Join Aprio's Risk Advisory and Assurance Services (RAAS) team and you will help clients maximize ... Aprio's Information Assurance Services (IAS) practice supports the delivery of attestation and ...
Join Aprio's Risk Advisory and Assurance Services (RAAS) team and you will help clients maximize ... Aprio's Information Assurance Services (IAS) practice supports the delivery of attestation and ...
We reduce information risk by ensuring and enhancing the Confidentiality, Availability, and Integrity of Information systems at Freddie Mac. Your Impact: In this role, you will help fulfill the ...
We reduce information risk by ensuring and enhancing the Confidentiality, Availability, and Integrity of Information systems at Freddie Mac. Your Impact: In this role, you will help fulfill the ...
We reduce information risk by ensuring and enhancing the Confidentiality, Availability, and Integrity of Information systems at Freddie Mac. Your Impact: In this role, you will help fulfill the ...
We reduce information risk by ensuring and enhancing the Confidentiality, Availability, and Integrity of Information systems at Freddie Mac. Your Impact: In this role, you will help fulfill the ...
Experience with Factored Analysis of Information Risk (FAIR) or COSO methodologies. Basic proficiency with Python and API integrations with threat intelligence tools. Additional Information All your ...
Experience with Factored Analysis of Information Risk (FAIR) or COSO methodologies. Basic proficiency with Python and API integrations with threat intelligence tools. Additional Information All your ...
Developing an agency Information Security Risk Management Strategy in accordance with the latest released versions of NIST Special Publications (SPs) such as SP 800-37, Risk Management Framework for ...
Developing an agency Information Security Risk Management Strategy in accordance with the latest released versions of NIST Special Publications (SPs) such as SP 800-37, Risk Management Framework for ...
Cyber Supply Chain Risk Management (C-SCRM) Analyst
Washington, DC · On-site
$89K - $100K/hr
This role serves as the analytical engine behind risk discovery - reviewing submitted data, evaluating supply chain risk indicators, interpreting platform findings, and translating raw information ...
Cyber Supply Chain Risk Management (C-SCRM) Analyst
Washington, DC · On-site
$89K - $100K/hr
This role serves as the analytical engine behind risk discovery - reviewing submitted data, evaluating supply chain risk indicators, interpreting platform findings, and translating raw information ...
Risk Manager
Rockville, MD · On-site
Developing an agency Information Security Risk Management Strategy in accordance with the latest released versions of NIST Special Publications (SPs) such as SP 800-37, Risk Management Framework for ...
Risk Manager
Rockville, MD · On-site
Developing an agency Information Security Risk Management Strategy in accordance with the latest released versions of NIST Special Publications (SPs) such as SP 800-37, Risk Management Framework for ...
Risk Manager
$155K - $165K/yr
Developing an agency Information Security Risk Management Strategy in accordance with the latest released versions of NIST Special Publications (SPs) such as SP 800-37, Risk Management Framework for ...
Quick apply
Risk Manager
$155K - $165K/yr
Developing an agency Information Security Risk Management Strategy in accordance with the latest released versions of NIST Special Publications (SPs) such as SP 800-37, Risk Management Framework for ...
Risk Mitigation Specialist-Entity Vetting
Quantico, VA · On-site
$106K/yr
Conduct research and analysis using Government systems, commercial databases, open source information, corporate records, and other authorized sources. * Develop risk assessments, recommendations ...
Quick apply
Risk Mitigation Specialist-Entity Vetting
Quantico, VA · On-site
$106K/yr
Conduct research and analysis using Government systems, commercial databases, open source information, corporate records, and other authorized sources. * Develop risk assessments, recommendations ...
Senior Consultant - IT Governance, Risk & Compliance (GRC) ABOUT INFINITIVE Infinitive is a data and AI consultancy that enables its clients to modernize and operationalize their data to create ...
Senior Consultant - IT Governance, Risk & Compliance (GRC) ABOUT INFINITIVE Infinitive is a data and AI consultancy that enables its clients to modernize and operationalize their data to create ...
Developing an agency Information Security Risk Management Strategy in accordance with the latest released versions of NIST Special Publications (SPs) such as SP 800-37, Risk Management Framework for ...
Developing an agency Information Security Risk Management Strategy in accordance with the latest released versions of NIST Special Publications (SPs) such as SP 800-37, Risk Management Framework for ...
Senior Consultant - IT Governance, Risk & Compliance (GRC)
Ashburn, VA · On-site
$90K - $139K/yr
Senior Consultant - IT Governance, Risk & Compliance (GRC) ABOUT INFINITIVE Infinitive is a data and AI consultancy that enables its clients to modernize and operationalize their data to create ...
Quick apply
Senior Consultant - IT Governance, Risk & Compliance (GRC)
Ashburn, VA · On-site
$90K - $139K/yr
Senior Consultant - IT Governance, Risk & Compliance (GRC) ABOUT INFINITIVE Infinitive is a data and AI consultancy that enables its clients to modernize and operationalize their data to create ...
In this role, you will apply your expertise in IT governance, risk management, and compliance to drive successful client engagements from initiation through delivery. You will serve as a primary ...
In this role, you will apply your expertise in IT governance, risk management, and compliance to drive successful client engagements from initiation through delivery. You will serve as a primary ...
Manager, Cybersecurity Governance and Risk, Washington, DC The Manager, Cybersecurity Governance and Risk will lead IT risk management (ITRM) initiatives to increase the transparency of risk impacts ...
Manager, Cybersecurity Governance and Risk, Washington, DC The Manager, Cybersecurity Governance and Risk will lead IT risk management (ITRM) initiatives to increase the transparency of risk impacts ...
Risk Mitigation Specialist-Entity Vetting
Quantico, VA · On-site
$106K/yr
Conduct research and analysis using Government systems, commercial databases, open source information, corporate records, and other authorized sources. * Develop risk assessments, recommendations ...
Risk Mitigation Specialist-Entity Vetting
Quantico, VA · On-site
$106K/yr
Conduct research and analysis using Government systems, commercial databases, open source information, corporate records, and other authorized sources. * Develop risk assessments, recommendations ...
Risk Manager
Washington, DC · On-site
Ensure risks associated with cybersecurity, information assurance, and compliance requirements are appropriately assessed and managed. * Support risk management activities related to federal ...
Risk Manager
Washington, DC · On-site
Ensure risks associated with cybersecurity, information assurance, and compliance requirements are appropriately assessed and managed. * Support risk management activities related to federal ...
Risk Manager
Reston, VA · On-site
Risk Manager Job Category: Project and Program Management Time Type: Full time Minimum Clearance ... The GMOS contract aims to provide world-class IT support by modernizing and maintaining ...
Risk Manager
Reston, VA · On-site
Risk Manager Job Category: Project and Program Management Time Type: Full time Minimum Clearance ... The GMOS contract aims to provide world-class IT support by modernizing and maintaining ...
Cybersecurity and Risk Analyst
Arlington, VA · On-site
$110K - $183K/yr
The Cybersecurity and Risk Analyst is a critical member of the Vulnerability Assessment and ... Master's degree in Information Technology, Cybersecurity, Data Science, Information Systems, or ...
Cybersecurity and Risk Analyst
Arlington, VA · On-site
$110K - $183K/yr
The Cybersecurity and Risk Analyst is a critical member of the Vulnerability Assessment and ... Master's degree in Information Technology, Cybersecurity, Data Science, Information Systems, or ...
Risk Manager
Washington, DC · On-site
Ensure risks associated with cybersecurity, information assurance, and compliance requirements are appropriately assessed and managed. * Support risk management activities related to federal ...
Risk Manager
Washington, DC · On-site
Ensure risks associated with cybersecurity, information assurance, and compliance requirements are appropriately assessed and managed. * Support risk management activities related to federal ...
Cybersecurity and Risk Analyst
$110K - $183K/yr
The Cybersecurity and Risk Analyst is a critical member of the Vulnerability Assessment and ... Master's degree in Information Technology, Cybersecurity, Data Science, Information Systems, or ...
Cybersecurity and Risk Analyst
$110K - $183K/yr
The Cybersecurity and Risk Analyst is a critical member of the Vulnerability Assessment and ... Master's degree in Information Technology, Cybersecurity, Data Science, Information Systems, or ...
Information Risk information
See Washington salary details
$59.7K - $71.1K
2% of jobs
$71.1K - $82.4K
4% of jobs
$82.4K - $93.8K
6% of jobs
$101K is the 25th percentile. Wages below this are outliers.
$93.8K - $105.1K
19% of jobs
$105.1K - $116.5K
16% of jobs
The median wage is $118.2K / yr.
$116.5K - $127.9K
14% of jobs
$127.9K - $139.2K
4% of jobs
$139.2K - $150.6K
6% of jobs
$153.1K is the 75th percentile. Wages above this are outliers.
$150.6K - $161.9K
12% of jobs
$161.9K - $173.3K
7% of jobs
$173.3K - $184.6K
9% of jobs
$59.7K
$127.9K
$184.6K
How much do information risk jobs pay per year?

Senior Associate, Information Assurance Services (SOC Focus)
Washington, DC
$81K - $125K/yr
Full-time
Medical, Dental, Vision, Retirement
Re-posted 26 days ago
Key responsibilities
Plan, lead, and execute client meetings, reviews, and testing of control procedures related to information security and privacy.
Perform assessments and testing against standards such as ISO 27001, Trust Services Criteria, PCI DSS, NIST CSF, GDPR, and HITRUST, and prepare related client reporting deliverables.
Support the development of client reports, including gap and risk assessments, SOC reports, GDPR assessments, and ISO 27001 certifications.
Aprio rating
8.8
Based on 7 frontline employees who took The Breakroom Quiz
Job description
Project and focus areas within the Information Assurance Services practice include:
- Service Organization Control (SOC) Reporting (e.g., SOC 1 and SOC 2)
- Payment Card Industry Data Security Standard (PCI DSS)
- ISO Standards (e.g., ISO 27001/27002, 22301
- GDPR
- HITRUST
- Risk Assessments
- Risk Management
- Cyber Threats and Cybersecurity
- Agreed Upon Procedures
- Internal Audit Co-Sourcing
- EI3PA
- Planning and leading client meetings, walk-through reviews of clients control procedures and processes; delivery and presentation of client deliverables.
- Developing and leading the performance of, testing of clients' security, privacy and other information risk management related controls.
- Directing the execution of testing of clients' internal controls, testing of clients' internal controls and review of internal control testing executed by other team members.
- Supporting clients in problem identification and resolution.
- Performing assessments and testing against leading information security and privacy standards and frameworks, including ISO 27001, Trust Services Criteria, PCI DSS, NIST CSF, GDPR, HITRUST and others.
- Leading and supporting preparation of client reporting deliverables; e.g., gap and risk assessments, SOC reporting, GDPR assessments, ISO 27001 certifications, etc.
- Collaborating with other team members to streamline internal processes and procedures to improve client service and efficiencies.
- Participate in meetings with new prospects and/or new service opportunities with existing clients.
- Support preparation of sales proposals.
- Interviewing potential candidates.
- Being a mentor and/or coach to other team members.
- Support in the development and delivery of training.
- One or more industry relevant certifications or wiliness to obtain relevant certification(s) within two years of employment.
- Certifications can include: CISA, CRISC, CIPP, CISSP, CISM, QSA, ISO/IEC 27001, or PCI ISA.
- Undergraduate Degree (required): preferably in MIS/IS or related concentration - minimum 3.3 GPA.
- Graduate Degree (preferred): preferably in MIS, IS or Accounting Information Systems.
- Relevant work experience (2-4 years).
- Strong communication skills; verbal and written, with the ability to produce excellent written reports and audit documentation.
- Commitment to continual learning and development.
- Commitment to exceptional client service and creative problem-solving ability with a consultancy mindset.
- Flexible, self-starter with the ability to interact with various levels of client and firm management.
- Understanding of information technology risks and internal controls.
- Ability to write test procedures and execute tests of controls.
- Understanding of Service Organization Control, PCI, ISO, HITRUST and/or similar information technology control frameworks.
- Ability to travel up to 40%.
- Ability to manage personal schedule and to lead multiple projects, tasks and deadlines.
About Aprio
Sourced by ZipRecruiter
Industry
Accounting services
Company size
501 - 1,000 Employees
Headquarters location
Atlanta, GA, US
Year founded
1952