Information Governance Risk and Compliance Analyst

Fried Frank Attorney Opportunities

$110K — $125K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in a relevant field.
  • 3-5 years of hands-on experience in IG, compliance, IT audit, or information security.
  • Experience running control tests or performing access reviews.
  • Certifications in IT audit (e.g., CISA) or Microsoft security and compliance (e.g., SC-400, SC-200) are a plus.
  • Proficiency in PowerShell and KQL for querying audit logs.

Responsibilities

  • Develop IG policies and procedures, translating them into technical controls.
  • Maintain an auditable inventory of data assets in Microsoft 365.
  • Contribute to risk assessments and quantify exposure from data vulnerabilities.
  • Implement compliance controls for client contractual obligations and regulations.
  • Plan and execute recurring control audits across multiple platforms.
  • Collect evidence programmatically to demonstrate control effectiveness.
  • Communicate findings to both technical and non-technical stakeholders.

Benefits

  • Opportunity to work with Microsoft 365 and advanced security tools.
  • Engagement in a dynamic audit and compliance environment.
  • Collaboration with legal and procurement teams.
  • Flexibility in tracking and mitigating enterprise risks.
  • Potential growth in a mid-level IT governance and security position.
Full Job Description
Position Summary:

As an Information Governance (IG), Risk, and Compliance Analyst, you will test, evidence, and report on the controls behind the firm's IG, risk, compliance, and information security programs. You will run recurring control audits, build the queries and scripts that generate the evidence, and produce the artifacts relied upon in client audits and internal assurance work.

Duties & Responsibilities:

Information Governance:
  • DevelopIG policies and procedures, and translate them into enforceable technical configurations and measurable controls.
  • Maintain an auditable inventory of data assets across Microsoft 365 and other approved information repositories, capturing classification, ownership, location, and retention state.

Risk Management:
  • Contribute to enterprise-wide risk assessments, quantifying exposure from overprovisioned access, stale data, and sensitive data sprawl from platform reporting rather than self-attestation.
  • Develop risk mitigation strategies and control requirements, and track findings and remediation to verified closure.

Compliance:
  • Support compliance with client contractual obligations (including outside counsel guidelines), regulations, and data protection laws by implementing and evidencing the corresponding controls.
  • Serve as technical respondent for client audits, security questionnaires, and regulatory inquiries, mapping requests to implemented controls and assembling the evidence; familiarity with control frameworks (ISO, SOC 2, NIST) helps, though the emphasis is technical testing over certification work.

Audit, Control Testing, and Evidence Collection:
  • Plan and execute recurring control audits across Microsoft 365, Entra ID, Active Directory, and approved information repositories, and maintain the audit calendar, evidence library, and exception record.
  • Collect evidence programmatically with PowerShell, Microsoft Graph, and KQL, querying audit trails across identity, mail, file, and endpoint platforms to show a control operated over a defined period.
  • Perform entitlement reviews and access recertification covering nested group membership, privileged roles, service and shared accounts, dormant objects, and broadly permissioned repositories.
  • Test control effectiveness rather than assuming it, validating classification and DLP detection, retention and disposition execution, and alerting coverage.

Information Security:
  • Oversee of the information security program, including periodic review of security tooling configuration against approved baselines and hardening against exfiltration and insider risk.
  • Perform incident response and recovery tasks, including log review, containment and scoping queries, evidence preservation, and post-incident remediation tracking.

Vendor and Third-Party Management:
  • Assess third-party vendor risk in data handling, reviewing questionnaires, audit reports, and penetration test summaries against observable configuration.
  • Collaborate with procurement and legal teams on contractual security, audit rights, and data handling requirements.

Reporting and Communication:
  • Communicate risk, compliance, and security findings to technical and non-technical stakeholders, and maintain recurring reporting on control testing and access review results.

Education:
  • Bachelor's degree in a relevant field; certifications in IT audit (e.g., CISA), Microsoft security and compliance administration (e.g., SC-400, SC-200), or in risk management are a plus.

Experience:
  • Mid-level position; 3-5 years of hands-on experience in IG, compliance, IT audit, or information security, including demonstrable work running control tests or access reviews.

Skills & Abilities:
  • Strong analytical, problem-solving, and communication skills, with working proficiency in PowerShell and KQL and experience querying platform audit logs.
  • Practical familiarity with Microsoft 365, Entra ID, Active Directory, and permissions models across approved information repositories, plus audit logging on those platforms and the ability to collaborate cross-functionally.


The actual salary offered will be based on a number of factors including but not limited to the qualifications of the applicant, years of relevant experience, level of education attained, certifications or other professional licenses held, and if applicable, the location in which the applicant lives and/or from which they will be performing the job.

New York Salary Range

$110,000-$125,000 USD

Similar Jobs

More Jobs at Fried Frank Attorney Opportunities

More Information Technology Jobs

Find similar Information Governance Risk and Compliance Analyst jobs: