Xerox

Senior Risk Analyst

Xerox$146K — $195K *
US-AnywhereRemote in United States
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in Cybersecurity, Information Systems, Computer Science, or related field; equivalent practical experience considered.
  • 5+ years in information security, IT risk management, audit, compliance, or related field.
  • Experience leading or mentoring analysts or project teams.
  • Strong knowledge of CIS Critical Security Controls and the NIST Cybersecurity Framework.
  • Experience with third-party/vendor risk management programs, including questionnaires and monitoring.
  • Familiar with CMMC and NIST SP 800-171 requirements.
  • Understanding of FedRAMP processes, including SSPs and SARs.

Responsibilities

  • Lead cybersecurity risk assessments using CIS and NIST frameworks.
  • Support and enhance the Third-Party Risk Management program.
  • Review vendor-submitted evidence and security documentation.
  • Assist in CMMC compliance efforts and leadership reporting.
  • Advise on FedRAMP authorization activities for cloud services.
  • Manage the security policy exception process and risk scoring.
  • Guide and review work for risk analysts and GRC projects.
  • Develop risk dashboards and reports translating technical findings into business contexts.

Benefits

  • Comprehensive benefits package including health and wellness programs.
  • Flexible remote work options within Eastern or Central Time Zones.
  • Opportunities for professional development and training.
  • Support for work-life balance with a full-time schedule.
Full Job Description
General Information

Country

United States

Date

Monday, September 21, 2026

Working time

Full-time

Ref#

20041179

Job Level

Specialist

Job Type

Experienced

Seniority Level

Mid-Senior Level

Currency

USD - United States - US

Annual Base Salary Minimum

97,740

Annual Base Salary Maximum

195,480

The salary range above represents the low and high end in the local currency of Xerox's salary range for this position and is reflected in an annualized amount. Actual salaries will vary based on factors including, but not limited to, geographic location, market competition, and/or the successful applicant's education, experience, knowledge, skills, and abilities. The range listed is just one component of Xerox's total compensation package for employees. Employees are also afforded a comprehensive suite of benefits, to view those details please visit Xerox Careers for your applicable country. If you are not reviewing this job posting on Xerox Careers, we cannot guarantee the validity of this posting. For a list of our current internal postings, please visit Xerox Careers.

Location: Remote - United States, Eastern or Central Time Zone
Schedule: Full-Time, Days
Compensation: $146,000-$195,000 based on experience

Overview

Xerox is seeking a Sr. Risk Analyst to support and lead key cybersecurity risk initiatives within our Governance, Risk, and Compliance organization. This role will help assess, monitor, and report on cybersecurity and third-party risk using industry-standard frameworks, including the CIS Critical Security Controls and the NIST Cybersecurity Framework.

The Sr. Risk Analyst will play a key role in Xerox's Third-Party Risk Management program, CMMC and FedRAMP compliance initiatives, security policy exception process, risk register management, and executive-level risk reporting. This position is ideal for an experienced risk, audit, or compliance professional who is ready to take ownership of complex programs, mentor others, and help mature enterprise cybersecurity risk practices.

What You'll Do
  • Lead and support cybersecurity risk assessments using frameworks such as CIS Critical Security Controls and the NIST Cybersecurity Framework.
  • Support and mature Xerox's Third-Party Risk Management program, including vendor security questionnaires, third-party risk assessments, ongoing monitoring, and escalation of high-risk findings.
  • Review vendor-submitted evidence, including SOC 2 reports, security questionnaires, certifications, and due diligence materials.
  • Support CMMC compliance efforts, including control documentation, System Security Plan development, readiness assessments, and leadership reporting.
  • Advise on FedRAMP authorization and continuous monitoring activities for applicable cloud services.
  • Manage the security policy exception process, including intake, risk scoring, compensating control review, and leadership approval preparation.
  • Provide direction, guidance, and quality review for risk analysts and related GRC workstreams.
  • Partner with Security Governance, Security Architecture, Global Sourcing, Internal Audit, and business leaders on risk-related matters.
  • Maintain the security risk register, ensuring risks are documented, prioritized, tracked, and driven toward closure.
  • Develop dashboards, metrics, and reports that translate technical risk findings into clear business risk narratives.
  • Support internal and external audits, including ISO 27001, SOC 2, and customer security assessments.
  • Track changes in cybersecurity regulations, frameworks, and compliance requirements, including NIST, CMMC, and FedRAMP updates.
  • Help establish and maintain risk assessment methodologies, templates, standards, and scalable processes.
  • Support GRC tooling and identify opportunities to improve efficiency, consistency, and program coverage.

Who You Are
  • Bachelor's degree in Cybersecurity, Information Systems, Computer Science, or a related field; equivalent practical experience will also be considered.
  • 5+ years of experience in information security, IT risk management, audit, compliance, or a related field.
  • Experience leading, mentoring, or providing guidance to analysts or project teams.
  • Strong working knowledge of CIS Critical Security Controls and the NIST Cybersecurity Framework.
  • Experience with third-party/vendor risk management programs, including questionnaires, due diligence, and ongoing monitoring.
  • Working knowledge of CMMC requirements and NIST SP 800-171.
  • Working knowledge of FedRAMP requirements and authorization processes, including SSPs, SARs, and POA&Ms.
  • Experience with security policy exception processes, risk-based decision-making, and compensating controls.
  • Strong communication and presentation skills, with the ability to explain technical risk findings to senior leadership and business stakeholders.

Preferred Qualifications

  • Relevant certification such as CISSP, CRISC, CRMA, CISA, CCSK, or a CMMC-related credential.
  • Direct experience supporting or leading a CMMC or FedRAMP assessment or authorization effort.
  • Experience with SOC 2, ISO 27001, or similar audit frameworks.
  • Experience with GRC or risk management tools such as ServiceNow GRC, OneTrust, or similar platforms.


#LI-AW1

#LI-REMOTE

About Xerox

Xerox Corporation is an American global corporation that sells print and digital document products and services in more than 160 countries. Xerox is headquartered in Norwalk, Connecticut, though its largest population of employees is based in and around Rochester, New York, the area in which the company was founded. The company's primary offerings are printers, scanners, copiers, and multifunction devices that handle document processing. Xerox also provides managed print services, workflow automation, and digitization services. The company was founded in 1906 as The Haloid Photographic Company, which originally manufactured photographic paper and equipment.
Learn more about Xerox
Size
23,400 employees
Market Cap
$2.2 billion
Industry
Net Income
$192 million
Founded
1960
5 Year Trend
-8.2%
Revenue
$7 billion
NASDAQ

Similar Jobs

More Jobs at Xerox

More Information Technology Jobs

Find similar Senior Risk Analyst jobs: