Information Governance Risk and Compliance Analyst
$110k - $125kFried Frank Business Services Opportunities
At Fried Frank, we’re a community of 800 lawyers and 500 business services professionals across New York, Washington, DC, London, Frankfurt, and Brussels. We advise leading corporations, investment funds, and financial institutions on high-stakes M&A, securities, regulatory matters, real estate, and litigation. Our culture is grounded in our core values — excellence, integrity and collaboration — and is designed to foster continuous learning, meaningful mentorship, and lasting professional growth. We are firmly committed to pro bono service and social justice, building on a proud legacy in civil rights. Our inclusive talent strategy is a core part of our broader talent management efforts and we remain steadfast in fostering a workplace where everyone has the opportunity to grow, thrive, and become their best professional and personal selves. Our business services professionals are integral to the firm’s success, driving innovation, operational excellence and exceptional client service across all areas of the firm. We offer competitive compensation and a comprehensive benefits package, including comprehensive medical coverage, retirement plans and health and wellness initiatives designed to support your personal and professional wellbeing. We welcome passionate, driven individuals to join us, and be part of a team where you’ll be supported, inspired and empowered to build an exceptional career. Position Summary:
As an Information Governance (IG), Risk, and Compliance Analyst, you will test, evidence, and report on the controls behind the firm's IG, risk, compliance, and information security programs. You will run recurring control audits, build the queries and scripts that generate the evidence, and produce the artifacts relied upon in client audits and internal assurance work.
Duties & Responsibilities:
Information Governance:
DevelopIG policies and procedures, and translate them into enforceable technical configurations and measurable controls.
Maintain an auditable inventory of data assets across Microsoft 365 and other approved information repositories, capturing classification, ownership, location, and retention state.
Risk Management:
Contribute to enterprise-wide risk assessments, quantifying exposure from overprovisioned access, stale data, and sensitive data sprawl from platform reporting rather than self-attestation.
Develop risk mitigation strategies and control requirements, and track findings and remediation to verified closure.
Compliance:
Support compliance with client contractual obligations (including outside counsel guidelines), regulations, and data protection laws by implementing and evidencing the corresponding controls.
Serve as technical respondent for client audits, security questionnaires, and regulatory inquiries, mapping requests to implemented controls and assembling the evidence; familiarity with control frameworks (ISO, SOC 2, NIST) helps, though the emphasis is technical testing over certification work.
Audit, Control Testing, and Evidence Collection:
Plan and execute recurring control audits across Microsoft 365, Entra ID, Active Directory, and approved information repositories, and maintain the audit calendar, evidence library, and exception record.
Collect evidence programmatically with PowerShell, Microsoft Graph, and KQL, querying audit trails across identity, mail, file, and endpoint platforms to show a control operated over a defined period.
Perform entitlement reviews and access recertification covering nested group membership, privileged roles, service and shared accounts, dormant objects, and broadly permissioned repositories.
Test control effectiveness rather than assuming it, validating classification and DLP detection, retention and disposition execution, and alerting coverage.
Information Security:
Oversee of the information security program, including periodic review of security tooling configuration against approved baselines and hardening against exfiltration and insider risk.
Perform incident response and recovery tasks, including log review, containment and scoping queries, evidence preservation, and post-incident remediation tracking.
Vendor and Third-Party Management:
Assess third-party vendor risk in data handling, reviewing questionnaires, audit reports, and penetration test summaries against observable configuration.
Collaborate with procurement and legal teams on contractual security, audit rights, and data handling requirements.
Reporting and Communication:
Communicate risk, compliance, and security findings to technical and non-technical stakeholders, and maintain recurring reporting on control testing and access review results.
Education:
Bachelor's degree in a relevant field; certifications in IT audit (e.g., CISA), Microsoft security and compliance administration (e.g., SC-400, SC-200), or in risk management are a plus.
Experience:
Mid-level position; 3-5 years of hands-on experience in IG, compliance, IT audit, or information security, including demonstrable work running control tests or access reviews.
Skills & Abilities:
Strong analytical, problem-solving, and communication skills, with working proficiency in PowerShell and KQL and experience querying platform audit logs.
Practical familiarity with Microsoft 365, Entra ID, Active Directory, and permissions models across approved information repositories, plus audit logging on those platforms and the ability to collaborate cross-functionally.
The actual salary offered will be based on a number of factors including but not limited to the qualifications of the applicant, years of relevant experience, level of education attained, certifications or other professional licenses held, and if applicable, the location in which the applicant lives and/or from which they will be performing the job.
New York Salary Range
$110,000—$125,000 USD
Vacancy posted 57 minutes ago
Similar jobs that could be interesting for youBased on the Information Governance Risk and Compliance Analyst in New York, NY vacancy
- ...Governance, Risk & Compliance (GRC) Analyst (AI Training) About the Role We're looking for experienced GRC professionals to help evaluate and... ...on experience in GRC, compliance, risk management, or information security ~ Solid familiarity with one or more major...SuggestedHourly payOngoing contractContract workFreelanceRemote workFlexible hours
$90k - $105k
...institutions, payroll providers, government agencies, and individual... ...The Vestwell Corporate Information Technology team is looking... ...oriented Information Security compliance analyst to be responsible for... ...Manage cybersecurity risk processes, including risk registers...SuggestedContract workFor subcontractorWork at officeLocal area- ...Expertise to JPMorganChase. As part of Risk Management and Compliance, you are at the center of keeping... ...Regulatory Strategy Officer within the Governance and Business Management team, you... ...and managing submission of certain information to regulators.Required qualifications...SuggestedWork at office
- The Senior IT GRC Analyst leads policy development and audit execution within CMG's IT Governance, Risk, and Compliance program, with particular emphasis on CMG's upcoming SOC 2 readiness... ...QUALIFICATIONS: Bachelor's degree in Information Technology, Cybersecurity, or a related...SuggestedWork at officeRemote work
$78.9k - $123.3k
...detail-oriented cybersecurity compliance professional to support... ...authorization lifecycle for one or more information systems, ensuring compliance... ...in accordance with Federal Risk Management Framework (RMF)... ...are subject to government customer review and approval...SuggestedPermanent employmentFull timeContract workPart timeWork at officeLocal areaRemote work- Position Overview:The Product Compliance Requirements Analyst for Diligent Entities will support the... ...About UsDiligent is the AI leader in governance, risk and compliance (GRC) SaaS... ...related or HIV/AIDS related), genetic information, or sexual orientation in accordance...Work at officeLocal areaVisa sponsorshipFlexible hours
$100k - $130k
Compliance Analyst Job type: Full Time · Department: Client Services · Work type: On-Site · USD 1... ...transactional behaviour, customer profiles, and risk indicators. Make risk‑based decisions... ...regulatory reviews, audits, and information requests as needed. Corporate...Full timeBank staffLocal areaRemote workFlexible hoursShift work- ...Role: IT Risk and Compliance Analyst Location: New York/Chicago, IL office at least 2-3 days... ...Handling: Our team receives numerous information requests from third parties and clients... .... 4. D42 Data Curation and Governance: Accurate D42 data is essential for...Contract workWork at office2 days per week3 days per week
- Reference: 13578Senior Compliance Officer, Investec USAInvestec - Where... ...regulatory and compliance risks across covered business... ...conduct, conflicts clearance and information barrier requirements across... ..., ensuring appropriate governance and documentation.Deliver management...Full timeWork at officeRemote work
$110k - $140k
The Compliance Officer will be instrumentally involved in overseeing... ...of interest and on information barriers. The CO will be reporting... ...conflicts-related matters and governance decisionsDrive remediation of... ...management on conflicts risk and control effectivenessCompliance...Full timeLocal area$110.7k - $218.3k
...Consultant - Regulatory & Compliance - Enterprise Operations & Risk Our Deloitte Regulatory,... ...those requirements into governance, risk, control, and... ...Required: Bachelor’s degree in Information Systems, Law, Business... ...or Chartered Financial Analyst designation The wage...Local areaVisa sponsorship- ...labor markets outside of NCAL.Support Health Plan Risk Adjustment operations through government audit readiness, compliance oversight, and internal quality assurance... ...promotes learning in others by proactively providing information, resources, advice, and expertise with...Work experience placement
- ...operate with honesty and clarity. We share information openly, the good and the bad, and... ...the Role Verse is looking for a Senior Compliance Associate to independently own the ongoing... ...scheduled visit Escalate urgent or high-risk findings promptly to compliance...Work at officeMonday to Friday
- We are seeking someone to join Global Compliance as a Vice President who will provide advisory... ...manages a Firmwide Compliance Risk Management program, including Compliance... ...perspectives, and experiences.For more information, please visit: .Employment Type:Full timeJob...Temporary work
$143k - $224k
...Wells Fargo is seeking a Lead Compliance Officer to play a critical... ...Operating at the intersection of risk management, regulatory... ...related to regulatory reporting governance, controls, and reporting... ...will be expected to provide information to the Wells Fargo Personal...Full timeWork experience placement$160k - $180k
Department: ComplianceDivision: Risk & Compliance DivisionTitle: Senior Compliance Manager and Privacy Officer Job SummaryProvide advice and... ....Ability to quickly assimilate sizable amounts of information relating to complex issues, maintain professionalism, diplomacy...Local area$120k - $155k
...and document any regulatory product risks, build out regulatory compliance frameworks for Adyen’s products,... ...into regulations, laws and rules that govern the landscape of payment processing... ..., veteran status, genetic information, marital status or any legally protected...Work experience placementWork at office$90k - $200k
...American Investigations, Diligence and Compliance practice is seeking a Senior Manager based... ...(client) investigations, insider risk compliance assessments, consulting projects... ...research where necessary.Ability to lead information gathering and investigative interviews with...Temporary work$90k - $110k
...26 at 4:00 AM Job Title: Security & Compliance Analyst Location: Home Office Compensation:... ...and audit artifacts in the company’s Governance, Risk, and Compliance (GRC) platform. Partner... ...& Experience Bachelor’s degree in Information Security, Information Technology, or...Home office$65k - $72.01k
...Provides overall labor compliance support to ensure... ...essential Labor Compliance Analyst responsibilities... ...to resolve. Develop risk assessments on Compliance... ...Participate in third party / Government reviews, audits and... .... Compile necessary information/documents and work...Hourly payFull timeTemporary workFor contractorsApprenticeshipWork experience placementFor subcontractorFlexible hours$72k - $78k
...Summary: Provides overall labor compliance support to ensure construction... ...to resolve. Develop risk assessments on Compliance Programs... ...Participate in third party / Government reviews, audits and inquiries. Compile necessary information/documents and work with...Full timeTemporary workFor contractorsApprenticeshipWork experience placementFor subcontractorLocal areaFlexible hours$96.57k - $130.65k
...Family: Cyber and IT Risk Management Job Qualifications... ...Cyber Risks, Security Compliance, Vulnerability... ...Security & Compliance Analyst will work as part of the... ...Data Modernization and Governance team responsible for... ...specialty area. Analyze information assurance-related...Temporary workWork at officeImmediate startRemote workWorldwideFlexible hours- Supporting federal cybersecurity compliance activities, the full-time Security Compliance Analyst will manage documentation,... ...: Support the Security Information Assurance Manager in executing... ...IT security Experience with Governance, Risk, and Compliance (GRC) tools such...Full timeRemote work
$134k - $202k
...comes next. About the role: We are looking for a GRC Analyst to join our Governance, Risk & Compliance (GRC) team. You will have the opportunity to manage... ...accountability is shared and stakeholders are informed. Streamline annual audits by managing audit deliverables...Work at officeRemote workWork from homeWorldwideMonday to FridayFlexible hours- Protective is seeking a Security Risk Analyst to strengthen our Information Security program in the United States... .... The role focuses on regulatory compliance, risk assessments, and vendor risk... ...teams. You will drive awareness, governance, and continuous improvement across...
- ...organization, the full-time GRC Analyst will design, implement... ...manage control and risk workflows, perform... ..., and ensure compliance with industry standards... ...Leads the design and governance of control frameworks... ...prioritization of risks Conducts information security risk...Full time
- Senior GRC Analyst job at Quantexa. New York, NY. What... ...experience in both US Government and non-government security and compliance, applying deep knowledge... ...of our Governance, Risk, and Compliance (GRC) function... ...3 controls for federal information systems and NIST SP 800...Contract workTemporary workWork experience placementImmediate start
- ...Private Markets. You will support day-to-day administration, governance coordination for a portfolio of U.S. entities, and assist the... ...with Europe and Asia teams ensures consistent execution and information flow. You will coordinate with external corporate secretarial...
$69.34 - $108.35 per hour
REGULATORY COMPLIANCE SPECIALIST (Contract) New York, NY, United States... ...ago root cause analysis Risk & Compliance Management... ...of model risk across design, governance and implementation. Applicable... ...oversight. Provide structured information transfer to Group Compliance...Permanent employmentContract workPart timeLocal area- We are looking for a Compliance Specialist that can engage in various areas of the risk and compliance team, who understands how to take a data-driven approach to... ..., and the ability to interpret regulatory information. Strong time management, organizational, and prioritization...
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Information Governance Risk and Compliance Analyst. Be the first to apply!
Related searches
- third party risk analyst New York, NY
- risk analyst intern New York, NY
- risk consultant New York, NY
- risk analyst New York, NY
- operational risk specialist New York, NY
- governance risk & compliance analyst New York, NY
- operational risk consultant New York, NY
- senior quantitative risk analyst New York, NY
- risk officer New York, NY
- it risk analyst New York, NY


