Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Information Security - Risk & Compliance Analyst

Victaulic

Job Description The Security Risk & Compliance Analyst supports the organization’s global information security program by assisting in the identification, assessment, and management of information security risks and compliance demands across Victaulic’s entire organization. This position plays an integral role in ensuring the company meets its obligations under domestic and international regulatory frameworks, including but not limited to NIST CSF, ISO27001, CMMC and the EU’s NIS2 Directive. The analyst will work closely with internal stakeholders, external auditors, and third‑party vendors to support a culture of security awareness and continuous compliance improvement. Responsibilities Risk Assessment & Management Assist in conducting information security risk assessments across business units, systems, and processes in accordance with established methodologies. Document risk findings, assign risk ratings, and track remediation activities through the risk register. Support the development and maintenance of risk treatment plans in coordination with system owners and IT teams. Participate in annual and ad hoc enterprise risk reviews, contributing analysis and supporting materials. Compliance & Framework Management Support compliance activities related to NIST Cybersecurity Framework (CSF), ISO/IEC 27001, CMMC (Cybersecurity Maturity Model Certification), and the EU NIS2 Directive. Conduct gap analyses against applicable frameworks and assist in developing remediation roadmaps. Maintain compliance documentation, including policies, procedures, control evidence, and assessment reports. Monitor regulatory changes and emerging framework updates; summarize implications for the security program. Third‑Party & Audit Management Coordinate and support third‑party security audits and assessments, including scheduling, evidence collection, and stakeholder communication. Assist in managing vendor risk assessments for new and existing third‑party vendors and suppliers. Track audit findings and corrective action plans, ensuring timely remediation and closure. Serve as a liaison between internal teams and external auditors during certification audits. Policy, Documentation & Awareness Assist in drafting, reviewing, and updating information security policies, standards, and procedures. Support the delivery of security awareness training and phishing simulation programs. Maintain organized records of all compliance and risk management activities in the Governance, Risk & Compliance platform. Collaboration & Reporting Collaborate with IT, Legal, Operations, and other business functions to integrate security requirements into business processes. Prepare regular status reports and metrics dashboards for management review. Contribute to the continuous improvement of the information security program by identifying process gaps and recommending enhancements. Qualifications Technical Experience Foundational understanding of information security principles, including confidentiality, integrity, and availability (CIA). Basic understanding of risk assessment methodologies and risk management concepts. Familiarity with third‑party risk management and audit processes. Strong analytical and problem‑solving skills with attention to detail. Capacity to understand legacy and progressive technology and security controls along with respective risk. Working knowledge of technologies such as cloud computing, DevOps, and application security is required. General Requirements Analytical Thinking – applies structured reasoning to evaluate risk and compliance data objectively Integrity & Accountability – Handles sensitive security information with discretion and professionalism. Communication – Clearly translates security requirements and findings for varied audiences across the organization Continuous Learning – Proactively keeps pace with evolving security frameworks, threats, and regulatory requirements Collaboration – Builds effective working relationships across IT, operations, and business functions globally Detail Orientation – Produces thorough, accurate documentation and maintains meticulous records of compliance activities Education & Certifications 0 – 2 years’ experience in information security, IT audit, risk management, or a related field. Bachelor’s degree, cybersecurity certification, or equivalent experience in an information security or related field. A minimum of an entry‑level certification such as the CompTIA Security+ certification. Additional Risk & Compliance certification(s), such as CISA, a plus. Work Environment & Physical Requirements This position is primarily office‑based with hybrid flexibility. The role may require occasional visits to manufacturing facilities domestically and internationally. Ability to work across global time zones may be required for coordination with European and Asian teams. Victaulic is an Equal Employment Opportunity (EOE/M/F/Vets/Disabled) employer and welcomes all qualified applicants. Applicants will receive fair and impartial consideration without regard to race, gender, color, religion, national origin, age, disability, veteran status, sexual orientation, genetic data, or other legally protected status. (Background checks may be required as part of our pre‑employment process). #J-18808-Ljbffr Victaulic

Vacancy posted 16 hours ago
Similar jobs that could be interesting for youBased on the Information Security - Risk & Compliance Analyst in New York, NY vacancy
  • $100k - $125k

    ## Risk and Compliance AnalystApplyremote type: Hybridlocations: New Yorktime...  ...**The Risk and Compliance Analyst will play a key role in...  ...to ISO 27001, client-facing security assessments, and enterprise...  ...and help maintain the Firm’s Information Security Management System... 
    Suggested

    Davis Polk

    New York, NY
    16 hours ago
  • Polsinelli is seeking a Governance Risk & Compliance Engineer to join our information security and data governance team. The role offers a remote work option, with a preference for the position to be based in Kansas City. You will participate in governance programs, review... 
    Suggested
    Remote job

    Polsinelli

    New York, NY
    1 day ago
  • Our client is seeking a Technology Risk & Compliance Analyst to support enterprise risk and information security compliance initiatives. This role partners with internal teams, external partners, and clients to help manage risk, maintain compliance frameworks, and support... 
    Suggested
    Contract work

    TBG | The Bachrach Group

    New York, NY
    4 days ago
  • Victaulic is seeking a Security Risk & Compliance Analyst to support its global information security program across various regulatory frameworks. This role involves conducting risk assessments, managing compliance documentation, and coordinating third-party audits. Ideal... 
    Suggested

    Victaulic

    New York, NY
    16 hours ago
  • $161.6k - $202k

     ...patients — and that responsibility demands a security and compliance program that scales with the business....  ..., SOC 2, PCI-DSS, HIPAA), third-party risk management, security awareness...  ...through mitigation, and surfacing risk-informed priorities to engineering and security... 
    Suggested
    Work from home
    Flexible hours

    Headway - Design & Development

    New York, NY
    16 hours ago
  •  ...Governance, Risk & Compliance (GRC) Analyst (AI Training) About the Role We're looking for experienced...  ...systems being trained on real-world security, compliance, and risk scenarios....  ..., compliance, risk management, or information security ~ Solid familiarity with... 
    Hourly pay
    Ongoing contract
    Contract work
    Freelance
    Remote work
    Flexible hours

    Alignerr

    New York, NY
    16 hours ago
  • $80k - $150k

     ...KeyCorp is looking for an Operational Risk Analyst V specializing in Third Party Management in Brooklyn, Ohio. The ideal candidate should...  ...management experience and be skilled in regulatory guidance compliance. The role involves providing oversight on third-party risk... 

    Dormont Manufacturing Company

    New York, NY
    16 hours ago
  • Senior Governance, Risk, Compliance (GRC) Analyst job at Oura. New York, NY. At Oura, our mission is to...  ...and New York) occasionally gather informally at local co-working locations. We are...  ...(GRC) Analyst to join our Security Team. This role will serve as a subject... 
    Work at office
    Local area
    Remote work
    Flexible hours

    Itlearn360

    New York, NY
    1 day ago
  •  ...Qualifications Interest in Computer Science, Information Systems, Cybersecurity, or a related field Experience in technology audit, governance, risk, and compliance, information security, or related field is preferred, and willingness to learn is required... 
    Work at office

    Saxon Global

    New York, NY
    2 days ago
  • $63.75k

     ...Manager of Corporate Insurance at TKO, the Risk Analyst role is responsible for providing...  ...and all underwriting, exposure and loss information. Diligently review and reconcile insurance...  ...about Privacy and Information Security for TKO employment candidates, please review... 
    Local area

    TKO, LP

    New York, NY
    2 days ago
  •  ...& Wardwell LLP in New York seeks a Risk and Compliance Analyst to support the firm's governance, risk...  ..., vendor risk assessments, client security questionnaires, and policy governance...  ...candidate has 3-5 years in IT risk or information security, a Bachelor's in a related... 

    Davis Polk & Wardwell LLP

    New York, NY
    1 day ago
  • Grasshopper Bank is seeking a Fintech Risk Analyst to strengthen our risk management program for our BaaS partners. This remote role reports...  ...teams. You will assess inherent and residual risks, monitor compliance with BSA/AML, OFAC, and data privacy rules, and help maintain... 
    Remote job

    Grasshopper Bank

    New York, NY
    2 days ago
  •  ...Customer is a leading global, diversified information, services and media company with...  .... Our Customer is seeking a AI Risk and Compliance Analyst on a contract basis to support the intake...  ...cases. Evaluate data use, privacy, security, third‑party risk, regulatory... 
    Contract work
    For contractors

    BBG Ventures, LLC

    New York, NY
    2 days ago
  •  ...communications firm is seeking an AI Risk and Compliance Analyst to join their team. W2 Candidates...  ...including evaluation of data use, privacy, security, third-party risk, regulatory...  ...governance, risk, compliance, privacy, information security,technology risk, third-... 

    ManpowerGroup Global, Inc.

    New York, NY
    3 days ago
  • TECHNOLOGY RISK & COMPLIANCE ANALYST Information Services Department RESPONSIBILITIES include but are not limited to: Client Security Assessment Support: Respond promptly to inquiries from clients and prospective clients for security information Track and coordinate... 
    Contract work

    Debevoise-&-Plimpton-LL

    New York, NY
    4 days ago
  • Rose International, Inc. is looking for a full-time Risk Management Compliance Analyst to manage regulatory compliance for clients remotely. The candidate will handle reporting schedules and ensure adherence to state-specific requirements. The ideal candidate has 5-10... 
    Remote job
    Full time

    Rose International, Inc.

    New York, NY
    16 hours ago
  • Trinity Church NYC in New York, NY seeks an IT Risk & Compliance Analyst to safeguard its technology environment by managing cybersecurity risk...  ...and business continuity programs. The role supports security policy development, conducts risk assessments, oversees disaster... 

    Trinity Church NYC

    New York, NY
    1 day ago
  • $80k - $100k

    Framework Ventures is looking for a Cyber Compliance & Risk Management professional to protect digital assets and enhance organizational resilience. This role involves identifying, assessing, and mitigating cybersecurity risks while ensuring compliance with regulations... 

    Framework Ventures

    New York, NY
    16 hours ago
  • Fast Retailing is seeking a Risk Management Specialist to support risk, insurance, safety and regulatory compliance across the business. You’ll gather underwriting data for renewals, review policy documents, and help manage claims with brokers and adjusters, while coordinating... 

    Fast Retailing

    New York, NY
    16 hours ago
  •  ...IT SECURITY SPECIALIST - 95622 The Office of Technology and Innovation (OTI) leverages...  ...services to New Yorkers. Headed by the Chief Information Security Officer of the City of New...  ...threats. About This Role The Cyber Risk Analyst will serve in the Cyber Command Risk Program... 
    Full time
    Work at office
    Shift work
    Night shift
    Weekend work
    Afternoon shift

    TECHNOLOGY & INNOVATION

    New York, NY
    3 days ago
  • Early Warning Services LLC based in New York is searching for a Security Governance, Risk & Compliance Analyst. The role involves supporting various security governance initiatives, conducting assessments, and ensuring compliance across the organization. The candidate... 

    Early Warning Services LLC

    New York, NY
    1 day ago
  • $170k - $230k

    Job Summary Cyber Security Assurance Analyst - New York Fed - Information Security FunctionThe Cyber Security Assurance (CSA) department assesses risks associated with third‑party vendors, systems...  ...for employees and applicants in compliance with applicable law and to an... 

    Federal Reserve Bank (NY)

    New York, NY
    4 days ago
  • Ellenco Estágios e Treinamentos is seeking a Senior Information Security GRC Analyst to manage security audits and compliance efforts. The role requires over 10 years of experience in information security and a strong understanding of NIST standards. This position allows... 
    Remote job

    Ellenco Estágios e Treinamentos

    New York, NY
    16 hours ago
  • Dormont Manufacturing Co is seeking a Senior Analyst for Cyber Risk & Control Monitoring in New York, NY. This role focuses on improving...  ...in Cybersecurity and over 5 years of experience in information security. You'll work collaboratively with various teams and have... 

    Dormont Manufacturing Company

    New York, NY
    2 days ago
  • $75k - $95k

     ...Morgan Stanley is seeking an Analyst for its Risk Capital group in New York, responsible for regulatory capital assessments and enhancing processes. This role involves analyzing counterparty risk, collaborating with various teams, and providing recommendations on new... 

    Morgan Stanley

    New York, NY
    1 day ago
  • $80k - $90k

     ...A fast-growing fintech company is seeking a Compliance Management System (CMS) Analyst to enhance its compliance program amidst evolving financial products. This remote role involves conducting compliance risk assessments and collaboration with product teams. Ideal candidates... 
    Remote work

    Earnin

    New York, NY
    16 hours ago
  • VOIS is looking for a Compliance Analyst to support Vodafone's Global Roles, Governance & Compliance function. This role involves ensuring effective...  ...understanding of SAP GRC controls, SOX compliance, and risk management, with responsibilities including governance... 
    Remote job

    VOIS

    New York, NY
    16 hours ago
  • AlphaSense is maturing its GRC function and seeks a Senior Compliance Analyst to own end-to-end evidence collection across ISO 27001, SOC 2 and ISO 42001. You will partner with Engineering, IT, and Legal to maintain audit-ready controls and drive AI-native, automated workflows... 

    Tribeca Venture Partners

    New York, NY
    1 day ago
  •  ...Cybersecurity Senior GRC Analyst plays a critical role in...  ...regulatory, legal, and compliance obligations while managing risk effectively. The Global...  ...key risk indicators and security metrics. Risk Management...  ...Experience Bachelor’s degree in Information Security, Risk... 
    For contractors

    UGI Utilities, Inc.

    New York, NY
    16 hours ago
  •  ...industry. Job Summary The IT Risk Associate will support the organization...  ...management and cybersecurity compliance programs. Reporting to the...  .... Help identify potential security vulnerabilities, control gaps...  ...the governance framework for information security and IT risk. Assist... 
    Internship
    Local area

    Dormont Manufacturing Company

    New York, NY
    2 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Information Security - Risk & Compliance Analyst. Be the first to apply!