Information Security - Risk & Compliance Analyst
Victaulic
Job Description The Security Risk & Compliance Analyst supports the organization’s global information security program by assisting in the identification, assessment, and management of information security risks and compliance demands across Victaulic’s entire organization. This position plays an integral role in ensuring the company meets its obligations under domestic and international regulatory frameworks, including but not limited to NIST CSF, ISO27001, CMMC and the EU’s NIS2 Directive. The analyst will work closely with internal stakeholders, external auditors, and third‑party vendors to support a culture of security awareness and continuous compliance improvement. Responsibilities Risk Assessment & Management Assist in conducting information security risk assessments across business units, systems, and processes in accordance with established methodologies. Document risk findings, assign risk ratings, and track remediation activities through the risk register. Support the development and maintenance of risk treatment plans in coordination with system owners and IT teams. Participate in annual and ad hoc enterprise risk reviews, contributing analysis and supporting materials. Compliance & Framework Management Support compliance activities related to NIST Cybersecurity Framework (CSF), ISO/IEC 27001, CMMC (Cybersecurity Maturity Model Certification), and the EU NIS2 Directive. Conduct gap analyses against applicable frameworks and assist in developing remediation roadmaps. Maintain compliance documentation, including policies, procedures, control evidence, and assessment reports. Monitor regulatory changes and emerging framework updates; summarize implications for the security program. Third‑Party & Audit Management Coordinate and support third‑party security audits and assessments, including scheduling, evidence collection, and stakeholder communication. Assist in managing vendor risk assessments for new and existing third‑party vendors and suppliers. Track audit findings and corrective action plans, ensuring timely remediation and closure. Serve as a liaison between internal teams and external auditors during certification audits. Policy, Documentation & Awareness Assist in drafting, reviewing, and updating information security policies, standards, and procedures. Support the delivery of security awareness training and phishing simulation programs. Maintain organized records of all compliance and risk management activities in the Governance, Risk & Compliance platform. Collaboration & Reporting Collaborate with IT, Legal, Operations, and other business functions to integrate security requirements into business processes. Prepare regular status reports and metrics dashboards for management review. Contribute to the continuous improvement of the information security program by identifying process gaps and recommending enhancements. Qualifications Technical Experience Foundational understanding of information security principles, including confidentiality, integrity, and availability (CIA). Basic understanding of risk assessment methodologies and risk management concepts. Familiarity with third‑party risk management and audit processes. Strong analytical and problem‑solving skills with attention to detail. Capacity to understand legacy and progressive technology and security controls along with respective risk. Working knowledge of technologies such as cloud computing, DevOps, and application security is required. General Requirements Analytical Thinking – applies structured reasoning to evaluate risk and compliance data objectively Integrity & Accountability – Handles sensitive security information with discretion and professionalism. Communication – Clearly translates security requirements and findings for varied audiences across the organization Continuous Learning – Proactively keeps pace with evolving security frameworks, threats, and regulatory requirements Collaboration – Builds effective working relationships across IT, operations, and business functions globally Detail Orientation – Produces thorough, accurate documentation and maintains meticulous records of compliance activities Education & Certifications 0 – 2 years’ experience in information security, IT audit, risk management, or a related field. Bachelor’s degree, cybersecurity certification, or equivalent experience in an information security or related field. A minimum of an entry‑level certification such as the CompTIA Security+ certification. Additional Risk & Compliance certification(s), such as CISA, a plus. Work Environment & Physical Requirements This position is primarily office‑based with hybrid flexibility. The role may require occasional visits to manufacturing facilities domestically and internationally. Ability to work across global time zones may be required for coordination with European and Asian teams. Victaulic is an Equal Employment Opportunity (EOE/M/F/Vets/Disabled) employer and welcomes all qualified applicants. Applicants will receive fair and impartial consideration without regard to race, gender, color, religion, national origin, age, disability, veteran status, sexual orientation, genetic data, or other legally protected status. (Background checks may be required as part of our pre‑employment process). #J-18808-Ljbffr Victaulic
$153.4k - $191.8k
Security failures are rarely caused by a single technical mistake... ...from gaps in governance, risk management, operational discipline... .... We are looking for an Information Security GRC Analyst to help mature Mercury’s security, risk, and compliance programs. This is not a...Suggested- Polsinelli is seeking a Governance Risk & Compliance Engineer to join our information security and data governance team. The role offers a remote work option, with a preference for the position to be based in Kansas City. You will participate in governance programs, review...SuggestedRemote job
- ...symptoms that increase a person’s risk of heart attacks. At Cleerly... ...risks, ensuring ongoing compliance throughout the entire... .... About the Opportunity Our Information Security team is growing, and we have... ...for a GRC and IT Compliance Analyst to help support and execute...SuggestedImmediate startRemote work
- ...Governance, Risk & Compliance (GRC) Analyst (AI Training) About the Role We're looking for experienced... ...systems being trained on real-world security, compliance, and risk scenarios.... ..., compliance, risk management, or information security ~ Solid familiarity with...SuggestedHourly payOngoing contractContract workFreelanceRemote workFlexible hours
$100k - $125k
## Risk and Compliance AnalystApplyremote type: Hybridlocations: New Yorktime... ...**The Risk and Compliance Analyst will play a key role in... ...to ISO 27001, client-facing security assessments, and enterprise... ...and help maintain the Firm’s Information Security Management System...Suggested- ...together through commerce.RoleWhatnot's Security GRC team is dedicated to building... ...defend and protect our users' data and information as if it were our own. As part of the... ...a long way here.As our Governance, Risk, & Compliance Analyst you should have a minimum of 8+ years...Local areaRemote workHome office
- ...demand and are committed to providing excellent client service, supported by leading technology and talent. ROLE PURPOSE The Risk & Compliance Analyst - Registered Funds supports the Head of US Registered Fund Compliance/Fund CCO (“Fund CCO”) to establish, maintain and...Temporary workImmediate startFlexible hours
- Plan and conduct risk assessment activities across frameworks including NIST, HITRUST, PCI, HIPAA, SOC, MAR... ...owners and stakeholders Collaborate with Information Security, Privacy, Procurement, Audit, Compliance, Legal, technical staff, project teams, and third...
- Polar is seeking a Risk & Compliance Specialist to protect the integrity of our billing and payments platform. You will review merchants, identify risks, and ensure policy and partner requirements are met as we scale. You’ll collaborate with Merchant Support, Product, and...
- Trinity Church NYC in New York, NY seeks an IT Risk & Compliance Analyst to safeguard its technology environment by managing cybersecurity risk... ...and business continuity programs. The role supports security policy development, conducts risk assessments, oversees disaster...
$75k - $85k
Governance, Risk, and Compliance Associate - IT Job Category : Advisory Requisition Number : GOVER... ...the ability to learn and understand information systems and related internal control theory... ...of IT general controls including security administration, program change management...Full timeInternshipWork at officeFlexible hours1 day per week$75k
...deliver vital services to New Yorkers. Headed by the Chief Information Security Officer of the City of New York, we provide in-depth support... ...from cyber threats. About This Role The Cyber Risk Analyst will serve in the Cyber Command Risk Program under the direction...Full timeWork at officeShift workNight shiftWeekend workAfternoon shift$85k - $110k
...or a supervisor to join our team in the Governance, Risk, and Compliance (GRC) department. Our GRC team works with our... ...Audits. Weaver’s GRC - IT team focuses on assisting the Information Technology/Information Security functions within organizations, while specializing...Flexible hours- Ellenco Estágios e Treinamentos is seeking a Senior Information Security GRC Analyst to manage security audits and compliance efforts. The role requires over 10 years of experience in information security and a strong understanding of NIST standards. This position allows...Remote job
- Protective is seeking a Security Risk Analyst to strengthen our Information Security program in the United States. The role focuses on regulatory compliance, risk assessments, and vendor risk management while collaborating with legal, compliance, and technology teams....
- Madison-Davis, LLC in New York seeks a Partner Banking Analyst to help develop and execute the risk and oversight framework for fintech and third-party... ...monitoring, and reporting partner risk across financial, compliance, and regulatory dimensions. Collaborate across...
$75k - $95k
...Morgan Stanley is seeking an Analyst for its Risk Capital group in New York, responsible for regulatory capital assessments and enhancing processes. This role involves analyzing counterparty risk, collaborating with various teams, and providing recommendations on new...$160k - $180k
Technology and Information Security Risk Specialist Vice President | Second Line of Defense Position Summary The Technology and Information Security... ...Partners — Partners with Risk, IT, Information Security, Compliance, Audit, Operations, Vendor Management, Head Office, and...Work at officeLocal area$97.9k - $179.5k
...,900 - $179,500Job Function: Risk ConsultingEmployer: EY Global... ...the complexities of regulatory compliance and operational efficiency.... ...clients in employing proper information systems, resources, and controls... ...technology control and security engagements.Skills and attributes...Contract workSummer holidayFlexible hours- Crédit Agricole Group in New York seeks an AML/KYC advisor within the Financial Security advisory group to review high-risk KYC files and ensure regulatory compliance for proposed transactions. The role provides AML and sanctions guidance to staff and requires knowledge...
$80k - $90k
A fast-growing fintech company is seeking a Compliance Management System (CMS) Analyst to enhance its compliance program amidst evolving financial products. This remote role involves conducting compliance risk assessments and collaboration with product teams. Ideal candidates...Remote job- Millennium is seeking a compliance professional in New York to support regulatory programs and controls across the Firm’s global operations. You will administer the Code of Ethics and personal trading policies, monitor trading activity, and help coordinate training and...
- A leading consulting firm is seeking a Compliance Analyst to join their team in New York. The role offers a hybrid schedule with four days in the office. You will support regulatory gap assessments, assist with project management in the derivatives market, evaluate internal...Work at office
- Rain seeks a hands-on Compliance Analyst focused on KYC and KYB onboarding operations. You will review applications, make risk decisions and work directly with partners to move onboarding forward without compromising compliance quality. You will own your queue end to end...
- ...IT Risk and Compliance Analyst Location: New York/Chicago, IL office at least 2-3 days a week Duration: 6+ months Contract Must Haves... ...Client Questionnaire Handling: Our team receives numerous information requests from third parties and clients to satisfy their...Contract workWork at office2 days per week3 days per week
$124k - $177k
...last.Role OverviewThe Data Risk Analyst plays a key role in advancing... ...Enterprise Risk Management, Compliance, and other stakeholders to strengthen... ....Bachelor’s degree in Information Systems, Computer Science,... ...and GCP.Exposure to data security and privacy risk concepts, including...Local area3 days per week- Mercury is seeking an Information Security GRC Analyst to mature security, risk, and compliance programs and build guardrails for business continuity and resilience. You will lead risk assessments, partner with cross‑functional teams, and drive audit readiness across SOC...
- ...performs business functions. Information Risk Governance (“IRG”) provides... ...oversight to information and cyber security risk by maintaining and... ...Information Security Risk Analyst is responsible for supporting... ...status reports. # Monitor compliance of system vulnerability...Work at officeWork from homeFlexible hours2 days per week
- ...Division” which performs business functions. Information Risk Governance (“IRG”) provides oversight to information and cyber security risk by maintaining and improving branch... ...Overview: The Security Operations Center (SOC) Analyst is responsible for monitoring, detecting,...Work at officeWork from homeFlexible hours2 days per week
$98.8k - $146.4k
Third Party Risk Management Analyst - USDS Responsibilities The USDS Security - Risk & Compliance team is responsible for managing USDS security compliance in accordance... ...accommodation, please reach out to us at Job Information 【For Pay Transparency】Compensation...Contract workTemporary workWork at officeLocal areaRemote work3 days per week
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Information Security - Risk & Compliance Analyst. Be the first to apply!
- data conversion analyst New York, NY
- information systems analyst New York, NY
- data solutions analyst New York, NY
- epic reporting analyst New York, NY
- healthcare data analyst New York, NY
- entry level data analyst New York, NY
- information risk analyst New York, NY
- sql data analyst New York, NY
- data analyst excel New York, NY
- entry level information security analyst New York, NY


