IT Enterprise Risk Analyst

Insight Global
Tampa, FL, United States
9 days ago
Apply on dejobs.org
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
3 years minimum
Working hours
Regular working hours
Job source

Tech stack

Microsoft Windows Microsoft Azure Cloud Computing Control Objectives for Information and Related Technology (COBIT) Cyber Security Information Systems Document Management Systems Information Security Management Microsoft Office Aderant Information Technology Data Management
+1 more
CIS Benchmarks

Job description

We are seeking an IT Enterprise Risk Analyst to join our team. The IT Risk Analyst helps manage the Firm’s GRC and IT risk programs, focusing on information security for client data, attorney work, and privileged communications. Reporting to the IT Enterprise Risk Management Manager, the role maintains policies, assesses risks and controls, coordinates third-party reviews, drafts responses for client guidelines, prepares evidence for cyber insurance, and supports audits. Responsibilities align with ISO/IEC 27001/27002, NIST CSF, CIS Controls, SOC 2, HIPAA, GLBA, GDPR, and state privacy laws (e.g., CCPA/CPRA).

Requirements

  • Strong written and verbal communication skills; ability to translate control requirements into clear documentation and actionable guidance.

  • Strong organizational skills and attention to detail.

  • Ability to manage multiple priorities and deadlines.

  • Knowledge or ability to learn Microsoft Office Suite, or Microsoft 365., * Bachelor’s degree in information security, Information Technology, Risk Management, Business, or equivalent practical experience.

  • 3+ years of experience in GRC, information security, technology risk management, compliance, internal audit, or third-party risk management.

  • Working knowledge of ISO/IEC 27000 Family concepts, NIST CSF/SP 800-53/800-171, and HIPAA.

  • Familiarity with EU information security and privacy requirements (e.g., GDPR security principles); familiarity with NIS2 is a plus where relevant.

  • Experience collecting, organizing, and validating control evidence and supporting audits/assessments.

Certifications - ISACA: CRISC (Certified in Risk and Information Systems Control) and/or CISA (Certified Information Systems Auditor). Prior exposure to GRC, IT risk, or information security work in a law firm, professional services firm, or other client-confidential environment is preferred.

Familiarity with legal-industry technology (document management such as iManage or NetDocuments; time and billing such as 3E or Aderant; conflicts and new business intake such as Intapp; eDiscovery platforms such as Relativity) and with the data-sensitivity considerations they raise is a plus.

Awareness of the ABA Model Rules of Professional Conduct (in particular Rules 1.1 and 1.6) and applicable state bar requirements relating to technology competence and client confidentiality is preferred.

Familiarity with Controlled Unclassified Information (CUI) handling, NIST SP 800-171, CMMC, and ITAR/EAR data-handling concepts; prior exposure to federal, defense, or government-contracts client matters is a plus.

Certifications -

ISACA: COBIT Foundation, CDPSE, or CGEIT as applicable to governance, privacy, and enterprise risk responsibilities ISO/IEC 27001 Internal Auditor, Lead Implementer, or Lead Auditor.

Cloud and platform risk certifications such as Microsoft Certified: Security, Compliance, and Identity Fundamentals (SC-900), Azure Security Engineer Associate (AZ-500), or similar.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on dejobs.org
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:03 min

Platform compliance and security certifications for sensitive data

Chad Carlson · World Congress 2021

2:15 min

Auditing container configurations against CIS benchmark security standards

Madhu Akula · LIVE

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

3:46 min

Navigating a career in cloud transformation consulting

Piet Van Dongen · LIVE

3:39 min

Validating data queries and infrastructure security configurations

Philipp Krenn · World Congress 2023

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

Videos

See all

Related articles

See all