We use cookies. Find out more about it here. By continuing to browse this site you are agreeing to our use of cookies.
#alert
Back to search results

Sr. Risk & Compliance Analyst

BDO USA, LLP
United States, Michigan, Grand Rapids
May 02, 2025

Job Summary:

The Senior Risk & Compliance Analyst works with the Information Security Analyst, Manager, and the Chief Information Security Officer (CISO) managing and coordinating the governance, risk and compliance framework for the organization. This role will coordinate risk identification, prioritization, treatment, monitoring, and risk reporting. The Senior Analyst will work with cross-functional teams to design and implement security initiatives and will serve as a resource person on specific information security technologies as well as technologies related compliance requirements.

Job Duties:

Compliance Management:



  • Facilitates the management of information security controls, requirements, and compliance frameworks, including ISO 27001, SOC 2 and HITRUST
  • Documents and assess the implementation of security controls and requirements
  • Coordinates third party audits, recommends treatment plans, and oversees remediation of findings
  • Establishes metrics and key performance indicators related to governance, risk, and compliance
  • Reports metrics and other key performance indicators to management


Risk and Governance:



  • Conducts risk assessments against established frameworks (i.e., ISO 27001)
  • Manages risk assessments, risk register and risk mitigation plans
  • Facilitates risk meetings with business and process owners to communicate findings and coordinate risk treatments
  • Establishes policies, standards, and procedures related to risk governance, risk, and compliance
  • Identifies opportunities for improvement and maintain a continuous improvement plan


Other duties as required

Supervisory Responsibilities:



  • N/A


Qualifications, Knowledge, Skills and Abilities:

Education:



  • High School Diploma or GED, required
  • Bachelor's degree in Computer Science, or Information Technology, preferred


Experience:



  • Five (5) or more years of experience in governance, risk and compliance (GRC) & certification management (i.e., ISO 27001), required
  • Prior experience and understanding of audit frameworks and facilitating compliance audits (i.e., SOC, HIPAA), required
  • Experience performing risk reporting and creating reports to inform stakeholders and risk owners, required
  • Experience performing third-party vendor risk assessments, preferred


License(s)/Certification(s):



  • Prior experience with Governance, Risk Management and Compliance Management (GRC) tools such as Archer, ServiceNow, or equivalent solutions, required
  • CISSP, CRISC, CISM, and/or CISA, preferred
  • Prior experience with third party vendor risk assessment tools, preferred


Language(s):



  • N/A


Other Knowledge, Skills & Abilities:



  • Ability to communicate well, participate in cross-functional and individual contributor efforts independently and with minimal oversight
  • Strong analytical and problem-solving skills
  • Strong verbal and written communication skills (documenting concepts, designs, presenting to groups, etc.)
  • Excellent interpersonal and customer relationship skills
  • Capacity to work in a deadline-driven environment while handling multiple complex projects/tasks simultaneously with a focus on details
  • Capable of successfully multi-tasking while working independently or within a group environment
  • Strong understanding of risk management and compliance frameworks
  • Ability to rely on extensive experience and judgement to plan and accomplish goals
  • Ability to quickly troubleshoot complex problems and take appropriate corrective action
  • Capable of working well under pressure while dealing with unexpected problems in a professional manner
  • Capacity to communicate and interact with all levels of employees and management
  • Ability to interact and build consensus among people
  • Strength in both business and technical requirements analysis
  • Ability to work after standard business hours (on-call) and travel as needed


Individual salaries that are offered to a candidate are determined after consideration of numerous factors including but not limited to the candidate's qualifications, experience, skills, and geography.
National Range: $105,000 - $110,000
Maryland Range: $105,000 - $110,000
NYC/Long Island/Westchester Range: $105,000 - $110,000
Applied = 0

(web-7fb47cbfc5-n2jr4)