Specialist, IT Risk Assessment

December 2, 2025
Application deadline closed.

Job Description

Main Responsibilities:

  • Perform risk assessments on IT systems, applications, networks, and third-party vendors.
  • Identify, analyze, and document technology risks and potential business impacts.
  • Collaborate with IT, InfoSec, Compliance, and Business teams to address and mitigate identified risks
  • Monitor and report on key risk indicators (KRIs), control effectiveness, and residual risk.
  • Support the implementation of risk management frameworks such as NIST, ISO 27001, COBIT, or FAIR.
  • Maintain up-to-date knowledge of emerging technology threats, vulnerabilities, and regulatory requirements.
  • Assist in audits, regulatory examinations, and internal control assessments.
  • Participate in development and enhancement of IT risk policies, standards, and procedures.
  • Support incident response and post-incident risk reviews.
  • Assess risk from third-party vendors and ensure appropriate controls are in place.
  • Perform other tasks assigned by the Unit Manager/Chief Risk Officer.

Qualifications and Requirements:

  • Bachelor’s degree in Information Technology, Cybersecurity, Risk Management, or a related field.
  • 2–3 years of experience in IT risk management, information security, or GRC roles.
  • Solid understanding of IT systems, cloud environments, and cybersecurity principles.
  • Experience with risk assessment methodologies and frameworks (e.g., NIST RMF, ISO 27001, COSO).
  • Familiarity with regulatory and compliance requirements such as GDPR, SOX, HIPAA, PCI DSS.
  • Strong analytical and problem-solving skills.
  • Excellent written and verbal communication skills for reporting and stakeholder engagement.