support to candidates with disabilities who may require reasonable accommodations. We also provide reasonable accommodations to employees based on their sincerely held religious beliefs, as well as for other covered reasons consistent with applicable federal, state, and local laws. If you're in need of a reasonable accommodation, please reach out to us at Your comfort and success matter to us, and we're here to ensure an inclusive experience.

Our DEIB Report and Our DEI Commitment



  • New York, New York, United States Insight Global Full time

    Position Overview:Insight Global is in search of a Senior Analyst specializing in Enterprise Risk Management for a notable not-for-profit financial institution.Work Environment:This opportunity offers a direct hire position with a flexible hybrid remote work arrangement.Key Responsibilities:As the Senior Analyst, you will engage with various stakeholders...


  • New York, New York, United States Insight Global Full time

    Position Overview:Insight Global is looking for a Senior Analyst specializing in Enterprise Risk Management for a prominent not-for-profit financial organization.Work Environment:This position offers a direct hire opportunity with the flexibility of a hybrid remote work arrangement.Key Responsibilities:As the Senior Analyst in Enterprise Risk, your primary...


  • New York, New York, United States Visa Full time

    Job OverviewCompany Overview:Visa stands as a global frontrunner in payment solutions and technology, facilitating over 259 billion transactions annually across more than 200 nations. Our mission is to connect the world through innovative, secure, and reliable payment networks, empowering individuals, businesses, and economies to prosper.Position Summary:The...


  • New York, New York, United States Considine Search Full time

    OverviewThe Senior Risk and Compliance Analyst will be responsible for safeguarding the integrity, confidentiality, and availability of the organization's information through comprehensive risk evaluations, audits, control assessments, policy formulation, and compliance efforts. The ideal candidate will engage in various governance, risk, and compliance...


  • New York, New York, United States Considine Search Full time

    OverviewThe Senior Risk and Compliance Analyst at Considine Search is responsible for safeguarding the integrity, confidentiality, and availability of the organization's information through comprehensive risk evaluations, audits, control assessments, policy formulation, and compliance initiatives. The ideal candidate will engage in various governance, risk,...


  • New York, New York, United States Insight Global Full time

    Position Overview:Insight Global is looking for a Senior Analyst specializing in Enterprise Risk Management for a prominent not-for-profit financial organization. Role Responsibilities:In this capacity, you will engage with various stakeholders across the organization to oversee vendor partnerships, facilitate and execute risk evaluations, including...


  • New York, New York, United States Insight Global Full time

    Position Overview:Insight Global is in search of a Senior Analyst specializing in Enterprise Risk Management for a prominent not-for-profit financial institution. Role Responsibilities:In this pivotal role, you will engage with key stakeholders across various levels to oversee vendor partnerships, facilitate and execute risk evaluations, which encompass...


  • New York, New York, United States Berrysoft Consulting Full time

    NYS Department of Financial Services- 30 Months - One State Street Plaza, Second Floor, New York, NY % remoteShort description:The Security Analyst will directly support the New York State Department of Financial Services (DFS) Information Security Program, responsible for ensuring the confidentiality, integrity, and availability of information and...

  • Senior Risk Analyst

    6 days ago


    New York, New York, United States AXA XL Ltd Full time

    Senior Risk Analyst - Builders Insurance At AXA XL, we specialize in providing expert solutions to navigate risk management challenges for large-scale contractors. Our Builders Risk division delivers tailored Project Specific, Master Builders Risk, and Contractors Block policies to clients with diverse global exposures. In this role, you will leverage your...


  • New York, New York, United States Natixis Corporate & Investment Banking Full time

    Position OverviewThe primary role of the Senior Credit Risk Analyst is to evaluate and analyze various proposals from the Global Structured Credit and Solutions (GSCS) division, focusing on credit risk implications. These proposals may encompass CLO warehouse/lending facilities, capital call facilities, and ABS warehouse/lending facilities, among others....


  • New York, New York, United States Goldman Sachs Full time

    VICE PRESIDENT: MARKET RISK ANALYSTWe are looking for a skilled professional to take on the role of Market Risk Manager with a focus on the Mortgages and Structured Products sector. The ideal candidate will possess a robust academic foundation in Finance, Mathematics, or a related field, along with 7-10 years of relevant experience in market risk...


  • New York, New York, United States Marsh McLennan Full time

    The Senior Specialist Technical Risk Assessment role's main purpose is to provide an in-depth analysis of the security risk affecting an information system being evaluated by MMC, as a component of MMC technology onboarding process. A technical risk assessment (TRA) function, as the main purpose of the Sr. technical risk analyst role, provides in-depth...


  • New York, New York, United States WSN Full time

    WSN is looking for a Senior Analyst in Business Risk and Control to engage in a long-term consulting assignment with a prominent investment banking client.The Senior Analyst in Business Risk and Control is a highly experienced professional role. This position requires the application of extensive disciplinary knowledge, contributing to the creation of...


  • New York, New York, United States WSN Full time

    WSN is looking for a Senior Analyst in Business Risk and Controls to engage in a long-term consulting position with a prominent investment banking client.The Senior Analyst in Business Risk and Controls is a highly experienced professional role. This position requires a deep understanding of disciplinary knowledge, contributing to the creation of innovative...


  • New York, New York, United States augmentjobs Full time

    Job OverviewPosition Summary: The Senior Financial Risk Analyst will play a crucial role in identifying and mitigating the financial risks encountered by the organization. This position requires the development of comprehensive risk management strategies, execution of thorough risk evaluations, and ensuring compliance with applicable regulations and internal...


  • New York, New York, United States AMEX Full time

    About the RoleWe are seeking a highly skilled Senior Risk Management Analyst to join our US Consumer Services Control Management Product/Service Risk Advisory team. As a key member of our team, you will play a critical role in ensuring control management is embedded in the day-to-day operations of our organization.Key ResponsibilitiesProvide strategic risk...


  • New York, New York, United States WSN Full time

    WSN is in search of a Senior Analyst of Business Risk and Controls to engage in a long-term consulting assignment with a prestigious investment banking client.The Senior Analyst of Business Risk and Controls is a highly experienced professional role. This position requires a comprehensive understanding of disciplinary knowledge, contributing to the...


  • New York, New York, United States WSN Full time

    WSN is looking for a Senior Analyst in Business Risk and Control to engage in a long-term consulting assignment with a prominent investment banking client.The Senior Analyst in Business Risk and Control is a highly experienced professional role. This position requires a deep understanding of disciplinary knowledge, contributing to the formulation of...

  • Senior Analyst

    5 days ago


    New York, New York, United States Collabera Full time

    Home Search Jobs Job Description Business Risk and Control Senior Analyst AVP Contract: Remote Work Salary: $56.00 Per Hour Job Code: End Date: Days Left: 28 days, 3 hours left Note: Extensive banking or Big 4 consulting experience is essential.Position Overview:The Business Risk and Control Senior Analyst is a highly experienced professional role. This...


  • New York, New York, United States WSN Full time

    WSN is in search of a Senior Analyst of Business Risk and Controls to engage in a long-term consulting opportunity with a prestigious investment banking client.The Senior Analyst of Business Risk and Controls is a highly experienced professional role. This position requires the application of extensive disciplinary knowledge, contributing to the creation of...