Information Security Risk Analyst

  • Rockville, MD
  • Posted 7 hours ago | Updated 7 hours ago

Overview

Hybrid
Depends on Experience
Contract - Independent
Contract - 12 Month(s)

Skills

ServiceNow GRC
Riskonnect
LogicManager
RSA Archer
NIST SP 800-53
Factor Analysis of Information Risk (FAIR)
ISO 27005
FedRAMP
PCI
HIPAA Security Rule
ISO 27001
NIST RMF 800-37
CISA
CISSP
EMC RSA Archer
HIPAA
ISACA
ISO/IEC 27001:2005
Information Security
Information Systems
Management
NIST 800-53
Payment Card Industry
RSA
Regulatory Compliance
Risk Analysis
SAP GRC
ServiceNow
System On A Chip
CRISC
GRCP
CGRC

Job Details

ASSYST is seeking a qualified Information Security Risk Analyst to support our client s Governance, Risk, and Compliance (GRC) program. This role involves identifying, assessing, and documenting risks related to information systems, technologies, vendors, and operational processes ensuring alignment with client security policies and regulatory standards.

Key Responsibilities:

  • Conduct structured risk assessments

  • Review internal controls

  • Evaluate third-party security attestations

  • Support vulnerability and compliance activities

Policy Exception Management:

  • Validate and assess policy exception requests via ServiceNow GRC

  • Conduct risk evaluations and recommend approval or denial

  • Collaborate with cross-functional teams to enhance risk posture

Qualifications:

  • Experience with GRC tools (ServiceNow, RSA Archer, etc.)

  • Knowledge of frameworks: NIST 800-53, ISO 27001, HIPAA, PCI, FedRAMP

  • Strong technical foundation and risk analysis skills

  • Familiarity with FAIR and SOC 1/2 Type II assessments

Preferred Certifications:

  • CISSP, CRISC, GRCP, CISA, CGRC

ASSYST is an Equal Opportunity Employer. Qualified applicants will receive consideration for employment without regard to race, color, religion, sex, age, disability, military status, national origin or any other characteristic protected under federal, state, or applicable local law.

Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.