IT Security Risk Analyst

  • Princeton, NJ
  • Posted 1 day ago | Updated moments ago

Overview

On Site
BASED ON EXPERIENCE
Full Time
Contract - Independent
Contract - W2
Contract - 5+ mo(s)

Skills

SANS
IT Security
IT Risk
FOCUS
Human Resources
Finance
Procurement
Data Flow
NIST SP 800 Series
PCI DSS
ISO/IEC 27001:2005
Artificial Intelligence
Risk Management Framework
RMF
Privacy
Security Controls
Management
Risk Management
Workflow
Process Flow
Numara
Collaboration
Business Process
IT Risk Management
Testing
ServiceNow
SAP GRC
Training

Job Details

Role Name: IT Security Risk Analyst
Rate: $85/hr
Location: Princeton, NJ, USA (onsite)

"Develop and implement IT risk identification process aligned with risk management framework.
* Conduct IT risk workshops with business stakeholders to identify, discuss, and analyze potential risks within their environment.
* Current focus is on Human Resources, Finance, Global Procurement, and ERC IT applications. Moving forward, this process will extend to other business functions.
* Analyze and evaluate IT systems, integrations, and processes to identify vulnerabilities and weaknesses. Work closely with the IT Application and Security architects to better understand the data flow and integrations between IT systems.
* Develop an internal risk control framework based on industry standards aligned with CIS Safeguard, NIST SP 800-53, PCI-DSS 4.0, ISO 27001/2, NIST AI RMF, and NIST Privacy Framework. The goal is to verify all recommended security controls are aligned with industry standards.
* Monitor and manage IT risks in the risk register.
* Develop and implement risk mitigation plans and controls based on the internal risk control framework.
* Design, implement, and test ServiceNow GRC Risk Management Workflow Updates. Update GRC SOPs to reflect process flow updates.
* Monitor and track IT risk indicators and metrics by developing KRI (key risk indicators) to identify risk trends across the IT environment.
* Collaborate with cross-functional teams to verify IT risk management practices are integrated into business processes.
* Provide guidance and training to associates on IT risk management best practices.
* Provide testing for ServiceNow GRC application updates and develop training materials."

Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.

About Apolis