Indianapolis, Indiana, 46204
Job description
The Risk Analyst will be responsible for conducting security and compliance risk assessments related to third-party vendors, assessing vendor risk exposure, and evaluating the effectiveness of controls. Additionally, they will handle user access review processes and act as a reliable consultant to stakeholders on matters of governance and compliance. Applicants should possess a minimum of 5 years of experience in cybersecurity, IT risk management, or a similar discipline, along with practical experience in vendor risk evaluations. A solid understanding of compliance frameworks such as NIST CSF, SOC 2, or HIPAA is essential, and holding professional certifications like CISA or CGRC is highly desirable.
Alera Group provides equal employment opportunities to all employees and applicants for employment and prohibits discrimination and harassment of any type without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state or local laws.

