Ability to analyze complex technical environments and communicate risk in business-focused terms ... Strong knowledge of information security frameworks including NIST CSF, NIST 800‑53, ISO 27001 ...
120 Deloitte Information Security Risk Analyst Jobs Hiring Near You
Ability to analyze complex technical environments and communicate risk in business-focused terms ... Strong knowledge of information security frameworks including NIST CSF, NIST 800‑53, ISO 27001 ...
... information security program in collaboration with other key stakeholders in the Firm. Reporting to the Firm's Security Risk and Compliance Analyst, the assistant will have a range of ...
... information security program in collaboration with other key stakeholders in the Firm. Reporting to the Firm's Security Risk and Compliance Analyst, the assistant will have a range of ...
Strong analytical, documentation, and problem-solving skills. * Experience with reporting tools ... Bachelor's degree in Cybersecurity, Information Security, Risk Management, Information Technology ...
Strong analytical, documentation, and problem-solving skills. * Experience with reporting tools ... Bachelor's degree in Cybersecurity, Information Security, Risk Management, Information Technology ...
Proficient technical skills in planning, administration, and management of information systems, operational and technical security controls, and security risk analysis and management with thorough ...
Proficient technical skills in planning, administration, and management of information systems, operational and technical security controls, and security risk analysis and management with thorough ...
Provide credible challenge of risk analyses, control selection, and control design/operating effectiveness evidence for topics including Information Security and Information Technology risks, privacy ...
Provide credible challenge of risk analyses, control selection, and control design/operating effectiveness evidence for topics including Information Security and Information Technology risks, privacy ...
Strong analytical, documentation, and problem-solving skills. * Experience with reporting tools ... Bachelor's degree in Cybersecurity, Information Security, Risk Management, Information Technology ...
Strong analytical, documentation, and problem-solving skills. * Experience with reporting tools ... Bachelor's degree in Cybersecurity, Information Security, Risk Management, Information Technology ...
Senior Vendor Risk Analyst
Atlanta, GA · On-site
$100K - $130K/yr
Senior Vendor Risk Analyst Location: Hybrid - Candidates must be based in one of the following ... Maintain current knowledge of information security concepts, technologies, and practices * Apply ...
Senior Vendor Risk Analyst
Atlanta, GA · On-site
$100K - $130K/yr
Senior Vendor Risk Analyst Location: Hybrid - Candidates must be based in one of the following ... Maintain current knowledge of information security concepts, technologies, and practices * Apply ...
Corporate Information Security Risk & Vulnerability Analyst
Billings, MT · On-site
$38.66 - $58.01/hr
... in information security governance, risk management, auditing, compliance, and implementation of CIS Controls. Required Skills and Abilities * Vulnerability Management & Risk Analysis: Proficiency ...
Corporate Information Security Risk & Vulnerability Analyst
Billings, MT · On-site
$38.66 - $58.01/hr
... in information security governance, risk management, auditing, compliance, and implementation of CIS Controls. Required Skills and Abilities * Vulnerability Management & Risk Analysis: Proficiency ...
Provide credible challenge of risk analyses, control selection, and control design/operating effectiveness evidence for topics including Information Security and Information Technology risks, privacy ...
Provide credible challenge of risk analyses, control selection, and control design/operating effectiveness evidence for topics including Information Security and Information Technology risks, privacy ...
Corporate Information Security Risk & Vulnerability Analyst
Cody, WY · On-site
$38.66 - $58.01/hr
... in information security governance, risk management, auditing, compliance, and implementation of CIS Controls. Required Skills and Abilities * Vulnerability Management & Risk Analysis: Proficiency ...
Corporate Information Security Risk & Vulnerability Analyst
Cody, WY · On-site
$38.66 - $58.01/hr
... in information security governance, risk management, auditing, compliance, and implementation of CIS Controls. Required Skills and Abilities * Vulnerability Management & Risk Analysis: Proficiency ...
Principal Security Risk Analyst
$97K - $138K/yr
... for analysis. Assist in coordinating the security risk within the context of the security risk ... Assesses and communicates information regarding business risks with functions across the ...
Principal Security Risk Analyst
$97K - $138K/yr
... for analysis. Assist in coordinating the security risk within the context of the security risk ... Assesses and communicates information regarding business risks with functions across the ...
Principal Security Risk Analyst
$97K - $138K/yr
... for analysis. Assist in coordinating the security risk within the context of the security risk ... Assesses and communicates information regarding business risks with functions across the ...
Principal Security Risk Analyst
$97K - $138K/yr
... for analysis. Assist in coordinating the security risk within the context of the security risk ... Assesses and communicates information regarding business risks with functions across the ...
Ability to analyze complex technical environments and communicate risk in business-focused terms ... Strong knowledge of information security frameworks including NIST CSF, NIST 800-53, ISO 27001, CIS ...
Ability to analyze complex technical environments and communicate risk in business-focused terms ... Strong knowledge of information security frameworks including NIST CSF, NIST 800-53, ISO 27001, CIS ...
Senior Vendor Risk Analyst
Atlanta, GA · Hybrid
$100K - $130K/yr
Senior Vendor Risk Analyst Location: Hybrid - Candidates must be based in one of the following ... Maintain current knowledge of information security concepts, technologies, and practices * Apply ...
Senior Vendor Risk Analyst
Atlanta, GA · Hybrid
$100K - $130K/yr
Senior Vendor Risk Analyst Location: Hybrid - Candidates must be based in one of the following ... Maintain current knowledge of information security concepts, technologies, and practices * Apply ...
Corporate Information Security Risk & Vulnerability Analyst
Missoula, MT · On-site
$38.66 - $58.01/hr
... in information security governance, risk management, auditing, compliance, and implementation of CIS Controls. Required Skills and Abilities * Vulnerability Management & Risk Analysis: Proficiency ...
Corporate Information Security Risk & Vulnerability Analyst
Missoula, MT · On-site
$38.66 - $58.01/hr
... in information security governance, risk management, auditing, compliance, and implementation of CIS Controls. Required Skills and Abilities * Vulnerability Management & Risk Analysis: Proficiency ...
Senior Security Risk Analyst (HYBRID)
Hunt Valley, MD · Hybrid
$87K - $153K/yr
We are looking to hire an Senior Security Risk Analyst immediately in a Hybrid (50/50) capacity at ... Process risk acceptance requests and provide necessary information and analysis to allow business ...
Senior Security Risk Analyst (HYBRID)
Hunt Valley, MD · Hybrid
$87K - $153K/yr
We are looking to hire an Senior Security Risk Analyst immediately in a Hybrid (50/50) capacity at ... Process risk acceptance requests and provide necessary information and analysis to allow business ...
Principal Security Risk Analyst
$97K - $138K/yr
... for analysis. Assist in coordinating the security risk within the context of the security risk ... Assesses and communicates information regarding business risks with functions across the ...
Principal Security Risk Analyst
$97K - $138K/yr
... for analysis. Assist in coordinating the security risk within the context of the security risk ... Assesses and communicates information regarding business risks with functions across the ...
Corporate Information Security Risk & Vulnerability Analyst
Denver, CO · On-site
$38.66 - $58.01/hr
... in information security governance, risk management, auditing, compliance, and implementation of CIS Controls. Required Skills and Abilities * Vulnerability Management & Risk Analysis: Proficiency ...
Corporate Information Security Risk & Vulnerability Analyst
Denver, CO · On-site
$38.66 - $58.01/hr
... in information security governance, risk management, auditing, compliance, and implementation of CIS Controls. Required Skills and Abilities * Vulnerability Management & Risk Analysis: Proficiency ...
Ability to analyze complex technical environments and communicate risk in business-focused terms ... Strong knowledge of information security frameworks including NIST CSF, NIST 800‑53, ISO 27001 ...
Quick apply
Ability to analyze complex technical environments and communicate risk in business-focused terms ... Strong knowledge of information security frameworks including NIST CSF, NIST 800‑53, ISO 27001 ...
Corporate Information Security Risk & Vulnerability Analyst
Salt Lake City, UT · On-site
$38.66 - $58.01/hr
... in information security governance, risk management, auditing, compliance, and implementation of CIS Controls. Required Skills and Abilities * Vulnerability Management & Risk Analysis: Proficiency ...
Corporate Information Security Risk & Vulnerability Analyst
Salt Lake City, UT · On-site
$38.66 - $58.01/hr
... in information security governance, risk management, auditing, compliance, and implementation of CIS Controls. Required Skills and Abilities * Vulnerability Management & Risk Analysis: Proficiency ...
Deloitte Jobs Information
What is it like to work at Deloitte?
Do workers at Deloitte get paid breaks?
78% of people say they get paid breaks.
Based on data from 23 people who took the Breakroom Quiz between November 2024 and January 2026.
Does Deloitte pay people when they’re sick?
90% of people say they would get paid if they were sick but scheduled to work.
Based on data from 51 people who took the Breakroom Quiz between May 2025 and April 2026.
At Deloitte, are sick days and vacation days separate paid time off?
79% of people say they have to use vacation days when they’re out sick.
Based on data from 43 people who took the Breakroom Quiz between May 2025 and April 2026.
Is the health insurance from Deloitte affordable enough for their workers?
91% of people say the health insurance costs are okay
Based on data from 43 people who took the Breakroom Quiz between May 2025 and April 2026.
Do people get paid time off at Deloitte?
88% of people say they get paid time off.
Based on data from 51 people who took the Breakroom Quiz between May 2025 and April 2026.
How far ahead of time do people find out their work schedule?
- 71% of people with changing schedules find out their shifts one week or less ahead of time.
- 6% of people with changing schedules find out their shifts two weeks ahead of time.
- 0% of people with changing schedules find out their shifts three weeks ahead of time.
- 24% of people with changing schedules find out their shifts four weeks or more ahead of time.
Based on data from 17 people who took the Breakroom Quiz between March 2025 and April 2026.
Do workers at Deloitte worry about hours?
86% of people report they don’t worry about getting enough hours.
Based on data from 42 people who took the Breakroom Quiz between November 2024 and April 2026.
Do Deloitte workers get to choose the shifts they work?
79% report that they don’t have enough control over which shifts they work.
Based on data from 34 people who took the Breakroom Quiz between December 2024 and April 2026.
How easy is it for Deloitte workers to change shifts?
34% of people report that it’s hard to change shifts if they need to.
Based on data from 29 people who took the Breakroom Quiz between November 2024 and April 2026.
How easy is it to get time off at Deloitte?
82% of people report it’s easy to get time off.
Based on data from 44 people who took the Breakroom Quiz between May 2025 and April 2026.
Do Deloitte managers change schedules at the last minute?
76% of people say their manager doesn’t change their shift schedule at the last minute.
Based on data from 33 people who took the Breakroom Quiz between May 2025 and April 2026.
Do jobs at Deloitte spill into time workers aren’t paid for?
63% of people report that their job takes up time that they don’t get paid for.
Based on data from 35 people who took the Breakroom Quiz between May 2025 and April 2026.
How easy is it to take sick days at Deloitte?
87% of people report that it’s easy to take time off if they are sick.
Based on data from 53 people who took the Breakroom Quiz between May 2025 and April 2026.
Is a Deloitte job good for students?
100% of students report this is a good place to work if you’re studying.
Based on data from 10 people who took the Breakroom Quiz between January 2025 and December 2025.
Is working at Deloitte good if you’re a parent or caregiver?
80% of people who care for a child or other relative report this is a good place to work.
Based on data from 15 people who took the Breakroom Quiz between January 2025 and March 2026.
Do people at Deloitte feel treated with respect by their managers?
92% of people say they’re treated with respect by their managers.
Based on data from 53 people who took the Breakroom Quiz between May 2025 and April 2026.
Do people at Deloitte get to take their breaks without interruption?
72% of people report that they get to take their breaks without interruption.
Based on data from 46 people who took the Breakroom Quiz between May 2025 and April 2026.
Is it stressful to work at Deloitte?
79% of people say they often feel stressed out at work.
Based on data from 56 people who took the Breakroom Quiz between May 2025 and April 2026.
Do people at Deloitte enjoy their jobs?
45% of people report they don’t enjoy their job.
Based on data from 38 people who took the Breakroom Quiz between May 2025 and April 2026.
Do people at Deloitte recommend working with their team?
46% of people report that they wouldn’t recommend working with their immediate team to a friend.
Based on data from 57 people who took the Breakroom Quiz between May 2025 and April 2026.
Do people get enough training when they start at Deloitte?
71% of people report they got enough training when they started working here.
Based on data from 51 people who took the Breakroom Quiz between May 2025 and April 2026.
Do people get support to advance at Deloitte?
In the last year, 80% of people report being given support to advance their career here.
Based on data from 50 people who took the Breakroom Quiz between May 2025 and April 2026.
Do people think Deloitte’s headquarters understands what’s happening where they work?
52% of people think that this employer’s headquarters or owners have a good understanding of what’s really happening where they work.
Based on data from 46 people who took the Breakroom Quiz between May 2025 and April 2026.
Do workers feel well informed about how Deloitte is doing?
67% of people feel that they are kept well informed about how the company is doing as a whole.
Based on data from 51 people who took the Breakroom Quiz between May 2025 and April 2026.

Other
Posted 20 days ago
Job description
The Information Technology and Information Security Risk (IT / IS) Sr. Manager plays a critical enterprise-wide role in overseeing cybersecurity, technology, data, AI and information security risk governance across the Office of Finance (OF). This role partners with the Chief Risk Officer (CRO) and the Enterprise Risk Management team in identifying, assessing, and monitoring the organization's technology and cybersecurity risk profile to ensure alignment with the Office of Finance (OF)'s strategic objectives, risk appetite, and regulatory expectations. This role has broad ownership and visibility across the enterprise and serves as a key second-line risk partner to senior leadership, business lines, IT, Information Security, Compliance, and third-party vendors. The Senior Manager will help ensure adherence to regulatory expectations from agencies such as FHFA, FFIEC, OCC, FDIC, SEC, and FINRA. This person will partner with business lines, IT, and compliance teams to maintain a strong security posture and reduce exposure across critical financial systems and third-party relationships, strengthening the organization's overall cyber resilience and operational risk management framework.
We're proud of the way our teammates have a positive impact on everything we do. Our employees are committed to and exemplify our Core Values:
- Integrity through accountability, consistency, transparency, and trust
- Agility through adaptability, continuous improvement, expertise, and flexibility
- Partnership through collaboration, communication, leadership, and teamwork
- Inclusivity through relationships, respect, and support
- Evaluate and provide independent challenge regarding the alignments of the organization's IT and IS strategy with enterprise business objectives, risk appetite, and regulatory expectations.
- Review and assess the adequacy of information technology and security risk assessments across applications, infrastructure, and business processes.
- Partner with IT project teams to influence decisions related to technology architecture, cybersecurity controls, system implementations, and operational risk mitigation strategies
- Evaluate new and existing systems, platforms, and SAAS integrations for cybersecurity risks and regulatory compliance impacts.
- Conduct third party and vendor security risk assessments, including review of SOC 1/SOC 2 reports, SIG questionnaires, penetration testing results, and remediation plans to ensure vendor information security practices align with OF expectations.
- Provide effective second-line oversight and credible challenge related to cybersecurity incidents, operational disruptions, and emerging technology risks, including analysis of potential impacts to customer data, financial systems, and regulatory obligations.
- Collaborate with business units and technology teams to identify, document, and monitor risks, ensuring remediation activities meet regulatory timelines and internal risk appetite.
- Oversee the implementation of information technology and security risk management policies and the Cyber-Security Incident Response Plan, taking into consideration regulatory compliance expectations and industry best practices.
- Conduct cyber security awareness training and education through periodic email phishing tests, in-person and computer-based training, presentations to employees, and security related tabletop exercises.
- Monitor the status of remediation for IT and IS related issues and ensure that the remediation documentation is complete and adequate.
- Monitor cybersecurity and financial sector threat intelligence; communicate emerging risks to leadership.
- Oversee IT and IS key risk indicators (KRIs) and maintain clear and accurate dashboards and reporting metrics for senior management, risk committees, and regulators.
- Support the OF's core values of Integrity, Agility, Partnership, and Inclusivity.
- Ability to analyze complex technical environments and communicate risk in business-focused terms.
- Strong analytical and problem-solving skills, with attention to detail.
- Strong knowledge of information security frameworks including NIST CSF, NIST 800‑53, ISO 27001, CIS Controls.
- Effective oral and written communication skills for interacting with auditors, examiners, and senior management.
- Ability to build relationships, collaborate with diverse teams, and integrate different perspectives.
- Ability to manage workload with minimal supervision while demonstrating initiative and curiosity.
- Proof of eligibility to work in the United States
- A Bachelor's degree from an accredited college or university; majors in Information Security, Cybersecurity, Risk Management, or related fields (or equivalent work experience) preferred.
- 8–10 years of relevant experience in information security or risk management roles with experience in financial services, banking, payments, fintech, or related regulatory environments preferred.
- Experience with data analytics and visualization tools (e.g., Power BI, Tableau, or Python).
- Experience working in a regulated financial services or technology environment.
- Currently holds relevant professional certifications (e.g., CRISC, CISSP, CISM, Security+ or CGEIT).
The Federal Home Loan Banks Office of Finance is committed to equal employment opportunity without regard to race (including traits historically associated with race, such as hair texture, hair type and protective hairstyles), color, religion, sex, pregnancy (including childbirth, lactation, and related medical conditions), national origin or ancestry, age, physical or mental disability, veteran status, uniformed service member status, military status, sexual orientation, gender identity, status as a parent, marital status, genetic information (including testing and characteristics), citizenship status, or any other characteristic protected by applicable federal, state, or local law.