Risk Senior Analyst (Remote From Anywhere In CO).

State of Colorado
Full time
Other
United States
Hiring from: United States
Department Information

Together, we innovate for a stronger Colorado

The work of employees at the Governor's Office of Information Technology (OIT) is challenging and diverse because the needs of agencies, customers and Coloradans constantly evolve. But our focus never changes: improve the lives of all Coloradans through innovation and collaboration. We're building one of the nation's leading government IT organizations by reimagining how we support agencies, building first-of-their-kind applications, and creating an inclusive, collaborative culture, together. Join us in the important work of providing equitable access to services.

Watch this video to learn about how OIT is thinking differently!

Description Of Job

IMPORTANT NOTE: Please review your application to ensure completion. For the most equitable applicant experience, OIT’s hiring team considers only the contents of your application to review your qualifications. Please do not include any attachments (such as resume or cover letter) with your application as these items are not used by OIT’s hiring team.

Are you looking for an opportunity to play a critical role in the development and administration of our comprehensive security risk and compliance program at OIT? As our new Senior Risk Analyst , you will be responsible for ensuring our adherence to all established legal, statutory, and contractual requirements . Your work in this role will be integral to strengthening our overall security posture and upholding the integrity and confidentiality of state information systems.

As a key member of our team, your primary responsibilities include planning, developing, and managing risk assessment initiatives to systematically identify, quantify, and prioritize risks against established criteria. You will also collaborate across functional teams, partner with subject matter experts, and serve as a primary liaison to external partners.

Your expertise will also be instrumental in translating complex risk findings for stakeholders, providing clear interpretation and guidance. That guidance, and your validation of remediation efforts, will ensure they have been satisfactorily completed and that all policies and procedures are accurately implemented and documented.

Key Responsibilities Include

  • Developing and maintaining comprehensive security policies and procedures, ensuring adherence to all legal, state, and contractual regulations.
  • Planning and conducting security risk assessments; acting as the primary contact for internal and external risk assessments, including collaborating with teams to gather information and prepare official responses.
  • Developing and tracking Plans of Action & Milestones (POA&Ms) to address and resolve identified risks or compliance gaps, and following up to ensure solutions are effective and properly documented.
  • Reviewing and assessing the security posture of new vendors, contractors, and their associated contracts.
  • Enhancing risk and compliance activities to increase efficiency and effectiveness, and integrating security requirements into project implementation plans.
  • Building and reporting on the risk program, and continuously improving formal risk management processes, including tracking key metrics, generating security trend reports, and presenting findings to team leaders.
  • Serving as a key decision-maker for new project launches, providing final approval once all security and compliance standards have been met.

Minimum Qualifications, Substitutions, Conditions Of Employment & Appeal Rights

A wide salary range is posted for this position and any job offer is based upon a salary analysis to comply with the Colorado Equal Pay for Equal Work Act. The salary analysis considers relevant experience, education, certifications, and state seniority as compared to others doing substantially similar work. While all offers are compliant with the Colorado Equal Pay for Equal Work Act, there is no guarantee an offer will be at the top of the posted range based on the salary analysis.

Minimum Qualifications

This is a skills-based job announcement. The required minimum qualifications and/or education (if substituting for the proven experience, knowledge, and skills), are as follows:

  • Five (5) or more years of work experience in the IT Security field, including Risk and Vulnerability Management, and Compliance and Audit Management.
  • Risk Assessment experience.

Substitutions

  • Training or Certification related to the work assigned to the position will be assigned credit towards substitution for experience and/or education, but cannot completely substitute for these qualifications.
  • If the minimum qualifications include a degree requirement, additional appropriate paid or unpaid experience will substitute for the required education on a year-for-year basis.

Preferred Qualifications

  • CISA or CISSP certifications.
  • CRISC certification.
  • Knowledge or experience in SOC1 and SOC2, and other compliance reports.
  • Project Management experience.

Conditions Of Employment

OIT employees must comply with any screening procedures in place at state entity locations where they might be required to perform work.

A pre-employment background check will be conducted as part of the selection process.

Positions supporting some agencies such as the Department of Corrections and the Department of Public Safety will also require a pre-employment drug test.

This position may require travel within the specified geographic area, and to locations across the state as needed.

Supplemental Information

If this posting indicates “remote from anywhere in CO” in the title, periodic reporting to the primary state work location designated for the position is required. All remote work must be performed in Colorado.

While candidates from out of state will be considered for this role, the candidate selected for the position must relocate and reside in Colorado on the first day of their new position. A reasonable timeframe for relocation will be established on an individual basis, while considering business needs, and determining a start date.

We know it's important to support each other, and that means having a healthy balance of work and personal time. Visit our benefits to learn more about some of our great offerings that allow us all to have fulfilling lives.

Visit our How to Apply webpage to learn more about our application process and what to expect after you apply.

The State of Colorado strives to create a Colorado for All by building and maintaining workplaces that value and respect all Coloradans through a commitment to equal opportunity and hiring based on merit and fitness. The State is resolute in non-discriminatory practices in everything we do, including hiring, employment, and advancement opportunities.

The Governor's Office of Information Technology is committed to the full inclusion of all qualified individuals. As part of this commitment, our agency will assist individuals who have a disability with any reasonable accommodation requests related to employment, including completing the application process, interviewing, completing any pre-employment testing, participating in the employee selection process, and/or to perform essential job functions where the requested accommodation does not impose an undue hardship. If you have a disability and require reasonable accommodation to ensure you have a positive experience applying or interviewing for this position, please direct your inquiries to our ADA Coordinator at [email protected] or call (303) 764-7900.

This posting may be used to fill multiple vacancies based upon business need.

The Governor's Office of Information Technology does NOT offer sponsored Visas for employment purposes.

How to apply

To apply for this job you need to authorize on our website. If you don't have an account yet, please register.

Post a resume

Similar jobs

Road Runner Sports
Full time
16 - 19 USD / hour
As a Work From Home "Customer Service Representative" , you'll work directly with customers who call our inbound phone center, selling them top fitness products and services and be the voice of Road Runner Sports, the world’s largest running and...
Other
United States
Hiring from: United States
About Moncel Moncel is one of the fastest growing companies in the online education space. With 7 international brands, and operations in Canada, Australia, and the United States, we are an exciting blend of the technology and learning sectors. Our...
Other
Canada
Hiring from: Canada
Endeavour Consulting for Non-Profits
Volunteer
ORGANIZATION  Based in Toronto, Endeavour Volunteer Consulting for Non-Profits is a Canadian charity, 100% volunteer-led that provides management consulting to improve organizational capacity and community impact for non-profits that otherwise cannot afford professional consulting.  Endeavour has two consulting engagement rounds...
Other
Canada
Hiring from: Canada