Fisher Investments

Information Security Risk Analyst

Fisher Investments$80K — $130K *
Camas, WA 98607In-Person
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in computer science, Information Security, or related field.
  • 3+ years in Enterprise Risk Management for Digital Assets, including risk evaluation and vendor research.
  • 1+ year of experience in Digital Asset audit reviews (SOC 2 Type II, SOX, PCI compliance).
  • Familiarity with risk and security standards like NIST 800-53 and CIS benchmarks.
  • Experience in cloud-based risk assessments and control implementations.

Responsibilities

  • Represent Information Security in Enterprise Risk Management technology reviews.
  • Collaborate with experts to assess the effectiveness of Digital Asset controls.
  • Research new technical and practical risk controls for Digital Assets.
  • Perform risk and gap assessments for IT infrastructure and services.
  • Identify and document security risks and appropriate controls.
  • Assist in maturing Enterprise Risk Management procedures for Digital Assets.
  • Translate technical risk management information for business stakeholders.

Benefits

  • 100% paid medical, dental, and vision premiums for you and your dependents.
  • 50% 401(k) match up to the IRS maximum.
  • 20 days of PTO plus 10 paid holidays.
  • Family support programs including paid caregiver leave and fertility assistance.
  • Opportunity to participate in a hybrid work-from-home program based on eligibility.
Full Job Description
Overview

The Opportunity:

The Information Security Risk Analyst, reporting to the Vice President - Information Security, will work with Information Security, Technology, Project, and Enterprise Risk Management teams to perform technology risk analysis and recommend controls. You will also develop, recommend, and implement technology risk practices following Fisher Investments Digital Asset risk management goals.

The Day-to-Day:
  • Represent Information Security in Enterprise Risk Management technology reviews for Digital Assets, including evaluation of inherent risk, researching vendor practices and controls, recommending new practices and controls, and estimating residual risk
  • Continuously collaborate with Information Security, Technology, and Data Privacy Subject Matter Experts to determine efficacy of technical and practical Digital Asset controls
  • Research new possible technical and practical Digital Asset risk controls
  • Perform security-focused risk and gap assessments to identify, document and track security risks associated with Cloud and physical IT infrastructure and services, Applications, Information systems, and Vendors/other third parties
  • Identify risk levels and associated controls to manage risk levels applying both quantitative and qualitative techniques
  • Assist in continuously maturing Enterprise Risk Management evaluation procedures for Digital Assets
  • Translate risk management information from technical to business language
  • Provide security risk services to business owners and partners
  • Work with project teams to collect and document evidence of cyber control implementation
  • Understand and maintain a broad knowledge of methodologies and technologies in risk assessments and controls measures

Your Qualifications:
  • Bachelor's degree in computer science, Information Security, or related discipline or equivalent experience
  • 3+ years of experience in Enterprise Risk Management for Digital Assets, including development of risk evaluation processes, control evaluations and recommendations, and vendor research
  • 1+ years of experience in Digital Asset audit review experience (including SOC 2 Type II, SOX compliance, PCI compliance, vulnerability reports, retention policies)
  • Knowledge of Information Security and risk standards and frameworks such as NIST 800-53, CIS benchmarks, OWASP, ISO-27001, ITIL and COSO
  • Experience assessing risk or implementing controls in a cloud-based enterprise environment
  • Extensive knowledge of information systems, risk assessment methodologies and security control technologies such as Okta, EntraID, Splunk, and Netskope
  • Balance risks in ambiguous and complex scenarios
  • Team-oriented, highly collaborative, experienced leading initiatives
  • Experience in GRC platforms
  • Deliver quality as part of a Scrum team working in an Agile environment
  • Preference given to experience in a regulated industry: Finance, Healthcare, etc.

Compensation:
  • $80,200 - $130,000 base salary per year in the state of WA. New hires should expect to start at the lower end of the range depending on experience
  • Eligible for a discretionary bonus based on firm and individual performance

Why Fisher Investments:

We work for a bigger purpose: bettering the investment universe. We take great pride in our inclusive culture, our learning and development framework customized for every employee, and our Great Place to Work Certification. It's the people that make the Fisher purpose possible, and we invest in them by offering exceptional benefits like:
  • 100% paid medical, dental and vision premiums for you and your qualifying dependents
  • A 50% 401(k) match, up to the IRS maximum
  • 20 days of PTO, plus 10 paid holidays
  • Family Support programs including 8 week Paid Primary Caregiver Leave, $10,000 fertility, family forming, and hormonal health assistance, and back-up child, adult, and elder care
  • This is an in-office role. Based on your role, tenure, and performance eligibility you may have the opportunity to participate in our hybrid work from home program. This program is subject to change.

About Fisher Investments

Fisher Investments is a privately owned investment management firm founded in 1979 by Ken Fisher. The company is headquartered in Camas, Washington, and has offices in the United States, Europe, and Asia. Fisher Investments manages assets for individuals and institutions, including pension plans, endowments, and foundations. The company is known for its investment philosophy, which emphasizes a global perspective and a focus on long-term growth. Fisher Investments has been recognized for its performance and has won numerous awards for its investment strategies.
Learn more about Fisher Investments
Size
3,500 employees
Industry
Founded
1979

Similar Jobs

More Jobs at Fisher Investments

More Information Technology Jobs

Find similar Information Security Risk Analyst jobs: