Perform third party supplier risk assessments by reviewing contracts for compliance with security policies, standards and practices; document security gaps and recommend appropriate remediation ...
Perform third party supplier risk assessments by reviewing contracts for compliance with security policies, standards and practices; document security gaps and recommend appropriate remediation ...
... risk management awareness training programs for all associates, contractors and authorized system users. * Oversees third-party vendor due diligence security reviews to ensure compliance with ...
... risk management awareness training programs for all associates, contractors and authorized system users. * Oversees third-party vendor due diligence security reviews to ensure compliance with ...
... risk management awareness training programs for all associates, contractors and authorized system users. * Oversees third-party vendor due diligence security reviews to ensure compliance with ...
... risk management awareness training programs for all associates, contractors and authorized system users. * Oversees third-party vendor due diligence security reviews to ensure compliance with ...
... risk management awareness training programs for all associates, contractors and authorized system users. * Oversees third-party vendor due diligence security reviews to ensure compliance with ...
... risk management awareness training programs for all associates, contractors and authorized system users. * Oversees third-party vendor due diligence security reviews to ensure compliance with ...
Perform third party supplier risk assessments by reviewing contracts for compliance with security policies, standards and practices; document security gaps and recommend appropriate remediation ...
Perform third party supplier risk assessments by reviewing contracts for compliance with security policies, standards and practices; document security gaps and recommend appropriate remediation ...
Information Security Analyst
Columbus, OH ยท On-site
Information Security Analyst supports enterprise risk management and third-party risk management ... Apply established risk management, governance, and compliance processes across business operations ...
Information Security Analyst
Columbus, OH ยท On-site
Information Security Analyst supports enterprise risk management and third-party risk management ... Apply established risk management, governance, and compliance processes across business operations ...
You will execute risk-based assessments and independent control testing activities from the second ... Security Architecture or Engineering experience * SOX 404 compliance and testing * Risk assessment ...
You will execute risk-based assessments and independent control testing activities from the second ... Security Architecture or Engineering experience * SOX 404 compliance and testing * Risk assessment ...
Senior Security Analyst - REMOTE
Cincinnati, OH ยท On-site
$120K - $140K/yr
The ideal candidate is experienced across both technical security operations and governance, risk, and compliance functions, with the ability to translate complex security concepts into clear ...
Quick apply
Senior Security Analyst - REMOTE
Cincinnati, OH ยท On-site
$120K - $140K/yr
The ideal candidate is experienced across both technical security operations and governance, risk, and compliance functions, with the ability to translate complex security concepts into clear ...
001903 - Information Security Analyst
Columbus, OH ยท On-site
$75K - $100K/yr
Information Security Analyst supports enterprise risk management and third-party risk management ... Apply established risk management, governance, and compliance processes across business operations ...
001903 - Information Security Analyst
Columbus, OH ยท On-site
$75K - $100K/yr
Information Security Analyst supports enterprise risk management and third-party risk management ... Apply established risk management, governance, and compliance processes across business operations ...
Assists in risk assessments, highlighting areas for improvement and supporting remediation efforts ... compliance initiatives. * Familiarity with security frameworks (e.g. NIST CSF, ISO 27001)
Assists in risk assessments, highlighting areas for improvement and supporting remediation efforts ... compliance initiatives. * Familiarity with security frameworks (e.g. NIST CSF, ISO 27001)
Senior Security Analyst - REMOTE
Cincinnati, OH ยท On-site
$120K - $140K/yr
The ideal candidate is experienced across both technical security operations and governance, risk, and compliance functions, with the ability to translate complex security concepts into clear ...
Quick apply
Senior Security Analyst - REMOTE
Cincinnati, OH ยท On-site
$120K - $140K/yr
The ideal candidate is experienced across both technical security operations and governance, risk, and compliance functions, with the ability to translate complex security concepts into clear ...
Assists in risk assessments, highlighting areas for improvement and supporting remediation efforts ... compliance initiatives. * Familiarity with security frameworks (e.g. NIST CSF, ISO 27001)
Assists in risk assessments, highlighting areas for improvement and supporting remediation efforts ... compliance initiatives. * Familiarity with security frameworks (e.g. NIST CSF, ISO 27001)
Drive compliance and risk management : Ensure all materials and processes meet applicable laws ... S. Department of Homeland Security E-Verify program in all facilities located in the United States ...
Drive compliance and risk management : Ensure all materials and processes meet applicable laws ... S. Department of Homeland Security E-Verify program in all facilities located in the United States ...
Assesses security and/or compliance of university systems; responsible for assessing, monitoring and analyzing data, identifying security, risk or compliance issues and/or events Leveraging job aids ...
Assesses security and/or compliance of university systems; responsible for assessing, monitoring and analyzing data, identifying security, risk or compliance issues and/or events Leveraging job aids ...
Experience in the areas of information security governance and third-party risk management. - Required * Experience working with IT risk and compliance frameworks such as NIST (preferred), ISO, COBIT ...
Experience in the areas of information security governance and third-party risk management. - Required * Experience working with IT risk and compliance frameworks such as NIST (preferred), ISO, COBIT ...
Compliance Representative
Cincinnati, OH ยท Hybrid
$71K - $84K/yr
Partners with their assigned Line of Business, other Risk/Compliance/Audit (RCA) professionals, and ... S. Department of Homeland Security E-Verify program in all facilities located in the United States ...
Compliance Representative
Cincinnati, OH ยท Hybrid
$71K - $84K/yr
Partners with their assigned Line of Business, other Risk/Compliance/Audit (RCA) professionals, and ... S. Department of Homeland Security E-Verify program in all facilities located in the United States ...
Services Associate, Risk & Compliance (Tracking & Trading/Broker Data Import Program)
Cleveland, OH ยท On-site
Experience working with securities and financial relationships, including stocks, bonds, mutual ... Work you'll do As a Services Associate, Risk & Compliance (Tracking & Trading/Broker Data Import ...
Services Associate, Risk & Compliance (Tracking & Trading/Broker Data Import Program)
Cleveland, OH ยท On-site
Experience working with securities and financial relationships, including stocks, bonds, mutual ... Work you'll do As a Services Associate, Risk & Compliance (Tracking & Trading/Broker Data Import ...
Services Associate, Risk & Compliance (Tracking & Trading/Broker Data Import Program)
Columbus, OH ยท On-site
Experience working with securities and financial relationships, including stocks, bonds, mutual ... Work you'll do As a Services Associate, Risk & Compliance (Tracking & Trading/Broker Data Import ...
Services Associate, Risk & Compliance (Tracking & Trading/Broker Data Import Program)
Columbus, OH ยท On-site
Experience working with securities and financial relationships, including stocks, bonds, mutual ... Work you'll do As a Services Associate, Risk & Compliance (Tracking & Trading/Broker Data Import ...
Services Associate, Risk & Compliance (Tracking & Trading/Broker Data Import Program)
Dayton, OH ยท On-site
Experience working with securities and financial relationships, including stocks, bonds, mutual ... Work you'll do As a Services Associate, Risk & Compliance (Tracking & Trading/Broker Data Import ...
Services Associate, Risk & Compliance (Tracking & Trading/Broker Data Import Program)
Dayton, OH ยท On-site
Experience working with securities and financial relationships, including stocks, bonds, mutual ... Work you'll do As a Services Associate, Risk & Compliance (Tracking & Trading/Broker Data Import ...
Experience working with securities and financial relationships, including stocks, bonds, mutual ... Work you'll do As a Services Associate, Risk & Compliance (Tracking & Trading/Broker Data Import ...
Experience working with securities and financial relationships, including stocks, bonds, mutual ... Work you'll do As a Services Associate, Risk & Compliance (Tracking & Trading/Broker Data Import ...
Security Risk Compliance information
See Ohio salary details
$30.9K - $38.8K
6% of jobs
$38.8K - $46.6K
0% of jobs
$46.6K - $54.5K
6% of jobs
$60.1K is the 25th percentile. Wages below this are outliers.
$54.5K - $62.4K
17% of jobs
The median wage is $69.8K / yr.
$62.4K - $70.2K
21% of jobs
$70.2K - $78.1K
7% of jobs
$78.1K - $86K
9% of jobs
$86K - $93.8K
7% of jobs
$94.2K is the 75th percentile. Wages above this are outliers.
$93.8K - $101.7K
12% of jobs
$101.7K - $109.5K
6% of jobs
$109.5K - $117.4K
7% of jobs
$30.9K
$77.1K
$117.4K
How much do security risk compliance jobs pay per year?
What is the difference between Security Risk Compliance vs Security Analyst?
| Aspect | Security Risk Compliance | Security Analyst |
|---|---|---|
| Certifications | ISO 27001 Lead Implementer, CISSP, CISA | CISSP, CompTIA Security+, GIAC Security Certifications |
| Work Environment | Policy development, compliance audits, risk assessments | Monitoring security systems, incident response, vulnerability analysis |
| Employer & Industry Usage | Financial, healthcare, government sectors focusing on regulatory adherence | IT departments across various industries focusing on security operations |
Security Risk Compliance professionals focus on ensuring organizations meet regulatory standards and manage security risks through policies and audits. Security Analysts primarily monitor security systems, analyze threats, and respond to incidents. While both roles require security certifications and work within similar environments, their core responsibilities differ: compliance versus active security monitoring.
What are some common challenges faced by Security Risk Compliance professionals when balancing regulatory requirements with business objectives?
What are the key skills and qualifications needed to thrive as a Security Risk Compliance professional, and why are they important?
What is Security Risk Compliance?
- Senior Pci Consultant
- Freelance Technology Risk Consultant
- Senior Information Security Compliance Analyst
- Governance Risk Compliance Intern
- Weekend Vulnerability Analyst
- Cyber Security Risk Analyst
- Global Security Analyst
- Pci Compliance Analyst
- Information Security Compliance Analyst
- Contract Model Risk Governance

Contractor
Posted 4 days ago
Job description
SonSoft Inc. is a USA based corporation duly organized under the laws of the Commonwealth of Georgia. SonSoft Inc is growing at a steady pace specializing in the fields of Software Development, Software Consultancy and Information Technology Enabled Services.
- Implement the overall risk management framework and processes, tools, and reporting methodologies on a continuous cycle.
- Develop and standardize processes and procedures for ongoing risk identification, tracking, monitoring, and evaluating security measures and remediation efforts; communicate security control deficiencies and recommend mitigation plans, report status progress and with non-compliance issues; measure adherence to the security controls from a policy, governance and risk standpoint.
- Perform third party supplier risk assessments by reviewing contracts for compliance with security policies, standards and practices; document security gaps and recommend appropriate remediation actions as necessary to minimize risks to the business.
- Assist with documenting security policies, standards, and guidelines based on the organization's requirements, maturity level, and compliance objectives.
- Facilitate awareness communications to various audiences, coordinate, and maintain project schedules, plans, and scope using standard project management methodologies.
Daily Task Performed:-
- Planning, designing and implementing an overall risk management process for the organization;ย
- Risk identification, analysis, tracking, monitoring, documenting exceptions, and communicating risks to owners
- risk assessment, which involves analyzing risks as well as identifying, describing and estimating the risks affecting the business;
- risk evaluation, which involves comparing estimated risks with criteria established by the organization such as costs, legal requirements and environmental factors, and evaluating the organization's previous handling of risks;
- establishing and quantifying the organization's 'risk appetite', i.e. the level of risk they are prepared to accept;
- risk reporting in an appropriate way for different audiences, for example, to the board of directors so they understand the most significant risks, to business heads to ensure they are aware of risks relevant to their parts of the business and to individuals to understand their accountability for individual risks;
- corporate governance involving external risk reporting to stakeholders;
- carrying out processes such as purchasing insurance, implementing health and safety measures and making business continuity plans to limit risks and prepare for if things go wrong;
- conducting audits of policy and compliance to standards, including liaison with internal and external auditors;
- providing support, education, and training to staff to build risk awareness within the organization
- maintaining current documentation of all related activities for GRC Unit
Musts
- Bachelor degree in Information Systems or equivalent work experience of a minimum of 3-5 years as an information security risk management practitioner, preferably in the financial, consulting, and/or global organizations
- Prior work experience of risk management disciplines, security policies and standards, technology risk assessment, and third party supplier risk process and requirements
- Current or previous experience with risk assessment methodologies and conducting risk analysis in a regulated environment or related IT audit background
- Knowledge of security and control frameworks, such as ISO 27002, NIST, CobiT, COSO and ITIL
- Experience with implementation of information security best practices for key areas such as access control, data protection, systems development life cycle, PCI DSS, and cloud services
- Professional certification in risk management, and/or audit is preferred (e.g., CISSP, CRISC, CISA, or CISM)
Business Experience:-
- Proven ability to work with and across all levels of the organizations and navigate organizational boundaries
- Excellent organizational, interpersonal and communication skills with strong written, oral, and presentation skills; both delivery and creation of power points (must be able to distil complex topics into simple concepts)
- Ability to effectively communicate with technical and executive audiences and develop and maintain strong peer/client/customer relationships underpinned by a service oriented approach to work
- Adept at time management, tasks and projects prioritization, and multi-tasking
- High level of personal integrity, and the ability to professionally handle confidential matters and exude the appropriate level of judgment and maturity
- High degree of initiative, attention to detail, follow-up skills, deliver on commitments, dependability, and ability to work with little supervision
- Demonstrated problem-solving skills and capability to drive process improvements
- Highly proficient with Microsoft Office Suite especially Excel and PowerPoint; and SharePoint administration.
Wants:-
Demonstrate broad competency and understanding in a variety of IT security areas:
- Security Policy Development and Management
- Assist with documenting security policies, standards, standard operating procedures and guidelines based on the organization's requirements, maturity level, and compliance objectives.
- Risk Management
- Perform risk assessments, generate risk reports/updates, tracking progress of remediation efforts.
- Security Awareness
- Facilitate and distribute communications to various audiences to promote about GRC Unit's objectives and goals.
- Information security risk management, risk assessments, reporting, tracking and strong interpersonal and communication skills.
Connect with me atย https://www.linkedin.com/in/mir-hasham-ali/ย (For Direct Clients Requirements)
** U.S. Citizens and those who are authorized to work independently in the United States are encouraged to apply. We are unable to sponsor at this time.
Note:-
- This is aย Contract job opportunityย for you.
- Onlyย US Citizen,ย Green Card Holder,ย GC-EAD,ย H4-EAD & L2-EADย can apply.
- Noย OPT-EAD, H1B & TNย candidates,ย please.
- Please mention yourย Visa Statusย in yourย emailย orย resume.
**ย All your information will be kept confidential according to EEO guidelines.
About Sonsoft
Sourced by ZipRecruiter
Sonsoft , Inc. is a USA based corporation duly organized under the laws of the Commonwealth of Georgia. Sonsoft Inc. is growing at a steady pace specializing in the fields of Software Development, Software Consultancy and Information Technology Enabled Services.
Industry
It services
Company size
51 - 200 Employees
Headquarters location
Alpharetta, GA, US
Year founded
2007