IT Risk Management Analyst

Insight Global
Atlanta, GA, United States
2 days ago

Role details

Contract type
Temporary to permanent
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Compensation
$120,000.0 - $150,000.0
Working hours
Regular working hours
Job source

Tech stack

Microsoft Excel Microsoft Windows Data Analysis Apple Mac Systems Confluence JIRA Cyber Security Information Systems Linux Excel Formulas Issue Tracking Systems Intrusion Detection Systems
+9 more
Knowledge Management Open Web Application Security Pivot Tables Software Vulnerability Management Computer Network Technologies Macros Mitre Att&ck Firewalls (Computer Science) SC Clearance

Job description

This position is located within the GRC Team and will serve as a subject-matter expert for IT risk in the organization, * Monitor the institution’s information systems for security incidents and vulnerabilities, responding promptly to mitigate potential threats.

  • Conduct regular risk assessments and security audits to identify weaknesses in the institution’s cybersecurity posture and recommend remediation measures.

  • Develop and implement security policies, procedures, and protocols to protect sensitive data and ensure compliance with regulatory requirements.

  • Provide cybersecurity training and awareness programs for faculty, staff, and students to promote a culture of security within the institution.

  • Analyze security incidents and breaches to determine their root causes and develop strategies to prevent future occurrences.

  • Stay informed about emerging cybersecurity threats and trends, continuously updating security measures to address new challenges.

  • Prepare and present reports on the status of cybersecurity efforts, highlighting incidents, vulnerabilities, and progress on remediation activities.

  • Serve as a liaison with external agencies and partners on cybersecurity initiatives, collaborating on strategies to enhance the institution’s security capabilities.

  • Collaborate with IT teams to deploy security technologies, such as firewalls, intrusion detection systems, and encryption tools, to safeguard institutional data.

Requirements

  • Bachelor’s degree in cybersecurity, information security, information assurance, or a related field, or an equivalent combination of education and experience.

  • 5+ years of progressively responsible experience in governance, risk, compliance, or information security in a complex environment.

  • Strong practical knowledge of security technologies and controls, as well as operating system platforms including Windows, macOS, Linux, and core networking technologies.

  • Demonstrated experience with vulnerability management processes and tools, including scanning, reporting, prioritization, and remediation tracking.

  • Solid understanding of threats, vulnerabilities, exploitation techniques, and how they map to business risk.

  • Advanced experience with data analysis and reporting in Excel (pivot tables, lookups, intermediate/advanced formulas; scripting or macros a plus).

  • Proven ability to assess and communicate the priority and business impact of vulnerabilities and risks to both technical and non-technical stakeholders.

  • Excellent written and verbal communication skills, including experience drafting policies, standards, and executive-level summaries.

  • One or more intermediate or advanced cybersecurity/GRC certifications such as CISSP, CISM, CISA, SecurityX, CCNP-Security, or equivalent. * Active Secret clearance.

  • Master’s degree in cybersecurity, information security, information assurance, business, or a related field.

  • Deep understanding of cybersecurity frameworks and best practices such as NIST 800-53/171, CMMC, RMF, MITRE ATT&CK, and OWASP Top 10.

  • Demonstrated experience leading audit, assessment, or certification efforts (e.g., NIST, CMMC, DFARS, FedRAMP, or similar).

  • Experience developing and tracking security and compliance metrics for remediation stakeholders and leadership.

  • Strong knowledge of common vulnerability categorizations and scoring systems such as CVE, CVSS, and CWE.

  • Proficiency with Atlassian Confluence for documentation and knowledge management.

  • Proficiency with Atlassian Jira for workflow, issue tracking, and project management.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.juju.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

5:30 min

Identifying non-coding software vulnerabilities and organizational risks

Tino Sokic · WWC 2023

3:05 min

Integrating an assistant application with Jira software

Felix Augenstein · LIVE

52 sec

Running persistent Linux environments directly on Windows

Ben Breard Ben Breard · WWC 2025

3:03 min

Exploring declarative and procedural macro subtypes in Rust environments

Mykhailo Maidan · LIVE

2:41 min

Visualizing organizational risks through a maturity model

Nazneen Rupawalla · WWC 2022

5:47 min

Integrating user stories and test automation via Jira tools

Christoph Ruggenthaler · LIVE

Videos

See all

Related articles

See all