IT 风险管理分析师
IT Risk Management Analyst
IT风险管理人员在确保组织的IT系统和基础设施的安全性、合规性和韧性方面发挥着关键作用。该职位涉及识别、评估和缓解可能影响数字资产保密性、完整性和可用性的潜在风险和漏洞。IT风险管理人员与各团队合作,实施有效的风险管理策略,确保组织保持稳健安全的IT环境。
主要职责与工作内容:
风险评估:
- 识别并评估潜在的IT风险,包括网络安全威胁、漏洞和合规差距。
- 进行风险评估,以评估已识别风险的潜在影响和发生可能性。
- 分析和解释与IT安全事件、泄露和漏洞相关的数据。
风险缓解:
- 制定并实施风险缓解计划,以应对已识别的漏洞和威胁。
- 与IT和安全团队合作,设计并实施控制措施,降低组织面临的风险暴露。
- 跟踪新兴安全威胁和行业最佳实践,以提高风险缓解策略的有效性。
合规与监管:
- 监控并确保符合相关IT法规、标准和框架(例如GDPR、FERPA、FFIEC、HIPAA、NIST、ISO 27001)。
- 协助制定和维护IT政策、流程和指南,以确保符合合规要求。
安全事件响应:
- 参与事件响应活动,提供在分析和缓解安全事件方面的专业知识。
- 与事件响应团队合作,调查和修复安全泄露或漏洞。
风险报告与沟通:
- 准备并向管理层和相关利益相关者汇报IT风险、漏洞和缓解措施。
- 有效地向非技术人员传达复杂的概念。
安全意识与培训:
- 协助开发和实施IT安全意识计划,教育员工了解安全最佳实践。
- 为员工提供关于风险管理流程和政策的指导和培训。
持续改进:
- 识别流程改进的领域,并推荐解决方案以提升整体IT风险管理计划。
- 参与评估和优化现有的风险管理流程。
查看英文原文
The IT Risk Management Analyst plays a critical role in ensuring the security, compliance, and resilience of an organization's IT systems and infrastructure. This role involves identifying, assessing, and mitigating potential risks and vulnerabilities that could impact the confidentiality, integrity, and availability of digital assets. The IT Risk Management Analyst collaborates with various teams to implement effective risk management strategies and ensure that the organization maintains a robust and secure IT environment.Essential Duties & Responsibilities:
Risk Assessment:
- Identify and assess potential IT risks, including cybersecurity threats, vulnerabilities, and compliance gaps.
- Conduct risk assessments to evaluate the potential impact and likelihood of identified risks.
- Analyze and interpret data related to IT security incidents, breaches, and vulnerabilities.
Risk Mitigation:
- Develop and implement risk mitigation plans to address identified vulnerabilities and threats.
- Collaborate with IT and security teams to design and implement controls to reduce the organization's exposure to risks.
- Stay up-to-date with emerging security threats and industry best practices to enhance the effectiveness of risk mitigation strategies.
Compliance and Regulation:
- Monitor and ensure compliance with relevant IT regulations, standards, and frameworks (e.g., GDPR, FERPA, FFIEC, HIPAA, NIST, ISO 27001).
- Assist in the development and maintenance of IT policies, procedures, and guidelines to ensure adherence to compliance requirements.
Security Incident Response:
- Participate in incident response activities, providing expertise in analyzing and mitigating security incidents.
- Collaborate with incident response teams to investigate and remediate security breaches or vulnerabilities.
Risk Reporting and Communication:
- Prepare and present reports on IT risks, vulnerabilities, and mitigation efforts to management and relevant stakeholders.
- Communicate complex technical concepts to non-technical audiences effectively.
Security Awareness and Training:
- Assist in developing and delivering IT security awareness programs to educate employees about security best practices.
- Provide guidance and training to employees regarding risk management procedures and policies.
Continuous Improvement:
- Identify areas for process improvements and recommend solutions to enhance the overall IT risk management program.
- Participate in the evaluation and implementation of new technologies and tools to enhance risk assessment and mitigation capabilities.
Job Skills:
- Understanding of IT risk management principles, cybersecurity concepts, and industry standards.
- Proficiency in risk assessment methodologies, vulnerability assessment tools, and security frameworks.
- Excellent analytical and problem-solving skills, with the ability to assess complex situations and provide practical solutions.
- Effective communication skills to convey technical information clearly to both technical and non-technical stakeholders.
- Collaborative attitude with the ability to work across different teams and departments.
- Experience with security incident response and familiarity with security tools and technologies.
Work Experience:
· 3 to 5 years in a similar role.
Education:
· Bachelor's degree in Information Technology, Cybersecurity, Business, or a related field required.
Certificates, licenses and registrations:
· Preference: Professional certifications such as Certified Information Systems Security Professional (CISSP), Certified in Risk and Information Systems Control (CRISC) Certified Information Security Manager (CISM), or Certified Information Systems Auditor (CISA) are advantageous.
Other:
- Must be able to travel occasionally should a business need arise. For most roles travel would not be common. Travel may involve plane, car or metro. In accordance with ADA policies, reasonable accommodation regarding travel limitations can be provided. Travel will be more common for roles such as Account Executives (25 - 50%), senior leaders (10 – 20%) or Capella Core Faculty (5 – 10%).
- Ability to work onsite in Corporate or Campus location (in a typical office environment) may be required based on role. If so, this would include being mobile within the office, including movement from floor-to-floor using elevators or stairs.
- If offsite or hybrid role, must have access to work in setting which enables meeting all requirements of the role (including privacy, reliable internet access, phone, ability to video conference, etc.) at a remote location.
- Faculty and Federal Work Study roles require access to work in setting which enables meeting all requirements of the role (including computer, privacy, reliable internet access, phone, ability to video conference, etc.) at a remote location.
- This role may require lifting, however reasonable accommodations will be provided in accordance with our ADA policies.
- Must be able to meet critical thinking and problem solving aspects aligned to job duties, as well as effectively communicating with co-workers.
- Must be able to work more than 40 hours per week when business needs warrant. Accommodations related to schedule may be considered.
- Able to access information using a computer.
- Other essential functions and marginal job functions are subject to modification.
SEI offers a comprehensive package of benefits to employees scheduled 30 hours or more per week. In addition to medical, dental, vision, life and disability plans, SEI employees may take advantage of well-being incentives, parental leave, paid time off, certain paid holidays, tax saving accounts (FSA, HSA), 401(k) retirement benefit, Employee Stock Purchase Plan, tuition assistance as well as entertainment and retail discounts. Non-exempt employees are eligible for overtime pay, if applicable.
Careers - Our Benefits, Strategic Education, Inc
SEI is an equal opportunity employer committed to fostering an inclusive and collaborative culture where individuals can grow their careers and contribute fully. We strive to attract talent with broad experiences, skills and perspectives. We welcome applications from all. While it is not typical for an individual to be hired at or near the top end of the pay range at SEI, we offer a competitive salary. The actual base pay offered to the successful candidate may vary depending on multiple factors including, but not limited to, job-related knowledge/skills, experience, business needs, geographical location, and internal pay equity. Our Talent Acquisition Team is ready to discuss your interest in joining SEI. The expected salary range for this position is below.
$75,800.00 - $113,700.00 - SalaryIf you require reasonable accommodations to complete our application process, please contact our Human Resources Department at .
Originally posted on Himalayas