Information Risk Analyst - Information Security

  • Houston, TX
  • Posted 13 days ago | Updated 13 days ago

Overview

Hybrid
Depends on Experience
Contract - W2
Contract - Independent
Contract - 12 Month(s)

Skills

Analytical Skill
Articulate
Business Process
CISM
Communication
Cyber Security
DTCC
Database
Decision-making
ISACA
Information Security
Information Technology
Management
Microsoft Excel
Microsoft Power BI
Microsoft PowerPoint
Organizational Skills
Presentations
Reporting
Risk Assessment
Risk Management
Training
Writing

Job Details

Position Summary:

The Senior Information Risk Consultant is responsible for performing risk assessments of applications, infrastructure, business and technology vendors against a defined risk framework, when needed as part of Risk Treatment. These assessments will be conducted either through a formalized risk assessment program or through other risk reporting activities (e.g., policy exceptions, risk acceptance). The Senior Information Risk Consultant will have the ability to identify risks in the way that a business and technology utilize information and the supporting technological systems.

Principal Responsibilities:

Participate in and influence information risk assessment process improvement

Schedule and perform information risk assessments using DTCC methodology; identify, document and communicate control deficiencies in business processes and technology systems

Partner with the business and technology to agree cybersecurity risk findings identified through the risk assessment (e.g., vendor, application, infrastructure), new initiatives, and ad-hoc processes

Provide risk remediation recommendations that the business and technology may implement to mitigate identified control gaps

Partner with business and IT to ensure that risks are clearly articulated in a manner that is understood by business and technology audiences

Evaluate management responses to ensure that remediation plans and tasks adequately address identified control gaps

Document risk issues in the DTCC designated risk register

Assist the business and technology groups through the DTCC process for policy exceptions and risk acceptance, and work internally with the Risk Treatment team to address risks and issues efficiently.

Experience:

5 - 7 years of risk assessment experience in one or more areas: application, infrastructure, vendor risk management

Financial Services Industry experience a plus but not required

Proficiency with Information Risk Management best practices, standards, and frameworks

Knowledge and Skills Required:

Proven knowledge of technical infrastructure, networks, databases and systems and how they affect an organizations cybersecurity risk

Proven knowledge of security methodologies, policies, standards and best practices

Proven knowledge of information technology systems, infrastructure and operations

Ability to explain and articulate technical concepts using both technical and non-technical language

Critical thinking and analytical skills

Excellent presentation skills (MS PowerPoint / PowerBI)

Ability to manipulate data in a spreadsheet (MS Excel / PowerBI)

Ability to work collaboratively by building consensus and influencing decision making to foster forward progress with projects and initiatives

Strong oral and written communication skills

Excellent organizational skills, coupled with ability to be versatile and flexible

Sound business judgment and the ability to work successfully with all levels of management

Detail oriented; Excellent grammar and style skills; ability to adapt writing style for different audiences and media

Education, Training and Certification:

Bachelors degree preferred

CISSP/CISM/CRISC certification preferred

Regards,
Rajini Reddy
Sr IT Recruiter
Lumiere Systems Inc.,
Email :
Web :
Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.