● 2–5 years in InfoSec risk, GRC, or audit with heavy assessment operations focus
● Demonstrated familiarity with NIST RMF (SP , NIST 800-30, and control catalogs (e.g., ; ISO 27005 a plus.
● Great written communication for treatment plans, acceptance memos, and stakeholder updates.
● Hands-on with GRC/risk tools (e.g., ServiceNow, Archer, OneTrust, custom trackers)
● Comfortable assessing application/service changes, infrastructure, and vendors using structured questionnaires and evidence.
We are seeking a detail-oriented Information Security Risk Analyst for one of our clients to execute high-volume, standardized risk assessments aligned with our InfoSec Risk Management Framework (RMF).
This role emphasizes process discipline—applying a structured methodology, maintaining accurate documentation, ensuring consistent scoring, and driving assessments from intake through analysis, treatment, and acceptance in close coordination with team leads.
You'll also support third-party risk (TPRM) evaluations during peak demand or when coverage is needed, applying the same methodical approach.