Pinnacle Method Consulting logo

Security Risk Analyst

Pinnacle Method Consulting

RemoteFull timeMid levelPosted today
Apply with JobAssist

About the role

Pinnacle Method Consulting's mission is to help job seekers reach their career peak by accessing top-tier opportunities. We are not a staffing firm or agency. Pinnacle Method does not hire for these roles—we systematically source and verify them from premier employers.

Job Description External Posting Role Title - Security Risk Analyst College Board - Risk Management

Location: This is a remote role. Candidates who live near CB offices have the option of being fully remote or hybrid (Tuesday and Wednesday in office). All CB employees are required to occasionally travel to meet in person for business purposes.

Role Type This is a full-time position

About The Team The Information Security Governance Risk and Compliance (ISGRC) team at the College Board works closely with other teams across the organization to assess and certify the security of College Board's information systems and processes. This dedicated team facilitates information security governance and compliance by assessing College Board's vendors, reviewing and negotiating contractual commitments to information security, planning for disaster response and recovery, testing system strength using industry-recognized frameworks (ISO 27001, PCI-DSS and SOC2) and obtaining related compliance certifications, implementing information security policies, promoting security awareness and training, and testing the acumen of College Board employees through robust and innovative training and phishing campaigns.

About The Opportunity As a Security Risk Analyst, you will have the critical role of being responsible for evaluating and managing exceptions to IT security policies, for managing the Organization's Risk and Control Issues Register (Risk Register), and for developing reports and metrics.

Your strong technical communication and negotiation skills will help you build relationships and collaborate with diverse stakeholders and reduce risk to the organization and ensure compliance.

Under the direction of management, you will manage the Risk Register and perform security policy exceptions to help the College Board understand its critical risks.

In This Role You Will Manage the Risk Register (20%)

  • Leads the management of the issues and risks and quickly escalates any untimely completion of audit actions.
  • Works independently to communicate risks and works with others to problem-solve risks to tolerance levels based on data and evidence.
  • Maintains data quality of Risk Register and executes any required data clean-up exercises.
  • Understands College Board work to be able to drive Risk or Control Owners to ensure consistent application of policies and standards.
  • Raises awareness about Risk & Control Issues, Policy exceptions, and available risk reduction options.
  • Fosters a culture of risk awareness and compliance within the technology department and across the organization.

Manage Policy Exceptions (65%)

  • Independently analyzes policy exception submissions and provides risk assessment reports for critical service lines, applications, and infrastructure hosted on-prem and in the cloud.
  • Evaluates and manage exceptions to IT security policies.
  • Manages materials for the Exception Review Board and presents exception information to executive leadership and senior team members.
  • Maintains an up-to-date knowledge and understanding of IT security policies and principles.
  • Maintains a customer-focused attitude in all interactions with customers and colleagues.

Support Vendor Risk Management (10%)

  • Support the Vendor Risk Management program by understanding policies and procedures.
  • Perform New Vendor Risk Assessments and Reassessments.
  • Serve as backup to the Sr. Risk Analyst.

Manage Metrics and Reporting (5%)

  • Provides weekly and monthly reporting for the Risk Register and policy exceptions.
  • Produces trending metrics and escalate exceptions.
  • Performs other duties as assigned.

About You To qualify for this role you must have

  • 5-7 years of experience managing or supporting IT Security Risk and Control Risk Register and processing policy exceptions.

  • Strong understanding of risk management techniques such as risk identification, risk scoring, risk mitigation, and risk tracking.

  • Proven ability to lead conversations balancing risk and multiple business needs that result in positive outcomes with multiple stakeholders.

  • The capacity to assess risk information and make risk recommendations independently.

  • Strong organization and prioritization skills and the pro #PinnacleMethodConsulting

Millions of jobs, with real people getting hired every day

20,000+
New jobs added daily
7,000,000+
Verified job listings
500,000+
Tailored applications submitted
FAQ

Questions, answered

Click "Apply with JobAssist" – we tailor your resume and application to this role and submit it for your approval.

Yes. This role at Pinnacle Method Consulting was screened before publishing – we confirmed the employer before listing it.

The employer didn't disclose a salary range for this listing. JobAssist shows pay whenever it's available.

This position can be done from anywhere, with no in-office requirement.

Yes – every application is tailored from your profile and this job's requirements, and you can review and edit before it's sent.