Epicareer Might not Working Properly
Learn More

IT Risk Analyst Level II

Salary undisclosed

Apply on


Original
Simplified
Rightworks offers the only intelligent cloud purpose-built for accounting firms and professionals. Backed by award-winning around-the-clock support, our fully managed IT and applications ensure customers have secure, reliable, on-demand access to their technology. We provide a curated software ecosystem that simplifies the complexity of running an accounting firm or small business, supported by a community of thought leaders, peer networks, and educational resources. Our success is made possible by leveraging decades of specialized experience in leading accounting firms and technology companies. Thousands of Firms and SMBs count on us to run their business every day.

We have a great team, we’re growing fast, and have a winning culture based on innovation, teamwork, and mutual respect.

Job Overview

As an IT Risk Analyst Level II, you will be responsible for identifying, assessing, and mitigating IT risks that could impact the organization’s operations and objectives. Your role will involve analyzing various IT risk factors, developing risk management strategies, evaluating potential threats, and ensuring compliance with regulatory requirements, all under the guidance of the NIST Cybersecurity Framework (CSF 2.0). You will collaborate closely with different teams and departments to implement effective IT risk controls and enhance the organization’s overall IT risk posture.

Responsibilities

  • Risk Identification & Assessment: Identify and assess IT risks through quantitative and qualitative measures
  • Risk Mitigation: Develop, recommend, and implement risk mitigation strategies
  • Reporting: Prepare and present reports detailing risks and recommendations to both technical and non-technical stakeholders
  • Continuous Monitoring: Prepare and present reports detailing risks and recommendations to both technical and non-technical stakeholders
  • Collaboration: Work closely with various departments to ensure understanding and alignment of risk management goals
  • Training & Awareness: Promote and support IT risk awareness across the organization
  • Compliance: Ensure the organization’s IT landscape complies with industry standards and regulations
  • Vendor Assessment:Evaluate third-party vendors for compliance and risk considerations
  • Policy Development: Create and maintain cybersecurity policies and procedures for framework compliance
  • Security audits: Perform regular/continuous security audits of established controls and prepare recommendations for continuous improvement

Requirements

General Knowledge:

  • IT Fundamentals: Basics of IT infrastructure, databases, networking, and applications
  • Risk Management: Knowledge of risk assessment methodologies and frameworks (e.g., NIST, ISO 27001/27005)
  • Regulations and Compliance: Familiarity with relevant industry regulations and standards, such as SOC2, PCI-DSS, etc
  • Business Continuity and Disaster Recovery: Basic concepts and best practices
  • Security Frameworks: An understanding of common cybersecurity frameworks and best practices, with a strong proficiency in the NIST CSF

Skills & Qualifications:

  • Analytical Skills: Strong problem-solving skills and the ability to analyze complex data to identify potential risks
  • Communication Skills: Ability to convey technical information to non-technical stakeholders
  • Problem-solving: Develop solutions for mitigating identified risks
  • Project Management: Organize, plan, and execute risk-related projects
  • Technical Proficiency: Familiarity with IT systems, applications, and security controls and in depth knowledge of cybersecurity principles, technologies, and best practices
  • Interpersonal Skills: Collaboration with other departments and understanding business needs
  • Risk Management: Proficiencies with risk assessment methodologies and the NIST CSF, as well as other frameworks like ISO 27001, SOC 2, and PCI-DSS
  • Incident response: A working knowledge
  • Bachelor’s Degree (Required): In fields such as Information Technology, Computer Science, Information Security, or a related field
  • Certifications (Preferred): Certified Information Systems Auditor (CISA), NIST Risk Management Framework (RMF), Certified in Risk and Information Systems Control (CRISC), or Certified Information Systems Security Professional (CISSP)

Benefits

To provide best-in-class solutions, we need a best-in-class team. We offer competitive salaries to recruit the best talent. We provide company paid short and long-term disability insurance, life insurance and a generous 401K match. We offer highly affordable medical, dental, vision coverage, and many other valuable benefits. We offer a generous PTO bank, and numerous paid holidays, affording you the time to be there for what is important in your life. We encourage giving back to our communities by providing volunteer paid time off. We are proud to be an Equal Opportunity Employer!

This job description may not be inclusive of all assigned duties, responsibilities, or aspects of the job described, and may be amended at any time at the sole discretion of the employer.

Powered by JazzHR

4f7hsrDlQG