Job description
The Risk Analyst will be responsible for conducting security and compliance risk assessments related to third-party vendors, assessing vendor risk exposure, and evaluating the effectiveness of controls. Additionally, they will handle user access review processes and act as a reliable consultant to stakeholders on matters of governance and compliance. Applicants should possess a minimum of 5 years of experience in cybersecurity, IT risk management, or a similar discipline, along with practical experience in vendor risk evaluations. A solid understanding of compliance frameworks such as NIST CSF, SOC 2, or HIPAA is essential, and holding professional certifications like CISA or CGRC is highly desirable.


