Security Risk Assessor

Compunnel

$100K — $120K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 5+ years in IT governance, access control analysis, incident response, data analysis, or related fields.
  • Extensive knowledge of risk assessment frameworks.
  • Familiarity with HIPAA Security Rule and other regulatory requirements.
  • Excellent collaboration, facilitation, and negotiation skills.
  • Proficient in written and verbal communication, especially complex concepts.
  • Demonstrated analytical and problem-solving capabilities.
  • Strong organizational skills with project and program management experience.

Responsibilities

  • Provide expert consultation on information security and compliance.
  • Identify and implement process improvements for security best practices.
  • Ensure the confidentiality, integrity, and availability of enterprise information.
  • Conduct comprehensive risk assessments for various environments.
  • Document risks and communicate findings clearly to stakeholders.
  • Act as a representative in contract and design review sessions.
  • Create supporting documentation for risk assessment services.
  • Independently remediate security control deficiencies and propose improvements.
  • Troubleshoot security and risk issues effectively.

Benefits

  • Opportunities for professional development and growth.
  • Collaborative work environment with cross-functional teams.
  • Access to advanced information security tools.
  • Engagement with diverse technologies and risk scenarios.
Full Job Description
Job Summary

The Security Risk Assessor will provide advanced information security consultation across information security, compliance, policy, risk management, and remediation. The role is responsible for conducting risk assessments across applications, systems, infrastructure, cloud environments, and third-party arrangements; identifying security risks and process improvements; documenting findings; and communicating complex security matters effectively to technical and business leadership. The position requires a self-directed professional capable of independently addressing security control gaps, troubleshooting issues, and driving remediation and security best-practice improvements.

Key Responsibilities
• Provide advanced information security consultation across information security, compliance, policy, risk management, and remediation activities.
• Identify process improvements and develop plans to meet or exceed security best practices.
• Help ensure the confidentiality, integrity, and availability of information residing on or transmitted through enterprise devices, servers, systems, and data repositories.
• Conduct risk assessments for applications, systems, infrastructure, cloud environments, and third-party arrangements.
• Document identified risks through detailed risk reports and effectively communicate findings to business and technical leadership.
• Represent the Cyber & Information Security risk assessment services function when reviewing contracts, application designs, integration plans, and related materials.
• Create documentation supporting the risk assessment services team.
• Independently identify and lead efforts to remediate security control deficiencies and implement process improvements.
• Explain complex technical and security issues to non-technical colleagues and business executives.
• Troubleshoot and independently resolve security and risk-related problems as they arise.

Required Qualifications
• 5+ years of experience in at least four relevant disciplines, such as IT governance and operations, access control analysis, incident response, data analysis and control auditing, data protection, advanced threat protection, identity and access management, or integrated technologies with cross-functional impact.
• 5+ years of experience with risk assessment frameworks.
• Broad knowledge of commonly used information security concepts, best practices, and standards.
• Strong collaboration, facilitation, and negotiation skills.
• Strong written and verbal communication skills.
• Familiarity with HIPAA Security Rule and other applicable regulatory requirements.
• Proven analytical and problem-solving abilities.
• Strong project and program management planning and organizational skills.
• Customer service-focused approach with the ability to work effectively with stakeholders.
• Strong time management and prioritization skills.

Preferred Qualifications
• Hands-on experience with information security tools.

Similar Jobs

More Jobs at Compunnel

More Information Technology Jobs

Find similar Security Risk Assessor jobs: