Job Description
The IT Risk Management Senior Analyst will help design, implement, and mature our enterprise cybersecurity and technology risk program. This role is ideal for a risk professional who has built risk programs-not just operated them-and who can translate complex technical risks into clear, prioritized, and measurable risk decisions for leaders.
You will lead the development of our risk tolerance and thresholds, establish and manage a central risk register, and build a repeatable risk management lifecycle and supporting processes. You will partner across Cybersecurity, Physical Security, IT, Privacy, and business teams to ensure risks are identified, assessed, tracked, mitigated, and reported with consistency and transparency.
We are a company committed to creating diverse and inclusive environments where people can bring their full, authentic selves to work every day. We are an equal opportunity/affirmative action employer that believes everyone matters. Qualified candidates will receive consideration for employment regardless of their race, color, ethnicity, religion, sex (including pregnancy), sexual orientation, gender identity and expression, marital status, national origin, ancestry, genetic factors, age, disability, protected veteran status, military or uniformed service member status, or any other status or characteristic protected by applicable laws, regulations, and ordinances. If you need assistance and/or a reasonable accommodation due to a disability during the application or recruiting process, please send a request to [email protected] learn more about how we collect, keep, and process your private information, please review Insight Global's Workforce Privacy Policy: https://insightglobal.com/workforce-privacy-policy/.
Skills and Requirements
10 +years of experience in cybersecurity risk management, technology risk, GRC, or operational risk.
Demonstrated experience setting risk tolerance and thresholds and translating them into practical decision rules.
Proven track record of building and operating a risk register.
Experience creating or maturing a risk management lifecycle and supporting processes
Strong understanding of cybersecurity concepts (controls, threats, vulnerabilities, cloud risk, identity, incident risk, third-party risk).
Excellent written and verbal communication: ability to deliver clear, executive-ready risk narratives and recommendations.
Experience with GRC tools (e.g., ServiceNow GRC, Archer, OneTrust, LogicGate, MetricStream) or comparable workflow systems.
Compensation: $70-$75 Exact compensation may vary based on several factors, including skills, experience, and education. Benefit packages for this role will start on the 31st day of employment and include medical, dental, and vision insurance, as well as HSA, FSA, and DCFSA account options, and 401k retirement account access with employer matching. Employees in this role are also entitled to paid sick leave and/or other paid time off as provided by applicable law