Likeremote

Subscribe to the latest remote jobs:

  • Likeremote jobs on https://LinkedIn.com/
  • Likeremote jobs on https://telegram.org/
  • Likeremote jobs on Reddit.com
TikTok USDS logo

GRC Risk Management Analyst

TikTok USDS
  • ๐Ÿ‡บ๐Ÿ‡ธ United States
  • On-site
  • 4 weeks ago
  • Risk Management
  • NIST
  • RMF
  • COBIT
  • DevSecOps
  • IAM
  • Change Management
  • CRISC
  • CISA
  • CISSP
Not scoredNo CV on file. Upload one and this job gets a score out of 100.Upload CV

About the Team

The USDS Security - Governance, Risk & Compliance team is responsible for managing USDS security compliance in accordance with US compliance requirements and objectives, and providing industry leading governance, risk, and compliance services.

The core service offerings include: Compliance & Security Risk Management, Controls & Compliance Framework, Security Compliance Policies, Charters, & Protocols, Vendor Program & Third-Party Risk Management, National Security Reporting and Enablement, and Security & Compliance Behavior & Culture.

About the Role

We are looking for GRC Risk Management Analyst to drive risk register and lifecycle steps including but not limited to: leading risk identification, assign business ownership, perform risk assessments, evaluate control effectiveness, and drive mitigation strategies across stakeholders.

Responsibilities

  • Partner with cross-functional business units to track, reduce, and mitigate security, privacy, and compliance risks.Support the management and communication of the security and privacy risk taxonomy and leveling criteria with partner teams and leadership and align with security risk findings and analysis
  • Support the development, implementation, and documentation of the security and privacy risk intake and analysis program and corresponding processes in adherence with security principles and industry frameworks. Draft operating procedures and document the engagement model with internal partners to drive effective collaboration
  • Review internal and external data sources, identify trends, patterns, and vectors of security and privacy risk to drive treatment prioritization and assessment activities
  • Help define internal and external risk signals and implement risk quantification models (e.g., FAIR) to provide measurable, data-driven outputs.
  • Support conducting Privacy Impact Assessments "PIAs," and conducting privacy risk analysis based on core privacy principles. Mature risk reporting (KPIs/KRIs) to inform leadership decisions, foster a risk-aware culture across the enterprise and support risk rating justifications
  • Drive automation and efficiency in data collection and review functions to facilitate accurate and timely risk factors reviews. Engage in special projects and additional responsibilities may be needed as the team expands and capabilities are enhanced

Minimum Qualifications

  • 3+ years of experience in IT, Cyber, or Enterprise Risk Management in a fast-paced tech environment.
  • Hands-on experience conducting risk assessments, executing risk registers, and tracking remediation plans.Familiarity with industry frameworks such as FAIR, NIST RMF, ISO 31000, or COBIT.
  • Proven ability to translate technical risk concepts for non-technical stakeholders and drive alignment without direct authority.
  • Experience reporting risk (KRIs/KPIs) within a global enterprise, developing a culture of risk informed decision making
  • Excellent communication skills (verbal and written), ability to influence without authority . Experience conducting risk assessments and driving risk mitigation
  • Demonstrates teamwork and collaboration skills, in particular contributing to global and multi-functional teams.Demonstrates excellent organizational direction, time management, and problem-solving skills

Preferred Qualifications

  • Practical experience implementing FAIR or similar quantitative models.
  • Working knowledge of modern security disciplines (e.g., DevSecOps, IAM, Change Management, Cloud Security).
  • Maintain risk related certifications CRISC, FAIR, CISA, or CISSP.
  • Experience operating within highly regulated industries or global enterprise environments.

GRC Risk Management Analyst ยท TikTok USDS

Auto apply with Likeremote