IT Risk Services Analyst

Integrated Resources, Inc

Painted Post, New York

JOB DETAILS
JOB TYPE
Contractor
SKILLS
Access Control, Architectural Analysis, CISSP - Certified Information Systems Security Professional, Computer Security, Data Analysis, Data Processing, Data Recovery, Database Backup, Disaster Recovery, Distribution Channel, Employee Retention, External Audit, Housekeeping/Cleaning, Information Technology & Information Systems, Information/Data Security (InfoSec), Internal Audit, Internet Security, Maintain Compliance, Microsoft SharePoint, On Call, Request for Proposals (RFP), Risk, Risk Analysis, Risk Management, Security Analysis, Security Architecture, ServiceNow, Status Reports, System Architecture, Talent Management, Team Player, Technical Support, Testing, Training/Teaching, Vendor/Supplier Evaluation, Web Browsers, Wireless Software
LOCATION
Painted Post, New York
POSTED
2 days ago
IT Risk Services AnalystIntegrated Resources, Inc., is led by a seasoned team with combined decades in the industry. We deliver strategic workforce solutions that help you manage your talent and business more efficiently and effectively. Since launching in 1996, IRI has attracted, assembled and retained key employees who are experts in their fields. This has helped us expand into new sectors and steadily grow.Job DescriptionResponsibilities:Work with project teams to provide Privacy Impact AssessmentsConduct IT Risk Assessments on External Vendor's system architecture and design to ensure the security requirements meets maturity levelsReview third party RFP responses with security architects, and evaluate SSAE16 SOC Type 2 reports and similar reports to identify key areas concerning security, risk and complianceConduct training to project services resources on risk, security assessment process, and data privacy assessment processAssist with internal and external audits and assessmentsAssist with the development of programs to ensure compliance to regulatory requirementsPerform other IT related assessments as assignedMaintenance of Standards & PoliciesContribute to the maintenance of IT Policies – Clean Desk Policy, AD Password PolicyCreate work instructions for evaluating requests against Standards & PoliciesEvaluate requests and applies the IT exception processes to these requestsClearly document and define risks and potential impacts and identify systems affected by the defined riskCommunication of IT Risk Services policies and standardsMaintain and contribute to SharePoint sites regarding IT Risk contentCreate and/or coordinate training sessions as requiredMonitoring IT Risk Services mailbox and respond to requests and customer inquiriesAnswer and respond to ServiceNow help-line tickets – Administrative Rights, Removal and System identification, Ensure Software Compliance, Wireless Access Control, Email and Distribution list request, Vendor Network Access, Browser ExceptionsLog and follow up on customer issuesInteract with other teams : Global Information Security, Global Security, Cyber Security, and IT Teams as requiredDisaster RecoveryTrack and assist with the completion and updating of Component Recovery PlansCommunicate recommended business continuity preparations and controls, including deficiencies, to business unitsApprove restoration of Backup Data to DR sitesParticipate with internal audits and testing of Component and Disaster Recovery PlansMonitoring & ReportingProvide summary and status reports regarding assessments and project statusSummary reports exception requests and statusAwareness of all risk-centric tools within the environmentConditions of Work:On call rotation may be requiredOccasional after hours and weekend work requiredOccasional travel between the business sites may be requiredQualificationsQualifications:Bachelor's degree preferred, with 3-5 years' information risk management experience preferred and/or advanced degree in related fieldEducational, Licenses and Certificates.CISSP certification or SANS certificates or certification preferred3 + years' experience working with project teamsUnderstands risk and security processes and uses the knowledge to respond to customer inquiriesInteract with other teams : Global Information Security, Global Security, Cyber Security, and IT Teams as required

About the Company

I

Integrated Resources, Inc