ZS Associates

Senior Analyst - Governance, Risk & Compliance

ZS Associates • $95K — $115K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in Computer Science, Information Systems, or related field; master's degree is a plus.
  • 4-6 years of experience in IT risk management or governance.
  • Strong understanding of IT risk assessment methodologies and regulatory requirements (GDPR, HIPAA, PCI DSS).
  • Experience with vendor risk management and security risk assessments.
  • Proficiency in risk assessment tools and technologies.
  • Excellent analytical, problem-solving, and communication skills.
  • Relevant certifications (CRISC, CISSP, CISM) preferred.

Responsibilities

  • Perform comprehensive risk assessments for vendors, processes, and projects.
  • Evaluate risks across IT systems, applications, and third-party engagements.
  • Document assessment findings with actionable recommendations.
  • Maintain and update the risk register, ensuring accurate classification and closure tracking.
  • Collaborate with internal teams and external stakeholders for complete risk documentation.
  • Conduct periodic risk hygiene activities, including evidence collection and exception tracking.
  • Prepare risk reports summarizing findings and mitigation plans.

Benefits

  • Comprehensive total rewards package supporting health and well-being.
  • Robust skills-building programs and career progression paths.
  • Internal mobility opportunities for growth and role expansion.
  • Hybrid working model combining remote and on-site work.
  • Travel opportunities for client engagement and professional growth.
Full Job Description
Senior Analyst - Governance, Risk & Compliance

ZS IT Support teams are aligned with the company's business strategy and operating model and aims to provide its 4000 plus employees and their clients the right tools and information for high performance. The IT organization focuses on providing products and services to ZS to ensure successful business outcomes. This involves providing a scalable, sustainable and reliable IT infrastructure, customized applications, messaging and collaboration products, Business Intelligence and Database administration support along with a reliable 24*7 uninterrupted high-quality technology support services.

What You'll Do:

We are seeking applicants for the position of Senior Analyst - Governance and Risk team to join our US IT Governance, Risk and Compliance team. The position will support various management directed, IT risk governance initiatives which include following job requirements:

The primary responsibility of this role is to perform comprehensive risk assessments, including vendor due diligence, process/project security risk assessments, and maintaining the risk register. The successful candidate will possess a strong understanding of IT risk management principles and will play a crucial role in identifying, assessing, and mitigating risks to ensure the security and stability of our organizational infrastructure. It requires strong analytical skills, familiarity with security domains, and the ability to communicate risk insights clearly and effectively.

Risk Assessments:

  • Perform assessments for vendors, processes, and projects to identify security gaps and recommend controls.
  • Evaluate risks across IT systems, applications, infrastructure, and third-party engagements.
  • Document assessment findings with clear rationale and actionable recommendations.


VRA Execution & Risk Register Management:

  • Perform vendor risk assessments to evaluate third-party security posture, document findings, and recommend mitigation strategies aligned with organizational standards.
  • Maintain and update the risk register, ensuring accurate classification, ownership mapping, and closure tracking across all active and draft risks.
  • Collaborate with internal teams (e.g., security, legal, procurement) and external stakeholders to ensure risk documentation is complete, validated, and aligned with business priorities.
  • Conduct periodic risk hygiene activities, including archival of outdated risks, evidence collection, and exception tracking.
  • Ensure all risk-related documentation is clear, complete, and accessible for stakeholders, supporting decision-making and compliance readiness.


Compliance & Controls:

  • Apply knowledge of regulatory standards (e.g., ISO, NIST, GDPR) to assess and document compliance.
  • Support the implementation of security policies and control frameworks across business functions.
  • Monitor control effectiveness and suggest improvements where needed.


Reporting & Communication:

  • Prepare risk reports with summaries of findings, impact analysis, and mitigation plans.
  • Share updates on risk trends, exceptions, and closure progress on a regular cadence.
  • Communicate technical risk concepts in a clear, accessible format for non-technical audiences


What You'll Bring:
  • Bachelor's degree in Computer Science, Information Systems, or a related field (master's degree is a plus).
  • Minimum of 4-6 of years' experience in IT risk management, IT governance or related field.
  • Strong understanding and knowledge of IT risk assessment methodologies, frameworks industry best practices and regulatory requirements (GDPR, HIPAA, PCI DSS).
  • Strong experience with vendor risk management and security risk assessments.
  • High proficiency in using risk assessment tools and technologies.
  • Excellent analytical and problem-solving skills.
  • Strong written and verbal communication skills, with the ability to effectively communicate technical concepts to both technical and non-technical audiences.
  • Strong organizational and time management skills, with the ability to manage multiple priorities and deadlines.
  • Relevant certifications such as Certified in Risk and Information Systems Control (CRISC), Certified Information Systems Security Professional (CISSP), or Certified Information Security Manager (CISM) are preferred, ISO 27001.
  • Professional appearance and demeanor, with ability to exercise good judgment and discretion.
  • Proven ability to work creatively and analytically in a problem-solving environment.
  • Fluency in English.
  • Client-first mentality.
  • Intense work ethic.
  • Collaborative spirit and problem-solving approach.


How you'll grow:
  • Cross-functional skills development & custom learning pathways
  • Milestone training programs aligned to career progression opportunities
  • Internal mobility paths that empower growth via s-curves, individual contribution and role expansions


Perks & Benefits:

At ZS, your growth matters. We offer a comprehensive total rewards package that supports your health and well-being, financial future, time away, and professional development. With robust skills-building programs, multiple career progression paths, internal mobility, and a deeply collaborative culture, you'll have the opportunity to do meaningful work, expand your capabilities, and thrive as part of a global community. For details on total rewards in United States, visit ZS US office locations | Where we work | ZS.

Hybrid working model:

We are committed to giving our employees a flexible and connected way of working. A flexible and connected ZS allows us to combine work from home and on-site presence at clients/ZS offices for the majority of our week. The magic of ZS culture and innovation thrives in both planned and spontaneous face-to-face connections.

Travel:

Travel is a requirement at ZS for client facing ZSers; business needs of your project and client are the priority. While some projects may be local, all client-facing ZSers should be prepared to travel as needed. Travel provides opportunities to strengthen client relationships, gain diverse experiences, and enhance professional growth by working in different environments and cultures.

If you're eager to grow, contribute, and bring your unique self to our work, we encourage you to apply.

Work Authorization:

This position is not eligible for visa sponsorship. Candidates must have authorization to work in the United States that does not now or in the future require employer sponsorship.

To complete your application:
An on-line application, including a full set of transcripts (official or unofficial), is required to be considered.

NO AGENCY CALLS, PLEASE.

Find Out More At:
www.zs.com

About ZS Associates

ZS is a professional services firm that works side by side with companies to help develop and deliver products that drive customer value and company results. From R&D to portfolio strategy, customer insights, marketing and sales strategy, operations and technology, we leverage our deep industry expertise and leading-edge analytics to create solutions that work in the real world. Our most valuable asset is our people?a fact that?s reflected in our values-driven organization in which new perspectives are integral and new ideas are celebrated. ZSers are passionately committed to helping companies and their customers thrive in industries ranging from healthcare and life sciences, to high-tech, financial services, travel and transportation, and beyond.
Learn more about ZS Associates
Size
10,000 employees
Industry
Founded
1983

Similar Jobs

More Jobs at ZS Associates

More Information Technology Jobs

Find similar Senior Analyst - Governance, Risk & Compliance jobs: