Senior Information Security Risk Analyst

  • FM
  • Johnston, Rhode Island
  • 09/02/2026
Full time Information Technology Telecommunications

Job Description

FM seeks a Senior Information Security Risk Analyst to lead cyber and technology risk activities across the organization. You will perform detailed risk assessments on applications, infrastructure, and vendors, identify control gaps, and recommend pragmatic remediation plans. Partnering with IT, security, and business teams, you'll maintain risk registers, metrics, and reports aligned to frameworks such as NIST and ISO 27001. You will support policy development, third-party risk reviews, and incident response, helping FM strengthen its security posture while enabling business objectives.

Responsibilities

  • Lead information security risk assessments across systems, applications, and vendors.
  • Identify, analyze, and prioritize security risks and control gaps.
  • Recommend and track remediation plans with IT and business stakeholders.
  • Support third-party risk reviews and ongoing vendor monitoring.
  • Develop and maintain risk registers, metrics, and dashboards.
  • Align FM's security posture with frameworks such as NIST and ISO 27001.
  • Support policy, standard, and procedure development and updates.
  • Contribute to incident response by assessing business and control impacts.
  • Prepare clear reports and presentations for leadership and audit partners.
  • Collaborate with cross-functional teams to embed security into projects and change initiatives.

Required Skills

  • Information security risk assessment
  • Third-party/vendor risk management
  • NIST CSFISO 27001
  • SOC 2 controls
  • Cloud security (AWS/Azure/GCP)
  • Vulnerability management
  • Security incident response
  • GRC tools (e.g., Archer, Service
  • Now GRC)
  • Report writing & executive risk reporting