The Information Security Analyst - GRC supports the firm's information security compliance program, including audit readiness, policy governance, risk tracking, control reviews, security metrics, and compliance documentation. The role also participates in the Information Security on-call rotation and assists with first-level security event triage using established procedures.
We welcome candidates with experience in cybersecurity, compliance, audit, project coordination, governance, or operational risk who demonstrate strong organizational skills and an interest in developing expertise in information security compliance.
Responsibilities: Governance, Risk & Compliance - Support the firm's information security compliance program.
- Coordinate audit preparation and maintain supporting evidence.
- Maintain policies, standards, procedures, and ISMS documentation.
- Perform recurring control reviews and compliance checks.
- Track risks, exceptions, findings, and remediation activities.
- Prepare security metrics, dashboards, and compliance reporting.
- Administer the firm's security awareness training and phishing simulation program, including campaign scheduling, reporting, and compliance tracking.
- Support ISO 27001 activities and future compliance initiatives.
Security Operations Support - Participate in the Information Security on-call rotation.
- Review and triage low-complexity security alerts.
- Escalate suspicious activity according to documented procedures.
- Assist with incident documentation and follow-up activities.
- Training will be provided on firm-specific security tools and processes.
Project & Process Coordination - Coordinate security projects and recurring compliance activities.
- Track action items, deliverables, and remediation plans.
- Facilitate communication between technical and business teams.
- Identify opportunities to improve processes and documentation.
Qualifications: - Bachelor's degree or equivalent professional experience.
- 3-5 years of experience in information security, compliance, audit, project coordination, governance, operational risk, or related discipline.
- Strong organizational and documentation skills.
- Experience managing multiple priorities and deadlines.
- Strong written and verbal communication skills.
- Proficiency with Microsoft 365.
- Ability to function in a fast-paced, service-oriented environment, prioritize multiple projects on a daily basis, and adjust to shifting priorities.
- Strong planning, project management and organizational skills.
- Strong sense of urgency.
- Facility analyzing, working with and presenting data.
- Ability to collaborate and gain the respect, trust, and confidence of the Firm's attorneys and professional staff.
- Creative and proactive approach to problem solving.
- Facilitate teamwork and identify opportunities to develop new processes/infrastructure.
- Demonstrated ability to grasp and implement new concepts quickly.
- Strong analytical abilities, resourcefulness, and attention to detail.
- Ability to work independently and as part of a team with a proactive and positive style that fosters collaborative working relationships.
- Outstanding sense of customer service.
- Deep personal commitment to integrity, excellent judgment, and the highest standards of ethics.
- Must display the highest level of diplomacy, tact and discretion, with comfort in handling and maintaining confidential information
Preferred Qualifications: - Experience supporting employee training, awareness, compliance, or change management programs.
- Experience supporting compliance, audit, or risk management programs.
- Exposure to frameworks such as ISO 27001, NIST, SOC 2, or HIPAA.
- Experience preparing reports, dashboards, or metrics.
- Experience working in a regulated or professional services environment.
The Ideal Candidate: The successful candidate is:
- Organized and detail-oriented.
- Naturally curious and eager to learn.
- Comfortable coordinating across multiple teams.
- Strong at managing processes and following through on commitments.
- Interested in building a career in cybersecurity governance, risk, and compliance.
Professional Development: The firm supports professional development and encourages pursuit of certifications such as:
- CISA
- CRISC
- CISM
- Security+
- CGRC
- ISO 27001 Internal Auditor
This job description is a general description of the types of responsibilities that are required of an individual in this job. It is not intended to be a complete list of the responsibilities, duties and skills that may be required for this job.
Physical Demands: This position requires sitting or standing for long periods of time and the continuous operation of standard office equipment, such as computers, keyboards and phones. It also requires mobility sufficient to perform certain job functions, such as getting to photocopiers/scanners/fax machines, and regular bending, reaching, lifting, stooping and occasionally pulling, pushing and/or lifting items that weigh up to 25 pounds.
The salary range for this position in Boston is $85,000-$100,000
This position is bonus eligible. Mintz offers a comprehensive benefits package.
}