Responsibilities Risk Assessment & Management • Assist in conducting information security risk assessments across business units, systems, and processes in accordance with established methodologies ...
Responsibilities Risk Assessment & Management • Assist in conducting information security risk assessments across business units, systems, and processes in accordance with established methodologies ...
Responsibilities Risk Assessment & Management Assist in conducting information security risk assessments across business units, systems, and processes in accordance with established methodologies.
Responsibilities Risk Assessment & Management Assist in conducting information security risk assessments across business units, systems, and processes in accordance with established methodologies.
The successful candidate will support Facility Security Assessments (FSAs), perform risk and data analysis, coordinate with headquarters and field personnel, prepare executive reports and briefings ...
The successful candidate will support Facility Security Assessments (FSAs), perform risk and data analysis, coordinate with headquarters and field personnel, prepare executive reports and briefings ...
The successful candidate will support Facility Security Assessments (FSAs), perform risk and data analysis, coordinate with headquarters and field personnel, prepare executive reports and briefings ...
New
Quick apply
The successful candidate will support Facility Security Assessments (FSAs), perform risk and data analysis, coordinate with headquarters and field personnel, prepare executive reports and briefings ...
New
Risk Assessment Execution: Conduct technology and security risk assessments for internal systems, product and technology projects using established frameworks (NIST SP 800-30, ISO 27005, etc.
Risk Assessment Execution: Conduct technology and security risk assessments for internal systems, product and technology projects using established frameworks (NIST SP 800-30, ISO 27005, etc.
Additionally, the role manages the enterprise security risk intake, security risk assessments, security-based compliance, third-party security review, and security awareness across the enterprise.
New
Additionally, the role manages the enterprise security risk intake, security risk assessments, security-based compliance, third-party security review, and security awareness across the enterprise.
New
Risk Assessment Execution: Conducttechnologyandsecurity risk assessments for internal systems ... TheInformation Security GRCAnalyst partners closely with theManager of Information Security GRC,and ...
Risk Assessment Execution: Conducttechnologyandsecurity risk assessments for internal systems ... TheInformation Security GRCAnalyst partners closely with theManager of Information Security GRC,and ...
Overview Supplier Security, Risk, and Assurance (SSRA) is part of the Information Protection and ... SSRA staff perform and provides assistance with RFx process, supplier risk assessments, contract ...
Overview Supplier Security, Risk, and Assurance (SSRA) is part of the Information Protection and ... SSRA staff perform and provides assistance with RFx process, supplier risk assessments, contract ...
Deliver high-quality, bespoke, verbal and written security risk assessments tailored to an organisation or individual's s profile and itinerary, escalating to senior management as required. Ensure ...
Deliver high-quality, bespoke, verbal and written security risk assessments tailored to an organisation or individual's s profile and itinerary, escalating to senior management as required. Ensure ...
Translate regulatory and framework requirements into actionable governance expectations for IT Security. * Own the end-to-end lifecycle of IT Security risk, including identification, assessment ...
Translate regulatory and framework requirements into actionable governance expectations for IT Security. * Own the end-to-end lifecycle of IT Security risk, including identification, assessment ...
Deliver high-quality, bespoke, verbal and written security risk assessments tailored to an organisation or individual's s profile and itinerary, escalating to senior management as required. Ensure ...
Deliver high-quality, bespoke, verbal and written security risk assessments tailored to an organisation or individual's s profile and itinerary, escalating to senior management as required. Ensure ...
Close coordination with Assistance Centre teams-including Operations, Medical, Transport Desks, and Travel-is essential to integrate security risk assessments into responses and action plans. The SM ...
Close coordination with Assistance Centre teams-including Operations, Medical, Transport Desks, and Travel-is essential to integrate security risk assessments into responses and action plans. The SM ...
IT Security GRC Expert, Global
Center Valley, PA · Hybrid
$42.50 - $56.75/hr
Translate regulatory and framework requirements into actionable governance expectations for IT Security. * Own the end-to-end lifecycle of IT Security risk, including identification, assessment ...
IT Security GRC Expert, Global
Center Valley, PA · Hybrid
$42.50 - $56.75/hr
Translate regulatory and framework requirements into actionable governance expectations for IT Security. * Own the end-to-end lifecycle of IT Security risk, including identification, assessment ...
Experience withthird-party/vendor risk management, regulatory compliance assessments, and security awareness programs. * Experience supporting global environments and contributing to enterprise-wide ...
Experience withthird-party/vendor risk management, regulatory compliance assessments, and security awareness programs. * Experience supporting global environments and contributing to enterprise-wide ...
Experience withthird-party/vendor risk management, regulatory compliance assessments, and security awareness programs. * Experience supporting global environments and contributing to enterprise-wide ...
Experience withthird-party/vendor risk management, regulatory compliance assessments, and security awareness programs. * Experience supporting global environments and contributing to enterprise-wide ...
Cloud Security Engineer
Philadelphia, PA · On-site
$66 - $87.75/hr
Security Risk Advisors Intl., LLC (SRA) is offering a Cloud Security Engineer position. This role ... Conduct cloud security assessments and architecture reviews for new and existing environments.
Quick apply
Cloud Security Engineer
Philadelphia, PA · On-site
$66 - $87.75/hr
Security Risk Advisors Intl., LLC (SRA) is offering a Cloud Security Engineer position. This role ... Conduct cloud security assessments and architecture reviews for new and existing environments.
Cloud Security Engineer
Philadelphia, PA · On-site
$66 - $87.75/hr
Security Risk Advisors Intl., LLC (SRA) is offering a Cloud Security Engineer position. This role ... Conduct cloud security assessments and architecture reviews for new and existing environments.
Cloud Security Engineer
Philadelphia, PA · On-site
$66 - $87.75/hr
Security Risk Advisors Intl., LLC (SRA) is offering a Cloud Security Engineer position. This role ... Conduct cloud security assessments and architecture reviews for new and existing environments.
IT Security Program Manager
Devon, PA · On-site
Manage the third-party risk assessment program , ensuring that all vendors with access to PHI or critical systems undergo security evaluation and periodic reassessment. * Review BAAs , security ...
IT Security Program Manager
Devon, PA · On-site
Manage the third-party risk assessment program , ensuring that all vendors with access to PHI or critical systems undergo security evaluation and periodic reassessment. * Review BAAs , security ...
Cloud Security Engineer
$66 - $87.75/hr
Security Risk Advisors Intl., LLC (SRA) is offering a Cloud Security Engineer position. This role ... Conduct cloud security assessments and architecture reviews for new and existing environments.
Cloud Security Engineer
$66 - $87.75/hr
Security Risk Advisors Intl., LLC (SRA) is offering a Cloud Security Engineer position. This role ... Conduct cloud security assessments and architecture reviews for new and existing environments.
Cybersecurity GRC Manager
Pittsburgh, PA · On-site
$107K - $145K/yr
Conduct IT security risk assessments, documenting risks, impacts, likelihood, and mitigation plans; * Maintain the enterprise IT security risk register and track risks through remediation or formal ...
Cybersecurity GRC Manager
Pittsburgh, PA · On-site
$107K - $145K/yr
Conduct IT security risk assessments, documenting risks, impacts, likelihood, and mitigation plans; * Maintain the enterprise IT security risk register and track risks through remediation or formal ...
Temporary Security Risk Assessment information
What is the difference between Temporary Security Risk Assessment vs Security Analyst?
| Aspect | Temporary Security Risk Assessment | Security Analyst |
|---|---|---|
| Credentials | Certifications like CISSP, CISA often preferred | Same certifications typically required |
| Work Environment | Project-based, short-term assessments | Ongoing security monitoring and analysis |
| Industry Usage | Used during specific projects or audits | Continuous security operations in organizations |
| Search & Comparison Intent | Focus on temporary assessments and risk evaluations | Focus on ongoing security analysis roles |
The main difference is that a Temporary Security Risk Assessment is a short-term, project-specific evaluation of security risks, often used during audits or specific initiatives. In contrast, a Security Analyst performs ongoing security monitoring and analysis within an organization. Both roles require similar certifications and work in security-focused environments, but their scope and duration differ significantly.
Full-time
Re-posted 22 days ago
Victaulic rating
7.2
Based on 35 frontline employees who took The Breakroom Quiz
352nd of 537 rated manufacturers
Job description
The Security Risk & Compliance Analyst supports the organizations global information security program by assisting in the identification, assessment, and management of information security risks and compliance demands across Victaulic's entire organization. This position plays an integral role in ensuring the company meets its obligations under domestic and international regulatory frameworks, including but not limited to, NIST CSF, ISO27001, CMMC and the EU's NIS2 Directive. The analyst will work closely with internal stakeholders, external auditors, and third-party vendors to support a culture of security awareness and continuous compliance improvement.
The ideal candidate for this role will have knowledge of, if not actual experience, in the processes of obtaining and maintaining compliance with security frameworks as well as an understanding of industry standard Information Technology auditing.
Responsibilities
Risk Assessment & Management
• Assist in conducting information security risk assessments across business units, systems, and processes in accordance with established methodologies.
• Document risk findings, assign risk ratings, and track remediation activities through the risk register.
• Support the development and maintenance of risk treatment plans in coordination with system owners and IT teams.
• Participate in annual and ad hoc enterprise risk reviews, contributing analysis and supporting materials.
Compliance & Framework Management
• Support compliance activities related to NIST Cybersecurity Framework (CSF), ISO/IEC 27001, CMMC (Cybersecurity Maturity Model Certification), and the EU NIS2 Directive.
• Conduct gap analyses against applicable frameworks and assist in developing remediation roadmaps.
• Maintain compliance documentation, including policies, procedures, control evidence, and assessment reports.
• Monitor regulatory changes and emerging framework updates; summarize implications for the security program.
Third-Party & Audit Management
• Coordinate and support third-party security audits and assessments, including scheduling, evidence collection, and stakeholder communication.
• Assist in managing vendor risk assessments for new and existing third-party vendors and suppliers.
• Track audit findings and corrective action plans, ensuring timely remediation and closure.
• Serve as a liaison between internal teams and external auditors during certification audits.
Policy, Documentation & Awareness
• Assist in drafting, reviewing, and updating information security policies, standards, and procedures.
• Support the delivery of security awareness training and phishing simulation programs.
• Maintain organized records of all compliance and risk management activities in the Governance, Risk & Compliance platform.
Collaboration & Reporting
• Collaborate with IT, Legal, Operations, and other business functions to integrate security requirements into business processes.
• Prepare regular status reports and metrics dashboards for management review.
• Contribute to the continuous improvement of the information security program by identifying process gaps and recommending enhancements.
Qualifications
Technical Experience
• Foundational understanding of information security principles, including confidentiality, integrity, and availability (CIA).
• Basic understanding of risk assessment methodologies and risk management concepts.
• Familiarity with third-party risk management and audit processes.
• Strong analytical and problem-solving skills with attention to detail.
• Capacity to understand legacy and progressive technology and security controls along with respective risk.
• Working knowledge of technologies such as cloud computing, DevOps, and application security is required.
General Requirements
• Analytical Thinking - applies structured reasoning to evaluate risk and compliance data objectively
• Integrity & Accountability - Handles sensitive security information with discretion and professionalism.
• Communication - Clearly translates security requirements and findings for varied audiences across the organization
• Continuous Learning - Proactively keeps pace with evolving security frameworks, threats, and regulatory requirements
• Collaboration - Builds effective working relationships across IT, operations, and business functions globablly
• Detail Orientation - Produces thorough, accurate documentation and maintains meticulous records of compliance activities
Education & Certifications
• 0 - 2 years' experience in information security, IT audit, risk management, or a related field.
• Bachelor's degree, cybersecurity certification, or equivalent experience in an information security or related field.
• A minimum of an entry-level certification such as the CompTIA Security+ certification
• Additional Risk & Compliance certification(s), such as CISA, a plus
Work Environment & Physical Requirements
This position is primarily office-based with hybrid flexibility. The role may require occasional visits to manufacturing facilities domestically and internationally. Ability to work across global time zones may be required for coordination with European and Asian teams.
Victaulic is an Equal Employment Opportunity (EOE/M/F/Vets/Disabled) employer and welcomes all qualified applicants. Applicants will receive fair and impartial consideration without regard to race, gender, color, religion, national origin, age, disability, veteran status, sexual orientation, genetic data, or other legally protected status. (Background checks may be required as part of our pre-employment process).
What Victaulic employees say
Pay
Benefits
Hours and flexibility
Workplace
Get the full story on Breakroom
About Victaulic
Sourced by ZipRecruiter
Industry
Industrial machinery manufacturing
Company size
1,001 - 5,000 Employees
Headquarters location
Easton, PA, US
Year founded
1919