Our client is seeking an Information Security Risk Analyst to support policy exception administration, risk analysis, and enterprise risk management activities. The role involves maintaining risk records, processing policy exceptions, and utilizing ServiceNow IRM to support governance and compliance processes.
Review policy exception requests for completeness.
Verify required documentation and business justifications.
Request additional information when needed.
Maintain exception records in ServiceNow.
Track requests through the approval process.
Monitor exception expiration dates and coordinate renewals and closures.
Prepare status reports.
Review policy exception requests using client-approved methodologies.
Evaluate business impact, likelihood, and risk.
Identify compensating controls.
Prepare written risk analyses and approval/denial recommendations for CISO review.
Document analyses in ServiceNow.
Maintain the client's Information Security Risk Register.
Create and update risk records.
Record risks identified through:
Third-party penetration tests
Third-party security assessments
Internal risk assessments
Vulnerability scanning
Policy exceptions
Security incidents
Other approved sources
Track mitigation activities, due dates, and risk status.
Maintain supporting documentation and generate reports.
Process policy exceptions.
Maintain Risk Register records.
Track approvals.
Maintain documentation.
Generate reports and dashboards.
Communicate professionally with:
Department IT Staff
Department Management
Information System Owners
Client Leadership
Office of Enterprise Information Security
Bachelor's degree in one of the following:
Cybersecurity
Information Systems
Information Technology
Computer Science
Business Information Systems
CompTIA Security+
Certified Information Security Manager Fundamentals (CISM-F)
NIST Cybersecurity Framework (NCSF) Practitioner
ISACA IT Risk Fundamentals Certificate
ISACA Cybersecurity Audit Certificate
HIPAA Security Training or Compliance Certificates
Minimum
One (1) year of professional experience in Information Security, IT Governance, Compliance, Risk Management, Information Technology, Audit, or a related field.
Recent graduates with relevant internship or equivalent experience are encouraged to apply.
Preferred
Experience with ServiceNow.
Experience with Microsoft Office 365.
Experience with Governance, Risk and Compliance (GRC).
Experience preparing technical documentation.
Experience in customer service environments.
Experience coordinating projects, tasks, or workflows.
Basic understanding of:
Cybersecurity principles
Information Security
Risk Management
NIST Cybersecurity Framework
Risk Scoring Systems/Quantitative Risk Frameworks
HIPAA
Strong analytical and critical thinking
Excellent written and verbal communication
Customer service skills
Organization and attention to detail
Time management
Ability to learn new technologies quickly
Ability to work independently
Professionalism
Ability to manage multiple priorities
About Cyquent
Cyquent is a CMMI & ISO Certified Technology Enabler providing end-to-end IT solutions and services to organizations in both the public and private sectors since 2001. We are known for delivering high-quality, scalable solutions across complex enterprise environments.
Why Join Cyquent?
This is an opportunity to work alongside a high-performing technology team supporting a wide range of enterprise and public sector clients. You'll gain hands-on experience working on impactful projects in a collaborative and fast-paced environment.
We offer: