IT Risk Analyst I
Paycom
Date: 3 weeks ago
City: Oklahoma City, OK
Contract type: Full time

Description
The IT Risk team functions include assessing and mitigating risk through internal risk assessments and risk assessments for 3rd party vendors, providing client sales management services, providing security awareness training, maintaining the phishing awareness program, and developing and maintaining IT policies and procedures. Secondary responsibilities include delivering security recommendations for business and technology initiatives and security awareness month coordination.
Responsibilities
Education/Certification:
Education/Certification:
The IT Risk team functions include assessing and mitigating risk through internal risk assessments and risk assessments for 3rd party vendors, providing client sales management services, providing security awareness training, maintaining the phishing awareness program, and developing and maintaining IT policies and procedures. Secondary responsibilities include delivering security recommendations for business and technology initiatives and security awareness month coordination.
Responsibilities
- Perform security risk assessments for business and technology initiatives such as new vendors and supporting software by reviewing security questionnaire responses, utilizing web app scanning technology and open-source software scanning technology, reviewing security compliance reports such as ISO27001, SOC 2, CSA, SIG, and more.
- Provide security recommendations to system and technology owners.
- Assist in coordinating phishing awareness training and simulations.
- Assist in developing IT security and compliance trainings.
- Assist in coordinating security awareness month training and activities.
- Maintain and update policies and procedures related to IT and regulatory compliance.
- Provide compliance sales management services.
- Review critical vendors on a recurring cycle.
Education/Certification:
- Bachelor’s Degree required, CS, MIS or related field preferred
- 0-3 years of IT risk management, IT audit or regulatory compliance
Education/Certification:
- Industry Certification (CISA, CRISC, CISM, CISSP, etc.) preferred
- General knowledge of risks associated with cloud and on-premise technology
- Familiarity with GRC tools, particularly as it relates to vendor risk management
- General knowledge of phishing and social engineering principles
- Open-source software assessment and scanning
- Strong analytical and problem-solving skills
- Highly responsive with an ability to handle escalations quickly and professionally
- Excellent written and verbal communication skills
- Strong research skills and willingness to seek information
- Maintain effective working relationships with supervisor and coworkers
- Interpret and apply laws, regulations, and policies
How to apply
To apply for this job you need to authorize on our website. If you don't have an account yet, please register.
Post a resume