Information Security Risk Analyst

🕒 March 31

Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of CivicPlus

CivicPlus

501 - 1000 employees

Founded 2001

📋 Compliance

🏛️ Government

☁️ SaaS

Compliance • Government • SaaS

CivicPlus is a leading provider of technology solutions for local governments, aimed at transforming the way municipalities operate and engage with their residents. With over 25 years of experience, CivicPlus offers a broad range of software solutions designed to automate processes, digitize services, and enhance civic experiences, all while ensuring compliance and accessibility. Their offerings include municipal websites, mass notification systems, social media archiving, 311 CRM system, and agenda and meeting management, among others. CivicPlus focuses on delivering a modern government experience, providing flexible, scalable, and customizable solutions to meet the complex needs of public sector operations. Their technology is trusted by over 10,000 local governments and is designed to improve communication, streamline workflows, and increase civic participation and satisfaction.

📋 Description

• Identify and translate inherent and residual risk through likelihood, impact, treatment plans, and ownership. • Define and track risk and awareness key metrics to measure program effectiveness and communicate to leadership and governance committees. • Conduct and manage enterprise information security risk assessment through recognized frameworks (including NIST 800-30) and maintain an information security risk register. • Lead third-party security risk assessments for vendors, partners, and service providers through analysis of assurance documentation, security testing summaries, and security questionnaires. • Maintain the information security risk register and third-party vendor risk inventory to track and monitor ongoing risks and approved exceptions. • Develop and lead enterprise security awareness training, including phishing simulations and targeted role-based training for security education and reporting. • Support internal and external security and compliance assessments through risk evidence and documentation. • Partner closely with organizational functions and key stakeholders to understand and address organizational risks across systems and processes, and ensure security risks are understood, prioritized, and treated in alignment with organizational risk appetite.

🎯 Requirements

• 4 – 6 Years of experience in information security, cybersecurity, risk management, or related field • Working experience managing enterprise/third-party risk assessments, risk registers, and security training programs. • Working experience supporting compliance audits and certifications, including NIST 800-53 (FedRAMP/GovRAMP), ISO 27001, PCI, and/or SOC 2 • Certifications Security+, GSEC, or equivalent • Bachelor’s degree in Cybersecurity, Information Security, Information Systems, Risk Management, or a related field (preferred)

🏖️ Benefits

• Comprehensive health insurance • Dental insurance • Vision insurance • Flexible Time Off • 401(k) plan • and more.

Apply Now

Similar Jobs

🕒 March 31

VikingCloud

1001 - 5000

🔒 Cybersecurity

📋 Compliance

💳 Fintech

Certified Ethical Hacker responsible for securing client networks from threats. Conducting penetration testing, vulnerability assessments, and collaborating with cybersecurity teams.

SQL

TCP/IP

🕒 March 31

CertiK

201 - 500

🌐 Web 3

🔐 Security

₿ Crypto

Security Engineer focusing on penetration testing in blockchain for CertiK. Responsible for conducting security assessments and contributing to innovative techniques in the field.

AWS

Azure

Cloud

Google Cloud Platform

JavaScript

Python

TypeScript

Web3

🕒 March 31

Microsoft Azure Security Administrator managing security solutions for Azure. Responsible for implementation, administration, and improvement of security compliance across digital assets.

Azure

Cloud

Firewalls

🕒 March 31

Security Engineer contributing to security team by building tools and implementing security controls. Focus on patient and provider safety and collaborating with external teams.

AWS

Azure

Cloud

Google Cloud Platform

Node.js

Python

Ruby

Terraform

🕒 March 31

Turnkey Consulting

51 - 200

🏢 Enterprise

🔒 Cybersecurity

📋 Compliance

SAP GRC/Security Consultant handling client engagements and implementing security solutions. Driving task management of complex implementations for SAP security in a remote environment.

Cyber Security