Technology Risk & Continuity Analyst

GMO

$100K — $125K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in Cybersecurity, Information Technology, Risk Management, Business Continuity, or related field (or equivalent experience)
  • 2-5 years of experience in cybersecurity, business continuity, disaster recovery, operational risk, or IT risk management
  • Interest in business continuity and operational resilience practices
  • Familiarity with resilience or GRC platforms (e.g., Riskonnect)
  • Understanding of incident management frameworks and IT service management tools (e.g., ServiceNow)
  • Strong written and verbal communication skills
  • Excellent organizational skills and attention to detail.

Responsibilities

  • Map critical service dependencies and document recovery strategies through Business Impact Analysis
  • Maintain and improve Business Continuity and Incident Response Plans via regular reviews and exercises
  • Develop and maintain BCP standards and templates
  • Monitor IT incidents and prepare incident summaries for reporting
  • Coordinate security awareness programs and training
  • Support internal and external audits by collecting evidence and maintaining audit artifacts
  • Participate in vendor risk assessments and onboarding reviews.

Benefits

  • Medical insurance
  • Dental insurance
  • Life insurance
  • Long-term disability coverage
  • 401(k)/profit-sharing retirement plan
  • Open paid time off
  • Tuition reimbursement, charitable gifts matching, and commuter benefits.
Full Job Description
Overview:

As a key member of the Security Risk & Audit team, the Technology Risk & Continuity Analyst supports the firm's security risk, business continuity, and incident management programs, contributing across prevention, preparedness, and response activities.

This role performs core security risk functions such as risk and control support, audit readiness, access review coordination, and security awareness enablement. It also supports the development, maintenance, and testing of business continuity and incident response plans, including coordinating exercises and tracking remediation activities.

The analyst monitors threats and incidents, supports resilience and training platforms, and contributes to audit and due diligence efforts. Working closely with technology, risk, and business stakeholders, this role provides broad organizational exposure while helping ensure the firm is prepared for operational disruptions and cyber events, and continually improving its security posture.

We value individuals who are reliable, curious, collaborative, proactive, and strong communicators-professionals who enjoy problem-solving and are eager to build hands-on experience across security risk management, continuity planning, and incident management.

Primary Responsibilities:

Business Continuity
  • Work with all areas of the firm to map critical service dependencies and document recovery strategies through the BIA process, gathering recovery requirements, and identifying single points of failure
  • Support maintenance of Business Continuity and Incident Response Plans through regular reviews and exercises, with a focus on continuous improvement
  • Maintain program documentation including incident and exercise reporting, program metrics and reports for a variety of stakeholders
  • Develop and maintain BCP standards and templates.
  • Participate in Business Continuity and risk forums
  • Identify emerging risks (e.g., regulatory changes, natural and man-made risk) and perform risk assessments.
  • Administer and maintain the Riskonnect Resilience platform including monitoring platform updates, attending vendor training, and managing the vendor relationship

Security & Risk Management
  • Monitor IT incidents and document significant events
  • Prepare incident summaries for internal tracking and reporting
  • Coordinate security awareness programs via Learning Pool, including onboarding, annual training, and phishing simulations
  • Support internal and external audits by collecting evidence, documenting control activities, and maintaining audit artifacts
  • Assist with annual program reviews and audit readiness activities
  • Respond to client due diligence requests and RFPs, leveraging knowledge bases and SMEs as needed
  • Participate in vendor risk assessments, onboarding reviews, and ongoing monitoring of critical vendors


Job Requirements:

  • Bachelor's degree in Cybersecurity, Information Technology, Risk Management, Business Continuity, or a related field (or equivalent experience)
  • 2-5 years of experience in cybersecurity, business continuity, disaster recovery, operational risk, or IT risk management


Core Skills & Knowledge:

  • Interest in business continuity and operational resilience practices (BIAs, recovery strategies, dependency mapping, exercises, and issue remediation)
  • Familiarity with resilience or GRC platforms (e.g., Riskonnect or similar tools)
  • Ability to master learning management systems and security awareness training programs (e.g., Learning Pool)
  • Understanding of incident management frameworks and IT service management tools (e.g., ServiceNow)
  • Knowledge of client and third-party due diligence processes
  • Familiarity with threat intelligence sources and relevant frameworks/standards (e.g., NIST, ISO 22301, ITIL) is a plus


Professional Skills:

  • Strong written and verbal communication skills, with the ability to clearly document plans, exercises, and incidents
  • Excellent organizational skills and attention to detail, with the ability to manage multiple concurrent workstreams
  • Ability to collaborate across technology, risk, compliance, and business teams
  • Comfort facilitating discussions (e.g., tabletop exercises, walkthroughs), capturing outcomes, and driving follow-through
  • Continuous improvement mindset with the ability to learn, document, measure, and iterate


Certifications (Preferred):

  • ABCP, CBCP, Security+, or similar certifications are a plus


$100,000 - $125,000 a year

This is a reasonable, good faith estimate of the current salary range for this role. GMO's salary range accounts for a wide array of factors that are considered in making compensation decisions including but not limited to skill sets and market demand for skills; level of experience and training; specific qualifications, performance, time in role/company, geographic location, and other business and organizational needs.

In addition, this position is eligible for a discretionary annual bonus award, which award may be determined by individual, team, department and firm performance, and is subject to the terms of GMO's compensation plan. This position is also benefits eligible. GMO's comprehensive benefits program includes medical insurance, dental insurance, life insurance, long-term disability coverage, a 401(k)/profit-sharing retirement plan, open paid time off, leaves of absences, dependent care resources, tuition reimbursement, charitable gifts matching, flexible spending accounts, and commuter benefits.

Similar Jobs

More Jobs at GMO

More Information Technology Jobs

Find similar Technology Risk & Continuity Analyst jobs: