Enterprise Risk Analyst
$125k - $175kTrue Anomaly
Space is a warfighting domain. True Anomaly seeks those with the talent and ambition to build the technology that secures it.
OUR MISSION True Anomaly delivers decisive capabilities for space superiority. We build autonomous spacecraft, advanced payloads, mission software, and space-based interceptors - enabling the U.S. and its Allies to secure the space environment and counter threats from the ultimate high ground. OUR VALUES- Be the offset. We create asymmetric advantages with creativity and ingenuity.
- What would it take? We challenge assumptions to deliver ambitious results.
- It's the people. Our team is our competitive advantage and we are better together.
We are seeking a driven and detail-oriented Enterprise Risk Analyst to support two distinct but interconnected lines of effort: Enterprise Risk Management (ERM) and Third-Party Vendor Risk Management (TPVRM). Reporting to the Senior Enterprise Risk Manager, you will play a hands-on role in executing risk assessments, maintaining program documentation, tracking remediation activities, and building the data foundation that powers executive-level risk decision-making.
This role is ideal for a mid-career risk professional who is fluent in frameworks such as NIST RMF and CMMC, is developing practical experience with risk quantification methodologies like FAIR and OCTAVE, and is eager to grow within a fast-paced aerospace and defense SaaS environment. You will work closely with engineering, security, legal, compliance, and operations teams to help identify, document, and track risk across the enterprise and its third-party supply chain.
Responsibilities: Enterprise Risk Management
- Support the design, execution, and continuous improvement of the enterprise risk management program under the direction of the Senior Enterprise Risk Manager.
- Assist in conducting structured risk assessments using OCTAVE or similar threat-and-asset-centric methodologies, documenting findings, threat profiles, and recommended mitigations.
- Support the application of FAIR methodology to help quantify risks in financial terms and contribute to risk prioritization analyses for leadership.
- Maintain and update the enterprise risk register, ensuring accuracy of risk ratings, ownership assignments, remediation status, and residual risk tracking.
- Build and maintain program dashboards, KPI/KRI reports, and status tracking using tools such as Jira, Confluence, enterprise GRC platforms, and MS Project.
- Assist with audit readiness activities including evidence collection, pre-assessment preparation, control documentation, and post-audit remediation tracking.
- Support POA&M management for IL5 and IL6 environments, tracking open items to closure and escalating blockers to the Enterprise Risk Manager.
- Contribute to the development and maintenance of risk policies, standards, and guidelines aligned to NIST SP 800-53 Rev. 5, NIST SP 800-171, RMF, and CMMC Level 3.
- Coordinate and track internal audit schedules, findings, and corrective action plans across business units.
- Execute vendor risk assessments as part of the onboarding and periodic review lifecycle, including security questionnaire administration, documentation review, and risk scoring.
- Maintain the vendor risk inventory and lifecycle tracking records, ensuring all vendors are appropriately tiered and assessed on schedule.
- Monitor vendor risk signals including cybersecurity advisories, regulatory actions, and contractual compliance status, escalating material changes to the Enterprise Risk Manager.
- Support contract and procurement teams by providing vendor risk assessment findings and recommended risk mitigation language.
- Assist in ensuring TPVRM program alignment with CMMC supply chain requirements, DFARS clauses, and ITAR/export control considerations for critical suppliers.
- Develop and maintain vendor risk reporting inputs and dashboard content to support executive-level visibility into third-party risk exposure.
- Serve as a reliable day-to-day point of contact for risk-related inquiries from internal stakeholders across engineering, security, operations, and legal teams.
- Track program milestones, action items, and deliverables, proactively communicating status and flagging risks or dependencies to the Enterprise Risk Manager.
- Continuously improve risk program workflows, documentation templates, and reporting processes to support scalable and repeatable execution.
- Support the preparation of materials for internal leadership briefings, external assessor interactions, and government partner reviews.
- 5+ years of experience in enterprise risk management, GRC, cybersecurity risk, compliance, or a closely related discipline.
- Working knowledge of NIST SP 800-53, NIST SP 800-171, DoD RMF (IL5/IL6), and CMMC, with direct experience supporting assessments or audits under one or more of these frameworks.
- Familiarity with risk assessment methodologies including FAIR and/or OCTAVE, with a desire to deepen applied expertise in risk quantification.
- Experience supporting or executing third-party/vendor risk assessments, including questionnaire administration, documentation review, and risk tracking.
- Hands-on experience with program management and GRC documentation tools including Jira, Confluence (Atlassian suite), MS Project, enterprise GRC platforms, and MS Visio or Lucidchart.
- Strong written and verbal communication skills, with the ability to clearly document findings and translate risk concepts for both technical and non-technical audiences.
- Highly organized, self-directed, and comfortable managing multiple workstreams simultaneously in a fast-paced, regulated environment.
- Active or ability to obtain SECRET , TS/SCI security clearance .
- Must be a U.S. citizen, lawful permanent resident, or protected individual per ITAR requirements (8 U.S.C. 1324b(a)(3)).
- Background in startup, aerospace, defense technology, or SaaS companies operating in regulated government markets.
- Industry certifications such as:
- Certified in Risk and Information Systems Control (CRISC)
- Certified Information Systems Auditor (CISA)
- Open FAIR Certification (The Open Group)
- CompTIA Security+ or equivalent
- Certified ScrumMaster (CSM) or similar Agile certification
- Experience with cloud environments, particularly Azure Government and/or AWS GovCloud.
- Familiarity with POA&M management, SSP documentation, and audit evidence collection in DoD authorization contexts.
- Working knowledge of ITAR, EAR, DFARS, and export control considerations as they relate to vendor and supply chain risk.
- Familiarity with Agile/Scrum and hybrid project delivery models.
- Base Salary: Denver - $105,000 to $150,000, Long Beach - $115,000 to $160,000, Washington, DC - $115,000 to $160,000, SF Bay Area - $125,000 to $175,000
- Equity + Benefits including Health, Dental, Vision, HRA/HSA options, PTO and paid holidays, 401K, Parental Leave
Additional Requirements
- Work Location: This role will be onsite at one of our office locations: Centennial, CO, Long Beach, CA, SF Bay Area, or Washington, DC #LI-Onsite
- Work Environment: Standard office setting, working at a desk or in a production factory environment
- Physical Demands: May include frequent standing, sitting, walking, bending, and lifting or carrying items up to 20 lbs.
This position will be open until it is successfully filled.
To conform to U.S. Government space technology export regulations, including the International Traffic in Arms Regulations (ITAR), you must be a U.S. citizen, lawful permanent resident of the U.S., protected individual as defined by 8 U.S.C. 1324b(a)(3), or eligible to obtain the required authorizations from the U.S. Department of State.
We value diversity of experience, knowledge, backgrounds, and perspectives and harness these qualities to create extraordinary impact. True Anomaly is committed to equal employment opportunity regardless of sex, race, religion or belief, ethnic or national origin, disability, age, citizenship, marital, domestic or civil partnership status, sexual orientation, gender identity, pregnancy, maternity or related condition (including breastfeeding) or any other basis as protected by applicable law. If you have a disability or additional need that requires accommodation, please do not hesitate to let us know.
To conform to U.S. Government space technology export regulations, including the International Traffic in Arms Regulations (ITAR) you must be a U.S. citizen, lawful permanent resident of the U.S., protected individual as defined by 8 U.S.C. 1324b(a)(3), or eligible to obtain the required authorizations from the U.S. Department of State. True Anomaly is committed to equal employment opportunity on any basis protected by applicable state and federal laws. If you have a disability or additional need that requires accommodation, please do not hesitate to let us.
Vacancy posted 15 hours ago
Similar jobs that could be interesting for youBased on the Enterprise Risk Analyst in Denver, CO vacancy
$110k - $135.3k
...through our GEM awardsJob DescriptionResponsible for conducting detailed analysis that contributes to and advances one or more Enterprise Risk Management (ERM) programs to assist CoBank in managing credit/market/operational risks. Such programs include, but are not limited...SuggestedWork at officeWork visaFlexible hours- Trueanomalyinc is looking for a detail-oriented Enterprise Risk Analyst based in Denver, CO. The successful candidate will support enterprise risk management and vendor risk management efforts, collaborating with various internal teams to ensure risk mitigation and compliance...Suggested
$100k - $123k
...fellow associate through our GEM awardsJob DescriptionResponsible for conducting detailed analysis that contributes to and advances Risk Management programs and processes including the Operational Risk and Resilience, Product Governance, AI Risk Governance, and Risk Governance...SuggestedWork at officeWork visaFlexible hours$87k - $97k
...something better. Overview Crocs, Inc. is building a centralized Enterprise AI function to drive responsible adoption of artificial... ...the Sr Manager, AI Solutions & Delivery, the **AI Governance & Risk Analyst** will establish the policies, controls, risk assessments, and...SuggestedTemporary workWork at officeImmediate startRemote workFlexible hours$75k - $110k
...Risk Management AnalystAt Prologis, we don't just lead the industry—we define it with... ...next.A day in the lifeAs a Risk Management Analyst at Prologis, you will help manage risk across... ...careers here.As a successful global enterprise, Prologis has never lost sight of what matters...SuggestedFull time- Crocs, Inc. is forming a centralized Enterprise AI function. The AI Governance & Risk Analyst will establish policies, controls, and oversight to move quickly while protecting the company. The role partners with engineers, Legal, Security, IT, and auditors to build guardrails...
- ...Governance Risk & Compliance AnalystSystem One is seeking a GRC Analyst for an opportunity in Lakewood, CO. The GRC Analyst is a member of the Governance, Risk... ...infrastructure rules) and their potential impact on enterprise operations.System One, and its subsidiaries...Work at officeLocal area
$60k
...Suitability is preferred. U.S. citizenship or U.S. national status required. The Risk, Quality, and Performance Analyst serves as the Risk, Quality, and Performance Analyst supporting an enterprise IT services contract. This role is responsible for monitoring and reporting...Contract workRemote work$145k - $189k
Job Title: Salesforce - Senior Business Analyst You are an experience Salesforce Business... ...through clear requirements, reducing delivery risk by minimizing ambiguity and rework. You... ...with the complete lifecycle of complex enterprise projects; understanding of core project management...Temporary workLocal area- Ensure the accuracy, integrity, and reliability of data used in risk and compliance activities. Write advanced SQL/HQL scripts,... ...leverage new technology. Ensure all data practices adhere to enterprise governance, compliance, and data management standards. Perform...Work experience placement
$109.6k - $191.7k
Senior Risk ConsultantRemote - USAProvides loss control support for Property & Casualty underwriters and insurance customers in AXA... ...health, wellbeing, lifestyle and financial security. It provides enterprising compensation and personalized, inclusive benefits that evolve...For contractorsWork at officeFlexible hours$96k - $181k
...JobReporting to the Director of Cybersecurity Risk Oversight, the Sr. Cybersecurity Risk... ...corresponding Business Risk and Control Analysts.This position is responsible for... ...security risk oversight for areas of the enterprise that manage technology. As part of this...Full timeWork at officeFlexible hoursNight shift- ...Enterprise Data AnalystWe are seeking a skilled Data Analyst to join our dynamic team. As a Data Analyst, you will play a crucial role in supporting decision-making processes, optimizing business operations, and driving organizational growth through data-driven strategies...Work experience placement
$99k - $124k
...transform chronic conditions by identifying risk earlier, coordinating thoughtful care,... ...here. What You'll DoWe are seeking a Lead Analyst, Risk Adjustment Analytics to join our... ...decisions by linking operational performance to enterprise financial outcomes. Perform end-to-end...Work at officeRemote workWork from homeFlexible hours2 days per week$85k - $95k
Senior Risk & Insurance Analyst Within our Corporate Enterprise Risk Management team in Denver , Leprino is seeking a Senior Risk & Insurance Analyst to support and strengthen our insurance and risk management programs. This role partners with Finance and teams across...Work at officeLocal areaWorldwide$90.4k - $113k
.... To learn more, visit Location: Hybrid 3 days (offices in NYC, Denver, CO and Charlotte, NC area) Position Summary The Senior Analyst, Risk Management (PGs) supports the Risk Management function by maintaining the day-to-day governance, tracking, and reporting of client...Contract workLocal areaFlexible hours- Automation Anywhere, Inc. is seeking a Business Analyst in Bogota, Colombia to translate business challenges into scalable automation... ..., ensuring solutions align with governance, security, and enterprise architecture while supporting large-scale APA #J-18808-Ljbffr...
- CAC I International Inc. in Denver, CO is seeking an Integrated Operations (IO) Bridge Analyst for the night shift to monitor and manage enterprise services, provide situational awareness, and coordinate with ISC NOC and government partners. The role requires TS/SCI with...Night shift
$80.05k - $165k
...Role: Responsible for leading Cybersecurity and IT governance, risk, and compliance efforts, including the establishment and... ...including Internal Audit, External Audit, Corporate Compliance, Enterprise Risk Management, Legal) to ensure TAG is aligned with these groups...Full timeWork at officeLocal area- Judi Health in Denver, CO is seeking a Senior Analyst, Risk Management (Audit) to run cross-functional risk initiatives from intake to closure in a hybrid role. You will design dashboards, track KPIs, and surface audit findings and action plans. The ideal candidate has...
$76k - $91.75k
As a member of the Knowledge Management Department, the Risk Mitigation Analyst conducts hands‑on, detail‑oriented public records and investigative research in support of the firm's client engagements and internal risk management functions. The Analyst investigates individuals...Full timeWork experience placementWork at office- ...dynamic environment, business leaders face constantly shifting risks. Riveron helps organizations implement leading governance, risk... ...duties and access risk review, policy and procedure development, enterprise risk management, and IT and cybersecurity risk assessment. The...Full timeContract workWork at officeShift work
- Affirm is seeking an Analyst I in Risk & Analytics to learn consumer lending fundamentals and perform scoped analytical tasks daily. You will leverage SQL and Python to build scalable reports and partner with engineering to deploy ML and risk models. You will work under...Remote job
$100k - $123k
...stakeholders.Essential FunctionsContributes to the research and development of financial models incorporating credit and/or market risk elements.Contributes to or owns the ongoing management of existing models, which includes maintenance of data/documentation/parameters...Work at officeWork visaFlexible hours$65k - $75k
Position Information Security Risk and Compliance Analyst - Denver, CO Job Summary Provides day‑to‑day tactical support to the enterprise’s second line Information Security Risk & Compliance function by executing defined control oversight and risk support activities....- Sunflower Bank, N.A. in Denver, CO seeks an Information Security Risk and Compliance Analyst to provide day-to-day support to the enterprise's second line risk & compliance function. You will execute control oversight activities, including user access reviews and vendor...
$134.5k - $265.1k
Position Summary Financial Services Manager - Financial Risk Our Deloitte Regulatory, Risk & Forensic team helps client leaders... ...).Capital Management / Stress Testing: Capital planning and enterprise stress testing execution (e.g., scenario design support, model...Work at officeVisa sponsorship$110.7k - $218.3k
...Summary Financial Services Senior Consultant - Financial Risk Our Deloitte Regulatory, Risk & Forensic team helps client... ...governance).Capital Management / Stress Testing: Capital planning and enterprise stress testing execution (e.g., scenario design support, model...Work at officeVisa sponsorship- ...CORP (C2C), CONTRACT-TO-HIRE (CTH), OR THIRD PARTIES. About the Opportunity Our client is expanding its enterprise AI capabilities and is seeking an AI Governance & Risk Specialist to help create the processes, oversight, and controls that support responsible AI adoption....Contract work
- Fox Rothschild LLP's Knowledge Management Department seeks a Risk Mitigation Analyst to conduct hands-on public records and investigative research supporting client engagements and internal risk management. You will verify identities, synthesize findings into clear reports...
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Enterprise Risk Analyst. Be the first to apply!
Related searches

