Fisher Investments

Information Security Risk Analyst

Fisher Investments$90K — $110K *
Tampa, FL 33647In-Person
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in computer science, Information Security, or related discipline or equivalent experience
  • 3+ years of Enterprise Risk Management experience for Digital Assets including risk evaluation processes
  • 1+ years of Digital Asset audit review experience (e.g., SOC 2 Type II, SOX compliance)
  • Knowledge of information security and risk standards like NIST 800-53, CIS benchmarks
  • Experience in assessing risk or implementing controls in a cloud-based environment
  • Extensive knowledge of risk assessment methodologies and technologies like Okta and Splunk
  • Experience with GRC platforms

Responsibilities

  • Represent Information Security in technology reviews for Digital Assets
  • Collaborate with security and data privacy experts to assess controls
  • Research potential Digital Asset risk controls
  • Perform risk assessments to identify security risks across IT infrastructure
  • Identify risk levels and recommend associated controls
  • Assist in maturing Enterprise Risk Management evaluation procedures
  • Translate technical risk management information into business language

Benefits

  • 100% paid medical, dental and vision premiums for you and your qualifying dependents
  • 50% 401(k) match, up to the IRS maximum
  • 20 days of PTO, plus 10 paid holidays
  • Family support programs including paid caregiver leave and fertility assistance
  • In-office role with potential hybrid work opportunity based on performance
Full Job Description
Overview

The Opportunity:

The Information Security Risk Analyst, reporting to the Vice President - Information Security, will work with Information Security, Technology, Project, and Enterprise Risk Management teams to perform technology risk analysis and recommend controls. You will also develop, recommend, and implement technology risk practices following Fisher Investments Digital Asset risk management goals.

The Day-to-Day:
  • Represent Information Security in Enterprise Risk Management technology reviews for Digital Assets, including evaluation of inherent risk, researching vendor practices and controls, recommending new practices and controls, and estimating residual risk
  • Continuously collaborate with Information Security, Technology, and Data Privacy Subject Matter Experts to determine efficacy of technical and practical Digital Asset controls
  • Research new possible technical and practical Digital Asset risk controls
  • Perform security-focused risk and gap assessments to identify, document and track security risks associated with Cloud and physical IT infrastructure and services, Applications, Information systems, and Vendors/other third parties
  • Identify risk levels and associated controls to manage risk levels applying both quantitative and qualitative techniques
  • Assist in continuously maturing Enterprise Risk Management evaluation procedures for Digital Assets
  • Translate risk management information from technical to business language
  • Provide security risk services to business owners and partners
  • Work with project teams to collect and document evidence of cyber control implementation
  • Understand and maintain a broad knowledge of methodologies and technologies in risk assessments and controls measures

Your Qualifications:
  • Bachelor's degree in computer science, Information Security, or related discipline or equivalent experience
  • 3+ years of experience in Enterprise Risk Management for Digital Assets, including development of risk evaluation processes, control evaluations and recommendations, and vendor research
  • 1+ years of experience in Digital Asset audit review experience (including SOC 2 Type II, SOX compliance, PCI compliance, vulnerability reports, retention policies)
  • Knowledge of Information Security and risk standards and frameworks such as NIST 800-53, CIS benchmarks, OWASP, ISO-27001, ITIL and COSO
  • Experience assessing risk or implementing controls in a cloud-based enterprise environment
  • Extensive knowledge of information systems, risk assessment methodologies and security control technologies such as Okta, EntraID, Splunk, and Netskope
  • Balance risks in ambiguous and complex scenarios
  • Team-oriented, highly collaborative, experienced leading initiatives
  • Experience in GRC platforms
  • Deliver quality as part of a Scrum team working in an Agile environment
  • Preference given to experience in a regulated industry: Finance, Healthcare, etc.

  • 100% paid medical, dental and vision premiums for you and your qualifying dependents
  • A 50% 401(k) match, up to the IRS maximum
  • 20 days of PTO, plus 10 paid holidays
  • Family Support programs including 8 week Paid Primary Caregiver Leave, $10,000 fertility, family forming, and hormonal health assistance, and back-up child, adult, and elder care
  • This is an in-office role. Based on your role, tenure, and performance eligibility you may have the opportunity to participate in our hybrid work from home program. This program is subject to change.

About Fisher Investments

Fisher Investments is a privately owned investment management firm founded in 1979 by Ken Fisher. The company is headquartered in Camas, Washington, and has offices in the United States, Europe, and Asia. Fisher Investments manages assets for individuals and institutions, including pension plans, endowments, and foundations. The company is known for its investment philosophy, which emphasizes a global perspective and a focus on long-term growth. Fisher Investments has been recognized for its performance and has won numerous awards for its investment strategies.
Learn more about Fisher Investments
Size
3,500 employees
Industry
Founded
1979

Similar Jobs

More Jobs at Fisher Investments

More Information Technology Jobs

Find similar Information Security Risk Analyst jobs: