Information Security - Risk & Compliance Analyst
Victaulic
Job Description The Security Risk & Compliance Analyst supports the organization’s global information security program by assisting in the identification, assessment, and management of information security risks and compliance demands across Victaulic’s entire organization. This position plays an integral role in ensuring the company meets its obligations under domestic and international regulatory frameworks, including but not limited to NIST CSF, ISO27001, CMMC and the EU’s NIS2 Directive. The analyst will work closely with internal stakeholders, external auditors, and third‑party vendors to support a culture of security awareness and continuous compliance improvement. Responsibilities Risk Assessment & Management Assist in conducting information security risk assessments across business units, systems, and processes in accordance with established methodologies. Document risk findings, assign risk ratings, and track remediation activities through the risk register. Support the development and maintenance of risk treatment plans in coordination with system owners and IT teams. Participate in annual and ad hoc enterprise risk reviews, contributing analysis and supporting materials. Compliance & Framework Management Support compliance activities related to NIST Cybersecurity Framework (CSF), ISO/IEC 27001, CMMC (Cybersecurity Maturity Model Certification), and the EU NIS2 Directive. Conduct gap analyses against applicable frameworks and assist in developing remediation roadmaps. Maintain compliance documentation, including policies, procedures, control evidence, and assessment reports. Monitor regulatory changes and emerging framework updates; summarize implications for the security program. Third‑Party & Audit Management Coordinate and support third‑party security audits and assessments, including scheduling, evidence collection, and stakeholder communication. Assist in managing vendor risk assessments for new and existing third‑party vendors and suppliers. Track audit findings and corrective action plans, ensuring timely remediation and closure. Serve as a liaison between internal teams and external auditors during certification audits. Policy, Documentation & Awareness Assist in drafting, reviewing, and updating information security policies, standards, and procedures. Support the delivery of security awareness training and phishing simulation programs. Maintain organized records of all compliance and risk management activities in the Governance, Risk & Compliance platform. Collaboration & Reporting Collaborate with IT, Legal, Operations, and other business functions to integrate security requirements into business processes. Prepare regular status reports and metrics dashboards for management review. Contribute to the continuous improvement of the information security program by identifying process gaps and recommending enhancements. Qualifications Technical Experience Foundational understanding of information security principles, including confidentiality, integrity, and availability (CIA). Basic understanding of risk assessment methodologies and risk management concepts. Familiarity with third‑party risk management and audit processes. Strong analytical and problem‑solving skills with attention to detail. Capacity to understand legacy and progressive technology and security controls along with respective risk. Working knowledge of technologies such as cloud computing, DevOps, and application security is required. General Requirements Analytical Thinking – applies structured reasoning to evaluate risk and compliance data objectively Integrity & Accountability – Handles sensitive security information with discretion and professionalism. Communication – Clearly translates security requirements and findings for varied audiences across the organization Continuous Learning – Proactively keeps pace with evolving security frameworks, threats, and regulatory requirements Collaboration – Builds effective working relationships across IT, operations, and business functions globally Detail Orientation – Produces thorough, accurate documentation and maintains meticulous records of compliance activities Education & Certifications 0 – 2 years’ experience in information security, IT audit, risk management, or a related field. Bachelor’s degree, cybersecurity certification, or equivalent experience in an information security or related field. A minimum of an entry‑level certification such as the CompTIA Security+ certification. Additional Risk & Compliance certification(s), such as CISA, a plus. Work Environment & Physical Requirements This position is primarily office‑based with hybrid flexibility. The role may require occasional visits to manufacturing facilities domestically and internationally. Ability to work across global time zones may be required for coordination with European and Asian teams. Victaulic is an Equal Employment Opportunity (EOE/M/F/Vets/Disabled) employer and welcomes all qualified applicants. Applicants will receive fair and impartial consideration without regard to race, gender, color, religion, national origin, age, disability, veteran status, sexual orientation, genetic data, or other legally protected status. (Background checks may be required as part of our pre‑employment process). #J-18808-Ljbffr Victaulic
- Our client is seeking a Technology Risk & Compliance Analyst to support enterprise risk and information security compliance initiatives. This role partners with internal teams, external partners, and clients to help manage risk, maintain compliance frameworks, and support...SuggestedContract work
$90k - $115k
Job Summary IT Risk and Compliance Analyst position is a highly visible, client‑facing role that works closely with Legal and Business Unit... ...the firm’s risk and compliance with applicable information security standards and frameworks, industry best practices, and...SuggestedWork experience placementLocal area- ...AI Risk & Compliance Analyst | Location: New York, NY or Charlotte, NC | Contract To Hire AI Risk... ...collaboration across Legal, Privacy, Security, Procurement, Technology, and... ...Governance, Risk, Compliance (GRC), Information Security, Privacy, Technology Risk, Audit...SuggestedContract work
- ...AI Risk & Compliance Analyst Location: New York, NY or Charlotte, NC Job Type: Contract to Hire... ...evolving legal, regulatory, privacy, security, and compliance expectations. This role... ...governance, risk, compliance, privacy, information security, technology risk, third-...SuggestedHourly payContract workTemporary workFor contractorsLocal areaImmediate start
- Senior Governance, Risk, Compliance (GRC) Analyst job at Oura. New York, NY. At Oura, our mission is to... ...and New York) occasionally gather informally at local co-working locations. We are... ...(GRC) Analyst to join our Security Team. This role will serve as a subject...SuggestedWork at officeLocal areaRemote workFlexible hours
- Overview Remote Senior Governance, Risk and Compliance Analyst - Governance Remote. Come join the company that is reinventing cloud security and empowering businesses to thrive in... ...Help customer-facing teams respond to information security requirements and questionnaires...Remote job
- A defense contractor is seeking a Risk and Compliance Analyst to enhance data governance and interoperability for a DoD program. The role involves ensuring compliance with federal guidelines, conducting risk assessments, and preparing documentation for regulatory compliance...Remote jobFor contractors
$100k - $130k
King River Capital Group is seeking a Risk Management Analyst to join their Risk Management Team. The role involves supporting corporate insurance strategies and analyzing Property & Casualty exposures. Ideal candidates will have 5-7 years of risk management experience...Flexible hours- A leading IT recruitment firm is seeking a Risk & Compliance Analyst to support day-to-day activities related to quality control. In this remote role, you will analyze financial data, support compliance with audit requirements, and enhance processes through automation and...Remote jobContract work
$85k - $120k
...of laws, legal trends, and industry regulations. 8. Ensure compliance with all legal standards and regulations. 9. Develop strong... ...origin, age (40 and over), disability, military status, genetic information or any other basis protected by applicable federal, state, or...Permanent employmentLocal area$90k - $160k
...IT RISK & CONTROL SENIOR ANALYST WHAT IS THE OPPORTUNITY? The IT Risk Senior Analyst is a subject... ...complex technical environment. ITRM Security Senior Analyst will conduct fit for... ...Analyst's goal is to create actionable information for IT and business leadership, and...Remote work$63.75k
...Manager of Corporate Insurance at TKO, the Risk Analyst role is responsible for providing... ...and all underwriting, exposure and loss information. Diligently review and reconcile insurance... ...about Privacy and Information Security for TKO employment candidates, please review...Local area- ...consultants and project teams to assess security risks, develop security strategies,... ...systems, and encryption mechanisms. Compliance support: Assist clients in achieving and... ...master's degree in Computer Science, Information Security, or a related field. 1-3 years...
- ...mission. Our Unique Work: Information Security New York (ISNY) is... ...identifying and mitigating cyber risks and threats through risk-... ...are implemented through CSA analysts being embedded in the... ...employees and job applicants in compliance with applicable law and to...Full timeTemporary workPart timeShift work
$170k - $230k
Job Summary Cyber Security Assurance Analyst - New York Fed - Information Security FunctionThe Cyber Security Assurance (CSA) department assesses risks associated with third‑party vendors, systems... ...for employees and applicants in compliance with applicable law and to an...- ...it is essential that we have analysts dedicated to managing and execution of governance, risk, and compliance functions on behalf of the... ...stakeholders to strengthen the security posture of New York City... ...defending/protecting critical information and critical services. The City...Work at officeRemote workMonday to Friday
- ...Cybersecurity Risk Analyst We are seeking a Cybersecurity Risk Analyst to join our Information Security Risk team. This role focuses on assessing risks across applications (on-prem and cloud), infrastructure, and third-party vendors through a formalized risk assessment...
- A leading technology-driven financial services company in New York seeks an Information Security professional. The role involves governance, risk, and compliance activities pertinent to security within a hybrid work environment. Candidates should possess at least 2 years...Flexible hours
$80k - $90k
A fast-growing fintech company is seeking a Compliance Management System (CMS) Analyst to enhance its compliance program amidst evolving financial products. This remote role involves conducting compliance risk assessments and collaboration with product teams. Ideal candidates...Remote job$100k - $140k
Affirm is seeking a Compliance Analyst II in New York to support its compliance governance program. The role requires 3 to 5+ years of experience in Compliance or Risk within financial services. Responsibilities include addressing compliance concerns, reviewing consumer...Remote jobFlexible hours- A leading consulting firm is seeking a Compliance Analyst to join their team in New York. The role offers a hybrid schedule with four days in the office. You will support regulatory gap assessments, assist with project management in the derivatives market, evaluate internal...Work at office
- Kredete is looking for a Compliance Analyst to ensure compliance with regulatory standards in financial transactions. This role involves conducting KYC and KYB onboarding reviews, monitoring transaction activities, and preparing compliance metrics. The ideal candidate...
$60k - $75k
...in Fort Lee, New Jersey, is seeking an Analyst for IT Compliance to join its Technology team. The role... ...an IT compliance program, conducting risk assessments, and managing vendor documentation... ...to ensure compliance with legal and security standards. Ideal candidates have...$73.3k - $122.1k
CME Chicago Mercantile Exchange Inc. is looking for a Governance, Risk, and Compliance analyst to support Futures Commission Merchant compliance activities. The successful candidate will implement regulatory guidance, review transaction monitoring alerts, and conduct customer...$69k - $107k
Addepar, a global data and AI platform, is seeking a Compliance Analyst to maintain compliance programs and support legal functions. You'll implement compliance policies, conduct risk assessments, and develop training programs while collaborating across teams. The ideal...$87.8k - $160.9k
...objective of our consulting risk services is to provide clients... ...involves working closely with IT, security teams, and business units to... ...clients in employing proper information systems, resources, and... ...board of directors. Ensure compliance with relevant laws, regulations...Contract workSummer holidayWork at officeFlexible hours$90.6k - $150.44k
...Position Title Cloud/Cyber Risk Management Analyst Sr Location New York, NY 1001... ...monitor, and manage the Cybersecurity/Information Security ("Cyber") risk profile of the Bank,... ...of excess risk exposure and compliance with key regulatory requirements....Local area$1,150 - $1,450 per month
...Larry Summers , and Jack Dorsey . Position: Regulatory Compliance & Risk Management Expert Type: Contract Compensation: $1... ...For details about the interview process and platform information, please check: For any help or support, reach out to: support...Hourly payContract workSummer workRemote work$87.8k - $160.9k
...objective of our consulting risk services is to provide clients... ...involves working closely with IT, security teams, and business units to... ...clients in employing proper information systems, resources, and... ...board of directors. Ensure compliance with relevant laws, regulations...Contract workSummer holidayWork at officeFlexible hours$90.6k - $150.44k
Position Title: Cloud/Cyber Risk Management Analyst Sr | Location: New York, NY 10018 Job Summary... ..., and manage the Cybersecurity/Information Security risk profile of the Bank, ensuring... ...mitigation of excess risk exposure and compliance with key regulatory requirements....Local area
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Information Security - Risk & Compliance Analyst. Be the first to apply!
- entry level data analyst no experience New York, NY
- data analyst New York, NY
- neuroscience data analyst New York, NY
- data analyst full time New York, NY
- data protection analyst New York, NY
- salesforce data analyst New York, NY
- entry level information security analyst New York, NY
- information security analyst New York, NY
- remote data analyst New York, NY
- certified health data analyst New York, NY



