Why This Role Stands Out
This on-site role at a globally recognized leader in property risk management offers a competitive salary range of $106,000 - $152,000, where your expertise in third-party risk management will directly shape strategic decisions and enhance cybersecurity. You will thrive here if you are a seasoned analyst passionate about safeguarding critical data and collaborating with diverse teams to drive impactful risk mitigation strategies. Apply to contribute your skills to a company with a rich history and a forward-thinking approach to security.
Quick Overview
Job Description
FM seeks a Senior Information Security Risk Analyst to lead cyber and technology risk activities across the organization. You will perform detailed risk assessments on applications, infrastructure, and vendors, identify control gaps, and recommend pragmatic remediation plans. Partnering with IT, security, and business teams, you'll maintain risk registers, metrics, and reports aligned to frameworks such as NIST and ISO 27001. You will support policy development, third-party risk reviews, and incident response, helping FM strengthen its security posture while enabling business objectives.
Responsibilities
- Lead information security risk assessments across systems, applications, and vendors.
- Identify, analyze, and prioritize security risks and control gaps.
- Recommend and track remediation plans with IT and business stakeholders.
- Support third-party risk reviews and ongoing vendor monitoring.
- Develop and maintain risk registers, metrics, and dashboards.
- Align FM's security posture with frameworks such as NIST and ISO 27001.
- Support policy, standard, and procedure development and updates.
- Contribute to incident response by assessing business and control impacts.
- Prepare clear reports and presentations for leadership and audit partners.
- Collaborate with cross-functional teams to embed security into projects and change initiatives.
Required Skills
- Information security risk assessment
- Third-party/vendor risk management
- NIST CSFISO 27001
- SOC 2 controls
- Cloud security (AWS/Azure/GCP)
- Vulnerability management
- Security incident response
- GRC tools (e.g., Archer, Service
- Now GRC)
- Report writing & executive risk reporting
Similar jobs
- ST
Security Engineers
NewSVK Technology Solutions
CA🇺🇸HybridYesterdayAdministrative - PC
Mainframe Security Migration Specialist
NewPyramid Consulting, Inc.
United States🇺🇸$70 - $72/hrHybridYesterdayJavaTechnology - CF
Principle Security Engineer
NewCetera Financial Group, Inc.
United States🇺🇸HybridYesterdayAWSOWASPPenetration TestingTechnology - IG
ISSE with Security Clearance
NewInsight Global, Inc.
Arlington, VA🇺🇸$70 - $80/hrHybridYesterdayAdministrative - SI
Principle Security Engineer
NewStratEdge It consulting INC
NJ🇺🇸HybridYesterdayMicroservicesAWSCDN+5Technology - Y-
Security Administration Analyst with Sailpoint and ServiceNow- NJ - RTH-
NewYoh - A Day & Zimmerman Company
Jersey City, NJ🇺🇸HybridYesterdayMicrosoft ExcelTechnology