Security Risk Analyst
RIT Solutions
Security Risk Analyst
Onsite at 55 Water Street, NYC
Long Term Contract / Potential several years with Right to Hire GRC focused Security role / Risk management, etc.
The EITS Security Risk Analyst will interface between the CISO's strategic and process-based activities and the work of the technology-focused analysts, engineers and administrators in the IT organization. The Security Risk Analyst must be able to translate the IT-risk requirements and constraints of the business into technical control requirements and specifications, as well as develop metrics for ongoing performance measurement and reporting. The Security Risk Analyst coordinates the IT organization's technical activities to implement and manage security. The EITS Security Risk Analyst is part of the Enterprise Information Technology Services, Information Security and Risk Management team and will work at an enterprise level to ensure a consistent delivery of information security and risk management services. This individual will act as a subject matter expert to the assigned business units on matters regarding information security and compliance with HIPAA, Joint Commission, DSRIP, COBIT, and state privacy laws.
General tasks and responsibilities will include:
- Support information security and risk management by maintaining and enforcing the information security and risk management framework/methodology, including execution of risk analysis and risk mitigation strategies.
- Manage the process of gathering, analyzing and assessing the current and future threat landscape, as well as providing the CISO with a realistic overview of risks and threats in the enterprise environment.
- Exhibit best practice risk management skills through effective internal risk controls, risk monitoring, risk assessment and improvement of risk management processes.
- Document and maintain the enterprise security risk governance methodology and risk management policy, process, and procedure.
- Work with various stakeholders to identify information asset owners to classify data and systems as part of a control framework implementation.
- Organize and perform the enterprise security risk assessment and gap analysis for all technologies, products, and functions introduced, including maintaining risk project work plans to measure and manage progress.
- Track and document all internal risk reviews, assessments, risk acceptances, and security exceptions in a GRC tool.
- Work with the enterprise architecture team to ensure that there is a convergence of business, technical and security requirements; liaise with IT management to align existing technical installed base and skills with future architectural requirements.
- Develop a strong working relationship with the security engineering team to develop and implement controls and configurations aligned with security policies and legal, regulatory and audit requirements.
- Serve as the information security liaison and subject matter expert for all relevant EMR and PHI related security risk.
- Conduct or participate in all relevant audits and risk assessment activities (whether operational risk, legal/compliance risk, reputational risk, or information security risk).
- Aid in the planning and execution of risk remediation activities including the identification of practical, cost effective solutions.
- Facilitate team meetings between stakeholders, project leaders, and the Information Technology teams.
- Attend regular team, management, and project meetings and provide both verbal and written reports to the Leadership Team as required. This may include coordination with and support of an Operational Risk Committee.
- Keep informed on current threats and industry regulations.
Knowledgeable in:
- Healthcare industry experience required with understanding of EMR systems and data privacy issues related to PHI
- Experience with reviewing IT solution requirements and security controls implementation
- A strong understanding of the business impact of security tools, technologies and policies.
- Knowledge and experience working with a GRC Software tool
- Strong working knowledge of HIPAA, Joint Commission, CMS, and other regulatory legislation pertinent to the healthcare industry
- Working knowledge of information security frameworks such as NIST CSF, HITECH, ISO27001/27002, PCI DSS and COBIT
- Experience in conducting and responding to information security assessments and audits.
- Strong analytical skills and the ability to resolve complex security vulnerabilities and design compensating controls
Other preferred skills:
- Must possess a high degree of integrity and trust along with the ability to work independently
- Participate in special projects as needed and perform other duties as assigned
- Must be able to work independently as well as work as part of a fast-moving team
- Must be able to work at various locations when necessary along with working various shifts
Educational level:
- A bachelor's degree in information systems
- CISSP, CISA, CRISC or other relevant security qualification
Years of experience:
- A minimum of seven years of IT experience, least 5 years dedicated to IT Security Risk Management, Risk Audit/Assessment, and/or Security and/or Data Privacy Investigation least two years in a supervisory capacity.
- ...Position: Security Risk Analyst Location: Onsite at 55 Water Street, NYC Position Type: Long Term Contract / Potential several years with Right to Hire GRC focused Security role / Risk management, etc. Minimum Qualifications: The EITS Security...SuggestedLong term contractShift work
$160k - $190k
Simpson Thacher & Bartlett LLP is seeking a Senior Analyst, Third-Party Security in New York. This pivotal role involves managing the firm's Third-Party Security Program, which includes vendor risk assessments and incident response. The successful candidate will have over...Suggested$91k - $114k
...employer, at the date of hire. This position is ineligible for employment Visa sponsorship.Overall PurposeThe Security Governance, Risk & Compliance Analyst conducts comprehensive activities supporting information security governance, risk, and compliance, including but...SuggestedHourly payWork experience placementWork at officeImmediate startVisa sponsorshipWork visaFlexible hours$70k - $90k
Dormont Manufacturing Co is looking for an Information Security Analyst in Fort Lee, New Jersey. In this role, you will ensure compliance with IT governance requirements, work closely with various teams, and drive process improvements. The ideal candidate has over 3 years...Suggested- Presidio, Inc. is looking for a Security Analyst in New York to manage and maintain documentation related to information security standards.... ...developing policies and procedures, ensuring compliance, and analyzing risk. Ideal candidates will have 3-5 years of experience and...SuggestedRemote job
- ...Security Program Administrator The Security Program Administrator will be required to work with business owners and managers to acquire and maintain the knowledge and understanding of access control requirements of the business line applications and to provide security...Work at officeLocal area
- ...Securities & Derivatives Sr Analyst Hybrid Working at Citi is far more than just a job. A career with us means joining a team of more than 230,000... ...create, explore and be adventurous whilst taking measured risk, adopting safe practices to protect the firm. Data lineage...Work experience placementWork at officeLocal areaFlexible hours
$40 per hour
...A cybersecurity firm is seeking experienced professionals to join their team. In this remote role, you will evaluate AI-generated security content, solve technical cybersecurity problems, and provide valuable feedback to enhance AI systems. The ideal candidate has at least...Hourly payRemote work- ...Securities & Derivatives Analyst Working at Citi is far more than just a job. A career with us means joining a team of more than 230,000 dedicated people from around the globe. At Citi, you'll have the opportunity to grow your career, give back to your community and...Casual workWork at officeWork from home
- ...for an International US-based company. Key Responsibilities and Requirements: 4 to 5 years of experience specifically in Workday Security, including HR user security, domain security, business process security, integrations security, privacy, audit, controls, and regulatory...Contract workRemote work
$78.32k - $109.28k
...Securities and Derivatives Intermediate Analyst is an entry level position responsible for processing orders and transactions originating from trading desks... ...processing team members when required Appropriately assess risk when business decisions are made, demonstrating...Full time- ...Securities Valuation Analyst Start your journey at JPMorgan Chase, where you belong and your impact matters. Join a team that delivers independent... ...Bank provides strategic advice, raises capital, manages risk and extends liquidity in markets around the world....Worldwide
$90k - $110k
...stack, with a primary focus on Asset-Backed Securities (ABS). Covered sectors include autos,... ...analytics. The role focuses on identifying risk-adjusted investment opportunities in both... .... Act as a Securitized Products analyst with a primary focus on ABS, while...Flexible hours- ...Securities and Derivatives Intermediate Analyst Working at Citi is far more than just a job. A career with us means joining a team of more than 230,000... ...processing team members when required Appropriately assess risk when business decisions are made, demonstrating...
$85k - $95k
...standards to ensure AI is used ethically, securely, and transparently. If you join us, you'... ...looking for a Securities Lending Operations Analyst who will be responsible for performing... ...Must be able to identify and manage firm risk Organization - Must be able to prioritize...Contract workLocal areaFlexible hours- ...A leading AI cybersecurity firm is seeking experienced cybersecurity professionals to evaluate and improve AI-generated security content. This role focuses on assessing the accuracy of AI systems and solving technical cybersecurity challenges. Candidates should have over...Hourly payRemote workFlexible hours
- ...Database Security Role Database security role offers an opportunity to work in a hybrid environment of applying Access Control and Database knowledge. All Production database systems security is managed by a dedicated team and resources working on this team are focused...
- ...experienced cybersecurity and low-level programming experts for a short-term, high-impact project aimed at analyzing content for security vulnerabilities. Candidates with 2+ years of programming experience and strong knowledge of cybersecurity concepts are encouraged...Temporary work
$40 per hour
A tech firm specializing in cybersecurity is seeking experienced professionals to evaluate AI-generated content and address cybersecurity challenges. The ideal candidate will have 2+ years of hands-on experience, some coding knowledge, and strong analytical skills. This...Hourly payRemote work- ...Security Analyst Job Location: NYC, NY (Looking for local Candidate - MUST be able to onsite interview for this role in NYC) Job Type: 6+... ...metrics as both program performance indicators and enterprise risk indicators Assessing publicly and privately announced security...Contract workWork experience placementLocal area
- ...Summary: We are seeking an application security governance analyst to join and help establish and maintain effective governance practices... ...candidate will have a strong background in application security, risk management, compliance, and governance framework,...
$40 per hour
A cybersecurity tech company is seeking experienced professionals to evaluate AI-generated security content and address technical problems related to cybersecurity. This role offers both full-time and part-time remote options, allowing for flexible schedules and project...Hourly payFull timePart timeRemote workFlexible hours$196.9k - $295.3k
...Security Analyst, Bridge Bridge is Stripe's fintech innovation hub focused on building a modern, stablecoin-powered cross-border payments... ...This is a rare opportunity to design the security governance, risk and compliance programs from the ground up, while also leveraging...Full timeWork at officeLocal areaRemote workWork from homeRelocation$55 - $60 per hour
...Security Analyst Job Number: 26-00707 Use your skills where innovative technology solutions begin. ECLARO is looking for a Security... ...teams to detect threats, investigate security events, reduce risk, and help design secure enterprise solutions. Has 5 years...- ...Role Organization: Alignerr Type: Hourly Contract Location: Remote Commitment: 10–40 hours/week What You'll Do Analyze AI and LLM security scenarios to understand how models behave under adversarial, edge-case, or unexpected conditions Review and evaluate cases involving...Hourly payOngoing contractContract workFreelanceRemote workFlexible hours
- A consulting firm is seeking a Workday Security Analyst responsible for designing and maintaining security access within the Workday platform. This includes managing user provisioning, conducting security audits, and ensuring compliance with data privacy regulations. Candidates...Full timeContract workRemote work
$25 - $30 per hour
...A leading website security company is seeking a Security Analyst Support Intern to join their team. This 12-week internship offers a chance to work closely with customer support and gain hands-on experience in securing WordPress websites. Responsibilities include troubleshooting...Hourly payInternshipRemote work$34.62 - $43.99 per hour
...thoughtfully governed, continuously improved, and securely managed as we scale. Your work will directly reduce risk, strengthen compliance, and enable teams across... ...possible. As a IAM Governance & Controls Security Analyst , you’ll be a key contributor within our Identity...Hourly payFull timeRemote work$105.33k - $135k
...remote Employment Type Full time Location Type Remote Department Security Compensation $105,333 – $135,000 The salary range listed in... ...dynamic problems is collaboratively and respectfully. As a Security Analyst you will help build a culture of continuous improvement,...Full timeWork experience placementLive inLocal areaRemote workNight shift$40 per hour
A cybersecurity consultancy is seeking experienced professionals to evaluate AI-generated security content and solve technical problems. This role is fully remote, allowing candidates to work on a flexible schedule and select the projects they wish to engage with. Qualifications...Hourly payRemote workFlexible hours
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Security Risk Analyst. Be the first to apply!
- bond analyst New York, NY
- rate analyst New York, NY
- network security analyst New York, NY
- information security compliance analyst New York, NY
- security analyst intern New York, NY
- entry level information security analyst New York, NY
- security analyst remote New York, NY
- entry level security analyst New York, NY
- physical security analyst New York, NY
- security operations analyst New York, NY

