IT Enterprise Risk Analyst
Holland & Knight
We are a Firm where people truly believe in what they do and strive to achieve the highest standards of performance and success.
This position is based in the Firm's global operations center in Tampa, FL.General Description: We are seeking an IT Enterprise Risk Analyst to join our team. The IT Risk Analyst helps manage the Firm's GRC and IT risk programs, focusing on information security for client data, attorney work, and privileged communications. Reporting to the IT Enterprise Risk Management Manager, the role maintains policies, assesses risks and controls, coordinates third-party reviews, drafts responses for client guidelines, prepares evidence for cyber insurance, and supports audits. Responsibilities align with ISO/IEC 27001/27002, NIST CSF, CIS Controls, SOC 2, HIPAA, GLBA, GDPR, and state privacy laws (e.g., CCPA/CPRA). Key Responsibilities and Essential Job Functions:
- Policy, Standards and Governance
- Support the development, review, and maintenance of information security and technology risk policies, standards, procedures, and guidance documents.
- Maintain the policy lifecycle process, including stakeholder reviews, approvals, publication, periodic review schedules, and version control.
- Map policies/standards to ISO, NIST, CIS Controls, SOC 2, HIPAA, GLBA, U.S. state privacy laws, and EU requirements, and to applicable client Outside Counsel Guidelines and contractual security addenda; maintain crosswalks and control documentation to support audit readiness.
- Administer policy exception and risk acceptance of workflows, ensuring justification, compensating controls, approvals, and defined expiration/renewal dates.
- Contribute to awareness materials and operational guidance to promote consistent implementation of requirements.
- Help maintain controls supporting ethical walls / information barriers, matter-level access restrictions, and legal hold obligations, under the direction of the Senior Analyst and in partnership with the Office of the General Counsel, Conflicts, and Records & Information Governance.
- Maintain awareness of the Firm's professional responsibility obligations, including ABA Model Rules 1.1 (technology competence) and 1.6 (confidentiality of information), and apply that awareness to policy implementation and control activities.
- Information Security and Technology Risk Management
- Conduct or facilitate risk assessments for applications, infrastructure, cloud services, Firm-critical legal-industry platforms (document management, time and billing, conflicts and new business intake, eDiscovery, and matter management), and key business processes; document risk statements, likelihood/impact, and control effectiveness.
- Maintain and update the risk register, including inherent and residual ratings, treatment plans, owners, milestones, and status updates.
- Partner with control owners to identify remediation actions, track progress, and validate closure with appropriate evidence.
- Support ongoing risk monitoring through key risk indicators (KRIs) and control health metrics, including indicators relevant to the legal sector (e.g., business email compromise and wire-fraud schemes, ransomware targeting law firms, and client-confidential data exposure).
- Draft and contribute to risk reporting and summaries for governance forums under the direction of the IT Enterprise Risk Management Manager, including content packaged for Firm leadership and Firm Management Committee audiences.
- Support incident response activities by gathering control and risk evidence, contributing to post-incident lessons learned, and helping ensure resulting control improvements are tracked in the risk register.
- Vendor/Third Party Risk Management (TPRM)
- Perform third party security due diligence based on vendor criticality and risk tiering (including third-industry parties such as co-counsel and local counsel, eDiscovery and document review providers, expert witnesses, court reporters and translators, legal-technology SaaS vendors, and managed-service providers handling client matter data); coordinate security questionnaires and evidence collection.
- Review assurance artifacts such as SOC reports, ISO certificates, penetration test summaries, security whitepapers, and privacy/security attestations.
- Identify gaps, document findings, recommend remediation/compensating controls, and track vendor action plans to closure.
- Partner with Procurement/Legal to ensure contracts include appropriate security and privacy requirements (e.g., breach notification, subcontractor controls, right-to-assess, data processing terms, and data residency as applicable).
- Support periodic vendor reassessments and reassessments triggered by scope changes, incidents, or material updates.
- Draft initial responses to inbound client security questionnaires and Outside Counsel Guideline (OCG) inquiries for Senior Analyst review; help maintain a controlled answer library and partner with the engagement attorney and Loss Prevention on follow-ups.
- Audit, Assurance and Compliance (ISO / NIST / CIS / SOC 2 / HIPAA / GLBA / EU)
- Support internal and external audits by coordinating evidence collection, control walkthroughs, and timely responses to audit requests.
- Assist with gap assessments and control testing against ISO 27001/27002, NIST CSF / SP 800-53 / 800-171, CIS Controls, SOC 2 Trust Services Criteria, GLBA Safeguards Rule, and HIPAA requirements.
- Support EU-aligned compliance activities where applicable (e.g., GDPR security measures and accountability documentation; NIS2-aligned operational practices).
- Track audit findings, corrective action plans (CAPs), and management responses; monitor remediation progress and validate closure evidence.
- Maintain audit artifacts including control matrices, evidence inventories, and standardized templates to improve repeatability and audit readiness.
- Support control activities related to handling Controlled Unclassified Information (CUI) and other regulated client data for the Firm's federal, defense, aerospace, and government-contracts practices, including evidence gathering and documentation aligned with NIST SP 800-171, CMMC Level 2 readiness, and ITAR/EAR data-handling requirements, under the direction of the Senior Analyst.
- Help compile control attestations and evidence packages for the Firm's annual cyber insurance application and renewal cycle, supporting responses to underwriter and broker inquiries under senior oversight.
- Expected to maintain a regular and predictable work schedule and full attention to and engagement in work activities on behalf of the firm during business hours unless otherwise approved or required by applicable law.
- Special projects and duties as assigned.
- Strong written and verbal communication skills; ability to translate control requirements into clear documentation and actionable guidance.
- Strong organizational skills and attention to detail.
- Ability to manage multiple priorities and deadlines.
- Knowledge or ability to learn Microsoft Office Suite, or Microsoft 365.
- Bachelor's degree in information security, Information Technology, Risk Management, Business, or equivalent practical experience.
- 3+ years of experience in GRC, information security, technology risk management, compliance, internal audit, or third-party risk management.
- Working knowledge of ISO/IEC 27000 Family concepts, NIST CSF/SP 800-53/800-171, and HIPAA.
- Familiarity with EU information security and privacy requirements (e.g., GDPR security principles); familiarity with NIS2 is a plus where relevant.
- Experience collecting, organizing, and validating control evidence and supporting audits/assessments.
- Certifications - ISACA: CRISC (Certified in Risk and Information Systems Control) and/or CISA (Certified Information Systems Auditor).
- Prior exposure to GRC, IT risk, or information security work in a law firm, professional services firm, or other client-confidential environment is preferred.
- Familiarity with legal-industry technology (document management such as iManage or NetDocuments; time and billing such as 3E or Aderant; conflicts and new business intake such as Intapp; eDiscovery platforms such as Relativity) and with the data-sensitivity considerations they raise is a plus.
- Awareness of the ABA Model Rules of Professional Conduct (in particular Rules 1.1 and 1.6) and applicable state bar requirements relating to technology competence and client confidentiality is preferred.
- Familiarity with Controlled Unclassified Information (CUI) handling, NIST SP 800-171, CMMC, and ITAR/EAR data-handling concepts; prior exposure to federal, defense, or government-contracts client matters is a plus.
- Certifications -
- ISACA: COBIT Foundation, CDPSE, or CGEIT as applicable to governance, privacy, and enterprise risk responsibilities ISO/IEC 27001 Internal Auditor, Lead Implementer, or Lead Auditor.
- Cloud and platform risk certifications such as Microsoft Certified: Security, Compliance, and Identity Fundamentals (SC-900), Azure Security Engineer Associate (AZ-500), or similar.
- Ability to sit or stand for extended periods of time.
- Moderate or advanced keyboard usage.
Vacancy posted 3 days ago
Similar jobs that could be interesting for youBased on the IT Enterprise Risk Analyst in Tampa, FL vacancy
- Citigroup Inc. is seeking an Assistant Vice President Data Analyst in Tampa, to leverage data for Enterprise Risk Management. The role focuses on implementing advanced AI/ML solutions, developing data governance frameworks, and mentoring junior analysts. Ideal candidates...Suggested
- A financial services firm is seeking a Cybersecurity Risk Analyst. This position focuses on assessing risks across applications, infrastructure, and vendors. Ideal candidates will have 5+ years of risk assessment experience and a strong understanding of Information Risk...Suggested
- ...Cybersecurity Risk Analyst We are seeking a Cybersecurity Risk Analyst to join our Information... ...evaluating cybersecurity risks within enterprise environments. Candidates with a... ...and technology systems, partnering with IT and business units to communicate risks...Suggested
- ...scripts. Job Summary/Basic Function: Technology Risk Management Core Automation drives operational efficiencies within... ...tool. Principal Responsibilities: Understand cyber and IT best practices including knowledge of frameworks, guidelines, and...Suggested
- Sr IT Governance Risk and Controls Analyst Join to apply for the Sr IT Governance Risk and Controls Analyst role at Refresco Get AI-powered advice on this job and more exclusive features. Our vision is both simple and ambitious: to put our drinks on every table. We are...SuggestedFull timeTemporary workWork experience placementLocal areaWorldwideFlexible hours
- ...Compliance And Operations Risk Test Specialist Elevate your career by joining our team, where your analytical skills will drive impactful results in compliance and risk management. As a Compliance and Operations Risk Test Specialist in the Testing Center of Excellence...
- A leading financial services firm in Tampa is seeking a Risk and Controls Testing Associate to execute independent risk-based evaluations. Candidates should have over 3 years of experience in risk management, strong analytical skills, and proficiency in Microsoft Office...Work at office
- A leading restaurant company in Tampa, Florida is looking for a Claims Risk Analyst to provide operational and analytical support to the workers' compensation and general liability programs. You will assist with claims data reporting, support OSHA recordkeeping, and help...
- A reputable insurance company in Tampa, FL is seeking a Risk Analyst to collaborate with internal teams and analyze risk portfolios. This role requires strong analytical abilities, communication skills, and proficiency in tools like SQL and Excel. Candidates should possess...
- ...Senior Information Risk Consultant - Information Security Dallas, Texas, United States About the Job Job Title: Senior Information Risk Consultant - Information Security Location: Dallas, TX or Tampa, FL Experience Level: Mid-Senior (7+ years) Job Type: Contract...Contract workRelocationVisa sponsorship
- ...Third-Party Risk Management Senior Analyst (MRA Remediation Support) - VP Level New York City, NY or Tampa, FL (Hybrid) 6-12 Months Contract... ...excellent relationship with Markets Business Activity Owners, Enterprise Third Party Management, Operational Risk Management and...Contract work
- A financial services company based in Tampa, Florida, is looking for an experienced Data Analytics professional to join their Risk Management team. This role focuses on advancing risk management through data warehousing and analysis. The ideal candidate will have at least...
$87.8k - $160.9k
...St Louis, Tampa The opportunity The objective of our consulting risk services is to provide clients with a candid and reliable overview... ...across the organization. This role involves working closely with IT, security teams, and business units to ensure that our cyber risk...Contract workSummer holidayWork at officeFlexible hours$80.46k - $142.72k
A leading global consultancy is seeking a GIS Senior Analyst in Tampa, Florida. The role focuses on data management and execution of GIS projects using Esri software, including database management and development of analytical tools. Ideal candidates will have a Bachelor...Flexible hours- ...onboarding process.” Job Title: Enterprise Analyst Contract Length: 12+ Month contract... ...Analyst will work as part of a team to reduce risk, improve application governance, and... ...experience Preferred Skills ~3rd-level IT escalation support, including networking...Contract workVisa sponsorship
- ...governance, enforcement, and continuous improvement of the enterprise Citizen Development program. This position establishes and enforces... ...not meet established standards, and to escalate unresolved risks through IT governance and risk management forums. What will you do?...Flexible hours
- ...Enterprise Contract Analyst Position Highlights: The Enterprise Contract Analyst is responsible for market research, solicitation, negotiation... ...and costs with vendors to maximize value, mitigate risk, and streamline administration. This position will manage...Ongoing contractContract workLocal area
$70 - $75 per hour
...from Mindlance Subject Matter Expert - Recruitment, Banking & Financial Services | President Club Winner Job Title: Business Analyst - Payments Risk Transformation Program Location: New York, NY /Tampa, FL (Hybrid) Duration: 12+ Months (Possibility of Extension) Job...Contract work- ...seeking a GRC e-Discovery Specialist to support governance, risk, and compliance (GRC) operations by identifying,... ...regulatory matters. Partner with Legal, Risk, Privacy, enterprise Data Management and IT teams on discovery, audit, regulatory inquiries, compliance...
- ...Business Risk Officer/Issues Management Support Analyst 6+ Months Tampa, FL (Hybrid- 3 Days Onsite) $50/Hr on W2 Responsibilities: Designing, developing, delivering and maintaining best-in-class Compliance Issues Management programs, policies and practices...Flexible hours
$96.57k - $130.65k
...Yes Job Description: DATA ANALYST YOUR IMPACT Own your... ...and connected across the global enterprise-directly, contributing to a mission... ...that support mission critical IT services. KEY... ...Analyze data to identify trends, risks, lifecycle status, technical debt...Temporary workImmediate startWorldwideFlexible hours- ...Data Analyst Rootshell Enterprise Technologies Inc. is a recognized provider of professional IT Consulting services in the US. We are actively seeking a Data Analyst for one of our direct client in Tampa, Florida. Please share your resume with current location and full...Local area
- ...Data Analyst Join Fintech in Tampa, Florida as a Data Analyst! We're looking for a detail-driven Data Analyst to join our Data Governance... ...& Quality team. In this role, you'll be the guardian of our enterprise data, ensuring it's accurate, consistent, and high-quality....Temporary workCasual workLocal area
$31.44 - $43.26 per hour
...collaboration tools. Over 80 of the Fortune 100, 10,000 large enterprises, and millions of smaller organizations trust Proofpoint to stop... ...company protecting organizations’ greatest assets and biggest risks: vulnerabilities in people. With an integrated suite of cloud-based...Flexible hours- ...Texas, Utah, Virginia, or Wyoming. The Clinical Applications Analyst II - Prelude advances Moffitt's mission to prevent and cure... ...to the design, implementation, and support of clinical and enterprise applications that improve patient care, research, and operational...Remote work
- ...Position: Data Analyst Location: Tampa ,FL ( hybrid with 3 days onsite per week) Job Requirements Data Analyst with strong... ...closely with data science and business teams in large scale enterprise environments. Domain Retail (catalog, order, pricing,...Flexible hours3 days per week
- ...Business Analytics And Recognition Data Analyst We are a Firm where people truly believe... ...leadership and in partnership with the Enterprise Project Management Office (EPMO) as well... ...Knowledge Management, Finance, Human Resources, IT, and Innovation teams to promote...Temporary workWork at office
$147.29k - $199.28k
...Description: TECH REFRESH DATA ANALYST YOUR IMPACT Own your... ...and connected across the global enterprise directly, contributing to a... ...priorities. Your work strengthens IT reliability, reduces technical... ...standings, site progress, and risk indicators to support planning...Temporary workImmediate startWorldwideFlexible hours- ...Summary Position Highlights: The Patient Experience Analyst will develop analytic strategies to assess and trend the... ...and planning and designing reports and dashboards that provide enterprise leaders with key data to measure and improve the patient experience...
- ...Senior Data Analyst Senior Data Analyst with 5+ years of experience working in an enterprise data and analytics environment. Strong data mapping experience. Experience with reference data management or master data management. Experience mapping data into an enterprise...
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to IT Enterprise Risk Analyst. Be the first to apply!
Related searches


