IT Enterprise Risk Analyst
Holland & Knight
IT Enterprise Risk Analyst
We are a Firm where people truly believe in what they do and strive to achieve the highest standards of performance and success.
This position is based in the Firm's global operations center in Tampa, FL.
We are seeking an IT Enterprise Risk Analyst to join our team. The IT Risk Analyst helps manage the Firm's GRC and IT risk programs, focusing on information security for client data, attorney work, and privileged communications. Reporting to the IT Enterprise Risk Management Manager, the role maintains policies, assesses risks and controls, coordinates third-party reviews, drafts responses for client guidelines, prepares evidence for cyber insurance, and supports audits.
Key Responsibilities and Essential Job Functions:
- Policy, Standards and Governance
- Support the development, review, and maintenance of information security and technology risk policies, standards, procedures, and guidance documents.
- Maintain the policy lifecycle process, including stakeholder reviews, approvals, publication, periodic review schedules, and version control.
- Map policies/standards to ISO, NIST, CIS Controls, SOC 2, HIPAA, GLBA, U.S. state privacy laws, and EU requirements, and to applicable client Outside Counsel Guidelines and contractual security addenda; maintain crosswalks and control documentation to support audit readiness.
- Administer policy exception and risk acceptance of workflows, ensuring justification, compensating controls, approvals, and defined expiration/renewal dates.
- Contribute to awareness materials and operational guidance to promote consistent implementation of requirements.
- Help maintain controls supporting ethical walls / information barriers, matter-level access restrictions, and legal hold obligations, under the direction of the Senior Analyst and in partnership with the Office of the General Counsel, Conflicts, and Records & Information Governance.
- Maintain awareness of the Firm's professional responsibility obligations, including ABA Model Rules 1.1 (technology competence) and 1.6 (confidentiality of information), and apply that awareness to policy implementation and control activities.
- Information Security and Technology Risk Management
- Conduct or facilitate risk assessments for applications, infrastructure, cloud services, Firm-critical legal-industry platforms (document management, time and billing, conflicts and new business intake, eDiscovery, and matter management), and key business processes; document risk statements, likelihood/impact, and control effectiveness.
- Maintain and update the risk register, including inherent and residual ratings, treatment plans, owners, milestones, and status updates.
- Partner with control owners to identify remediation actions, track progress, and validate closure with appropriate evidence.
- Support ongoing risk monitoring through key risk indicators (KRIs) and control health metrics, including indicators relevant to the legal sector (e.g., business email compromise and wire-fraud schemes, ransomware targeting law firms, and client-confidential data exposure).
- Draft and contribute to risk reporting and summaries for governance forums under the direction of the IT Enterprise Risk Management Manager, including content packaged for Firm leadership and Firm Management Committee audiences.
- Support incident response activities by gathering control and risk evidence, contributing to post-incident lessons learned, and helping ensure resulting control improvements are tracked in the risk register.
- Vendor/Third Party Risk Management (TPRM)
- Perform third party security due diligence based on vendor criticality and risk tiering (including third-industry parties such as co-counsel and local counsel, eDiscovery and document review providers, expert witnesses, court reporters and translators, legal-technology SaaS vendors, and managed-service providers handling client matter data); coordinate security questionnaires and evidence collection.
- Review assurance artifacts such as SOC reports, ISO certificates, penetration test summaries, security whitepapers, and privacy/security attestations.
- Identify gaps, document findings, recommend remediation/compensating controls, and track vendor action plans to closure.
- Partner with Procurement/Legal to ensure contracts include appropriate security and privacy requirements (e.g., breach notification, subcontractor controls, right-to-assess, data processing terms, and data residency as applicable).
- Support periodic vendor reassessments and reassessments triggered by scope changes, incidents, or material updates.
- Draft initial responses to inbound client security questionnaires and Outside Counsel Guideline (OCG) inquiries for Senior Analyst review; help maintain a controlled answer library and partner with the engagement attorney and Loss Prevention on follow-ups.
- Audit, Assurance and Compliance (ISO / NIST / CIS / SOC 2 / HIPAA / GLBA / EU)
- Support internal and external audits by coordinating evidence collection, control walkthroughs, and timely responses to audit requests.
- Assist with gap assessments and control testing against ISO 27001/27002, NIST CSF / SP 800-53 / 800-171, CIS Controls, SOC 2 Trust Services Criteria, GLBA Safeguards Rule, and HIPAA requirements.
- Support EU-aligned compliance activities where applicable (e.g., GDPR security measures and accountability documentation; NIS2-aligned operational practices).
- Track audit findings, corrective action plans (CAPs), and management responses; monitor remediation progress and validate closure evidence.
- Maintain audit artifacts including control matrices, evidence inventories, and standardized templates to improve repeatability and audit readiness.
- Support control activities related to handling Controlled Unclassified Information (CUI) and other regulated client data for the Firm's federal, defense, aerospace, and government-contracts practices, including evidence gathering and documentation aligned with NIST SP 800-171, CMMC Level 2 readiness, and ITAR/EAR data-handling requirements, under the direction of the Senior Analyst.
- Help compile control attestations and evidence packages for the Firm's annual cyber insurance application and renewal cycle, supporting responses to underwriter and broker inquiries under senior oversight.
- Expected to maintain a regular and predictable work schedule and full attention to and engagement in work activities on behalf of the firm during business hours unless otherwise approved or required by applicable law.
- Special projects and duties as assigned.
Required Skills:
- Strong written and verbal communication skills; ability to translate control requirements into clear documentation and actionable guidance.
- Strong organizational skills and attention to detail.
- Ability to manage multiple priorities and deadlines.
- Knowledge or ability to learn Microsoft Office Suite, or Microsoft 365.
Required Qualifications & Education:
- Bachelor's degree in information security, Information Technology, Risk Management, Business, or equivalent practical experience.
- 3+ years of experience in GRC, information security, technology risk management, compliance, internal audit, or third-party risk management.
- Working knowledge of ISO/IEC 27000 Family concepts, NIST CSF/SP 800-53/800-171, and HIPAA.
- Familiarity with EU information security and privacy requirements (e.g., GDPR security principles); familiarity with NIS2 is a plus where relevant.
- Experience collecting, organizing, and validating control evidence and supporting audits/assessments.
- Certifications - ISACA: CRISC (Certified in Risk and Information Systems Control) and/or CISA (Certified Information Systems Auditor).
Preferred Qualifications & Education:
- Prior exposure to GRC, IT risk, or information security work in a law firm, professional services firm, or other client-confidential environment is preferred.
- Familiarity with legal-industry technology (document management such as iManage or NetDocuments; time and billing such as 3E or Aderant; conflicts and new business intake such as Intapp; eDiscovery platforms such as Relativity) and with the data-sensitivity considerations they raise is a plus.
- Awareness of the ABA Model Rules of Professional Conduct (in particular Rules 1.1 and 1.6) and applicable state bar requirements relating to technology competence and client confidentiality is preferred.
- Familiarity with Controlled Unclassified Information (CUI) handling, NIST SP 800-171, CMMC, and ITAR/EAR data-handling concepts; prior exposure to federal, defense, or government-contracts client matters is a plus.
- Certifications –
- ISACA: COBIT Foundation, CD
- ...Cybersecurity Risk Analyst We are seeking a Cybersecurity Risk Analyst to join our Information... ...evaluating cybersecurity risks within enterprise environments. Candidates with a... ...and technology systems, partnering with IT and business units to communicate risks...Suggested
- ...scripts. Job Summary/Basic Function: Technology Risk Management Core Automation drives operational efficiencies within... ...tool. Principal Responsibilities: Understand cyber and IT best practices including knowledge of frameworks, guidelines, and...Suggested
- ...Compliance And Operations Risk Test Specialist Elevate your career by joining our team, where your analytical skills will drive impactful results in compliance and risk management. As a Compliance and Operations Risk Test Specialist in the Testing Center of Excellence...Suggested
- ...Senior Information Risk Consultant - Information Security Dallas, Texas, United States About the Job Job Title: Senior Information Risk Consultant - Information Security Location: Dallas, TX or Tampa, FL Experience Level: Mid-Senior (7+ years) Job Type: Contract...SuggestedContract workRelocationVisa sponsorship
- ...Enterprise Analyst This is a contract opportunity with our company that must be worked on a W2... ...Analyst will work as part of a team to reduce risk, improve application governance, and... ...experience Preferred Skills ~3rd-level IT escalation support, including networking...SuggestedContract workVisa sponsorship
- ...Business Risk Officer/Issues Management Support Analyst 6+ Months Tampa, FL (Hybrid- 3 Days Onsite) $50/Hr on W2 Responsibilities: Designing, developing, delivering and maintaining best-in-class Compliance Issues Management programs, policies and practices...Flexible hours
- ...Sr. Data Analyst 3 days per week onsite, must be local to Tampa FL -Senior Data Analyst with 5+ years of experience working in an enterprise data and analytics environment -Strong data mapping experience -Experience with reference data management...Local area3 days per week
- ...Data Visualization Analyst Own your opportunity to support national... ...connected across the global enterprise-directly, contributing to a mission... ...that communicate trends, risks, and performance outcomes, enabling... ...and execute mission critical IT services. Create clear,...Work at office
- ...Front/Middle/Back-office systems • Domain knowledge in Finance, Risk Management and/or Regulatory Reporting in the Banking industry... ...data and mappings • Passion to deliver results in a complex enterprise application / environment • Able to work with global teams...
- ...Data Analyst Rootshell Enterprise Technologies Inc. is a recognized provider of professional IT Consulting services in the US. We are actively seeking a Data Analyst for one of our direct client in Tampa, Florida. Please share your resume with current location and full...Local area
$96.57k - $130.65k
...Yes Job Description: DATA ANALYST YOUR IMPACT Own your... ...and connected across the global enterprise-directly, contributing to a mission... ...that support mission critical IT services. KEY... ...Analyze data to identify trends, risks, lifecycle status, technical debt...Temporary workImmediate startWorldwideFlexible hours- ...Data Analyst Join Fintech in Tampa, Florida as a Data Analyst! We're looking for a detail-driven Data Analyst to join our Data Governance... ...& Quality team. In this role, you'll be the guardian of our enterprise data, ensuring it's accurate, consistent, and high-quality....Temporary workCasual workLocal area
- ...Texas, Utah, Virginia, or Wyoming. The Clinical Applications Analyst II - Prelude advances Moffitt's mission to prevent and cure... ...to the design, implementation, and support of clinical and enterprise applications that improve patient care, research, and operational...Remote work
- ...Data Analyst (Patient Experience) Working at Moffitt is both a career and a mission: to contribute to the prevention and cure of... ...and planning and designing reports and dashboards that provide enterprise leaders with key data to measure and improve the patient experience...
$147.29k - $199.28k
...Description: TECH REFRESH DATA ANALYST YOUR IMPACT Own your... ...and connected across the global enterprise directly, contributing to a... ...priorities. Your work strengthens IT reliability, reduces technical... ...standings, site progress, and risk indicators to support planning...Temporary workImmediate startWorldwideFlexible hours- ...Position: Data Analyst Location: Tampa ,FL ( hybrid with 3 days onsite per week) Job Requirements Data Analyst with strong... ...closely with data science and business teams in large scale enterprise environments. Domain Retail (catalog, order, pricing,...Flexible hours3 days per week
- ...Business Analytics And Recognition Data Analyst We are a Firm where people truly believe... ...leadership and in partnership with the Enterprise Project Management Office (EPMO) as well... ...Knowledge Management, Finance, Human Resources, IT, and Innovation teams to promote...Temporary workWork at office
- ...Greetings from Rootshell Inc.. Rootshell Enterprise Technologies Inc. is a recognized provider of professional IT Consulting services in the US. We are actively seeking Data Analyst I for one of our direct client in Tampa,FL Job Title: Data Analyst I Location...
- ...Information Technology Analyst We are looking for an experienced IT professional to help establish and support our internal technology operations. This... ...who enjoys providing end-user support, working with enterprise applications, coordinating with external technology...
- ...technologies and operations. In addition to overseeing critical enterprise systems and providing world-class client service to our... ...Firm's systems and people. Position Summary The Analyst, Governance and Risk plays a pivotal role in protecting the firm against...Contract workWork at office
$137.53k - $166.65k
...Sr Quality Systems Analyst New Brunswick - NJ - US The Technical... ...support solution design and enterprise architecture standards. Establish... ...-initiative dependencies, risks, and alignment with enterprise... ...outcomes across business, IT, Quality, and Compliance. Advanced...Hourly payFull timeTemporary workPart timeSummer workWork at officeRemote workFlexible hours- ...Position- Data Quality Analyst Duration-W2 Only Location- Tampa, FL/Irving... ...Responsibilities : • Partners with Enterprise Chief Data Office to contribute to the development... ...vision • Appropriately assess risk when business decisions are made, demonstrating...Work at officeImmediate start
- ...We’re looking for a GRC Analyst who thrives in fast-moving, high-impact environments and has experience with risk management standards as well as monitoring cybersecurity risks... ...cross-functionally to operationalize enterprise security standards Drive remediation lifecycle...
- ...Senior Data Quality Analyst Tampa, FL or Irving, TX (3 days onsite - Hybrid) 12 months... ...Responsibilities: Partners with Enterprise Chief Data Office to contribute to the development... ...vision Appropriately assess risk when business decisions are made, demonstrating...Work at officeRemote work
- ...Business / Systems Analyst - III America Networks is a leading sensor and networking solutions... ...are looking to quickly expand the number of Enterprise Agile program teams operating effectively in the Wireline Network IT organization. In order to do this, we need to...
$103.92k - $155.88k
...The Business Risk and Control Officer is a strategic professional who stays abreast of developments within own field and contributes... ...material, emerging and concentration risks in accordance with enterprise Policies and the establishment of Key Indicators to monitor risk...Full time- ...solutions to automate manual processes Aligns risk and control processes into day to day... ...To maintain strong alignment between IT and the business, we are bringing together... ...combines Application Development and Enterprise Application Support functions, allowing us...Remote workFlexible hours
$85.04k - $162.55k
...development to financial reporting and long-term risk management. If you enjoy solving complex... ...experience partners, designers, business analysts, developers, testers and others to develop... ...Partners with sponsors, stakeholders, and IT to facilitate, the translation of business...H1bWork at officeRelocation packageFlexible hours- ...Job Title Product Management Business Analyst - Master Reference Data Job Description Are you ready to make an impact at DTCC... ...services to transition business requirements into enterprise solutions Expertise in financial services (Equities/Fixed Income...Work at officeFlexible hours
- ...Position- Data Mgt Lead Analyst Duration-W2 Only Location- Tampa, FL (3 days... ...work of others. Appropriately assess risk when business decisions are made,... ...our Jobs Portal Minority Business Enterprise (MBE) Certified | E-Verified Corporation...Local areaImmediate start
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to IT Enterprise Risk Analyst. Be the first to apply!


