Security Risk Analyst

2 weeks ago


St Paul, United States The College Board Full time

Risk Analyst College Board - Risk Management Location This is a fully remote role. Candidates who live near CB offices have the option of being fully remote or hybrid (Tuesday and Wednesday in office). Type: This is a full-time position About the Team The Information Security Governance Risk and Compliance (ISGRC) team at the College Board checks and certifies the College Board's Information Security Programs. Our mission is to provide our stakeholders with meaningful insights that continuously improve the risk posture across the organization. ISGRC partners work with business leads to perform necessary security reviews of policies, systems, contracts, and vendors to better understand and manage risk. The team also manages security policies, security awareness training, and industry-recognized certifications (ISO 27001, SOC2 and PCI-DSS). About the Opportunity As a Security Risk Analyst, you will have the critical role of being responsible for evaluating and managing exceptions to IT security policies, for managing the Organization's Risk and Control Issues Register (Risk Register), and for developing reports and metrics. Your strong technical communication and negotiation skills will help you build relationships and collaborate with diverse stakeholders and reduce risk to the organization and ensure compliance. Under the direction of management, you will manage the Risk Register and perform security policy exceptions to help the College Board understand its critical risks. In this role you will: Manage the Risk Register (20%) * Leads the management of the issues and risks and quickly escalates any untimely completion of audit actions. * Works independently to communicate risks and works with others to problem-solve risks to tolerance levels based on data and evidence. * Maintains data quality of Risk Register and executes any required data clean-up exercises. * Understands College Board work to be able to drive Risk or Control Owners to ensure consistent application of policies and standards. * Raises awareness about Risk & Control Issues, Policy exceptions, and available risk reduction options. * Fosters a culture of risk awareness and compliance within the technology department and across the organization. Manage Policy Exceptions (65%) * Independently analyzes policy exception submissions and provide risk assessment reports for critical service lines, applications, and infrastructure hosted on-prem and in the cloud. * Evaluates and manage exceptions to IT security policies. * Manages materials for the Exception Review Board and present exception information to executive leadership and senior team members. * Maintains an up-to-date knowledge and understanding of IT security policies and principles. * Maintains a customer-focused attitude in all interactions with customers and colleagues. Manage Metrics and Reporting (15%) * Provides weekly and monthly reporting for the Risk Register and policy exceptions. * Produces trending metrics and escalate exceptions. * Performs other duties as assigned. About You * 5-7 years of experience managing or supporting IT Security Risk and Control Risk Register and processing policy exceptions. * Strong understanding of risk management techniques such as: risk identification, risk scoring, risk mitigation, and risk tracking. * The proven ability to lead conversations balancing risk and multiple business needs that result in positive outcomes with multiple stakeholders. * The capacity to assess risk information and make risk recommendations independently. * Strong organization and prioritization skills and the proven ability to manage multiple tasks simultaneously, both independently and as a member of the team. * 7-10 years of experience in information security; governance, risk, and compliance; and/or information technology projects. * Excellent verbal and written communication skills. * Experience with governance, risk, and compliance tools (e.g., RSAM, RSA Archer) preferred. * Experience with information security and privacy frameworks such as ISO 27001, COBIT, NIST-CSF, NIST 800-53, GDPR etc. * Current Information Security Certification (e.g., CISSP, CRISC, CISM, CISA, or related security certification) preferred or the ability to attain one within 6 months of hire. * Bachelor's degree in computer science, cybersecurity, engineering, IT management or four years equivalent IT and security industry experience. * For remote positions, ability to travel 4 times a year to our Reston, VA office. * Authorization to work for any employer in the USA About Our Process * Application review will begin immediately and will continue until the position is filled * While the hiring process may vary, it generally includes: resume and application submission, recruiter phone screen, hiring manager interview, performance exercise and/or panel interview, and reference checks. This is an approximately 8-week process About Our Benefits and Compensation College Board offers a competitive benefits and compensation program that attracts top talent looking to make a difference in education. As a self-sustaining non-profit, we believe in compensating employees equitably in relation to each other, their qualifications, their impact, and the relevant market. The hiring range for a new employee in this position is $72000 to $120000. College Board differentiates salaries by location so where you live will narrow the portion of this range in which you can expect a salary. Your salary will be carefully determined based on your location, relevant experience, the external labor market, and the pay of College Board employees in similar roles. College Board strives to provide our best offer up front based on this criteria. Your salary is only one part of all that College Board offers, including but not limited to: A comprehensive package designed to support the well-being of employees and their families and promote education. Our robust benefits package includes health, dental, and vision insurance, generous paid time off, paid parental leave, fertility benefits, pet insurance, tuition assistance, retirement benefits, and more Recognition of exceptional performance through annual bonuses, salary growth over time through market increases, and opportunities for merit raises and promotions based on increased scope of responsibility A job that matters, a team that cares, and a place to learn, innovate and thrive You can expect to have transparent conversations about benefits and compensation with our recruiters throughout your application process. #LI-Remote #LI-MD1


  • Risk Analyst

    5 days ago


    St Paul, United States Collabera Full time

    Job Title: Risk Analyst Location: Minneapolis, MN 55420 Duration: Contract (6 months contract with possible extensions) Desription: Risk/Reconciliation Management Experience Accounting/Finance experience Knowledge working/analyzing Scripts Comparing test scripts with set of Interface data files 2-3 years experience AutoSys Batch System ALM Testing (Existing...

  • Sr. Analyst

    4 weeks ago


    St Paul, United States Aramco Services Company Full time

    Sr. Analyst - Market Risk (1096) Aramco Trading Americas Houston, TX - Full Time OVERVIEW The Senior Risk Analyst role is a key control position within the Market Risk Group, which resides in the Middle Office. This role is responsible for independent risk and financial controls and is accountable for ensuring that trading activities are conducted within a...


  • St Paul, United States Blue Star Partners, LLC Full time

    Job Description Job Description Job Title: Senior Cybersecurity Analyst Location: St. Paul, MN – Onsite – Local candidates only Period: 05/13/2024 to 12/20/2024 – possibility of extension Hours/Week: 40 hours Rate: $40-$45/hour (Hours over 40 will be paid at Time and a Half) Contract Type: W-2 Scope of Services: The Senior Cybersecurity Analyst...


  • St Louis, United States Stifel Full time

    Summary Under general supervision, the IT Security Governance Analyst II is a front-line member of the IT Security Program team responsible for the overall management of the IT Security Program. The IT Security Governance Analyst is responsible for supporting internal, external, and client audits, managing security risks within a GRC solution, and assessing...


  • St Louis, United States Audit & Risk Recruitment Full time

    Audit & Risk Recruitment are currently working with a multinational company based in St. Louis to recruit a Senior Internal Controls Analyst. This is an exciting opportunity to an established Internal Controls function within a dynamic company, which promotes growth and development. The successful candidate will report to the Internal Controls Manager, and...


  • St Louis, United States KP Recruiting Group Full time

    Job DescriptionKP Recruiting Group is a consulting firm that provides leadership and exceptional talent to some of the world's leading companies. Headquartered in the Midwest, KP Recruiting Group has successfully completed countless engagements across the United States. We represent clients in all industries and all sizes. Our mission is to provide...


  • St. Louis, United States McCarthy Building Full time

    Position Summary:  McCarthy is seeking a developmentally minded, client focused individual to join its Risk Management team. The Risk Analyst is responsible for managing compliance of subcontractor, designer, consultant and supplier certificates of insurance. This position is highly visible and will be exposed to various aspects of Risk Management, Legal,...


  • St Paul, United States Midwest Reliability Organization Full time

    The Senior Risk Assessment and Mitigation (RAM) Engineer, Operations and Planning (OP)* is an expert on the application of OP Reliability Standards and the associated risk with non-compliance. This position shares electrical engineering technical expertise to internal and external teams to promote the reliable operations of the bulk power system (BPS). At...


  • St Paul, United States Midwest Reliability Organization Full time

    Senior Risk Assessment and Mitigation Engineer/Specialist, Operations and Planning Reports To Manager of Risk Assessment and Mitigation, Operations and Planning Location St. Paul, MN Post Date 03/22/2024 To apply for this position, please send your resume and cover letter in an email to [emailprotected] . Position Summary The Senior Risk Assessment and...


  • St Paul, United States MedNet Global Healthcare Solutions LLC Full time

    MedNet Egypt is one of the leading managed care service organizations that caters to healthcare needs and offers financial protection against unforeseen health risks. As a Cyber Security Specialist, you are the front line of defense for the safety and integrity of the company’s digital information. Working closely with management, you will be responsible...

  • Business Analyst

    4 days ago


    St Paul, United States Garda Capital Partners Full time

    Garda is looking to hire a Business Analyst in its Research and Technology (R&T) group in our Wayzata office to enhance and support our trading and risk system (Orchestrade). Orchestrade is a mission critical system used across Garda, and the role can expect to interface with multiple functions within the firm including front office, risk, middle and back...


  • St Paul, United States LHH Full time

    The Senior Financial Analyst role will work closely with executive management of a 1B private equity owned business location in the Twin Cities Metro. This person will develop financial models to help support company growth and access profitability. This company is fast-paced with a growth focus. Responsibilities Create complex financial models to access...


  • St Paul, United States Marriott Full time

    Additional Information Three positions for this requisitions--all contractor conversion candidates Job Number 24058361 Job Category Information Technology Location Marriott International HQ, 7750 Wisconsin Avenue, Bethesda, Maryland, United States Schedule Full-Time Located Remotely? Y Relocation? N Position Type Management JOB SUMMARY The Senior Manager...


  • St Paul, United States LHH Full time

    The Senior Financial Analyst role will work closely with executive management of a 1B private equity owned business location in the Twin Cities Metro. This person will develop financial models to help support company growth and access profitability. This company is fast-paced with a growth focus. Responsibilities Create complex financial models to access...


  • St Paul, United States LHH Full time

    The Senior Financial Analyst role will work closely with executive management of a 1B private equity owned business location in the Twin Cities Metro. This person will develop financial models to help support company growth and access profitability. This company is fast-paced with a growth focus. ResponsibilitiesCreate complex financial models to access...


  • St Paul, United States LHH Full time

    The Senior Financial Analyst role will work closely with executive management of a 1B private equity owned business location in the Twin Cities Metro. This person will develop financial models to help support company growth and access profitability. This company is fast-paced with a growth focus. ResponsibilitiesCreate complex financial models to access...


  • St Paul, United States Dice Full time

    Dice is the leading career destination for tech experts at every stage of their careers. Our client, Computershare, is seeking the following. Apply via Dice today! Location: St. Paul, Minnesota (Hybrid) This is a hybrid position primarily based in St. Paul. We're committed to your flexibility and wellbeing and our hybrid strategy currently requires two days...

  • IT Specialist II

    3 weeks ago


    St Louis, United States CareerBuilder Full time

    Job Description Information Technology Under general direction, develop and enforce enterprise information security policies and standards across The District, IT and OT. Work involves coordinating and/or planning, implementing, and monitoring security measures for the protection of the district's information assets from unauthorized use, modification, or...


  • St Paul, United States Serigor Inc Full time

    Job Title: Quality Assurance Analyst (Hybrid) Location: St. Paul, MN Duration: 2 Years Job Description: The client is seeking a Quality Assurance Analyst to work in the client At a high level, the resource will work on multiple initiatives including the Predatory Offender Registry (POR), My BCA (a secure criminal justice portal), and other products as...


  • St Paul, United States Serigor Inc Full time

    Job Title: Quality Assurance Analyst (Hybrid)Location: St. Paul, MNDuration: 2 YearsJob Description:The client is seeking a Quality Assurance Analyst to work in the client At a high level, the resource will work on multiple initiatives including the Predatory Offender Registry (POR), My BCA (a secure criminal justice portal), and other products as needed....