What are the responsibilities and job description for the IT Risk Analyst position at Princeton University?
Overview
The Information Technology Risk Analyst reports to the Associate Director of IT Risk and Awareness in the Information Security Office, and participates in the tracking, assessment, reporting and communications for the campus wide risk assessment process.
As a member of the ISO team, this role participates in the mitigation of risk to Princeton University by following and contributing to the improvement of mitigation processes, sharing guidance to university staff, and tracking and reporting on deviations from best practices in IT risk.
As the Information Technology Risk Analyst, you will be responsible for tracking and reporting on campus-wide risk assessments, documenting and monitoring risk mitigation and compliance tasks, and providing written, remote, or in-person support to the campus community. This position will focus on the tracking and reporting of risk issues, as well as assisting to educate the campus community on both continuous risk assessment, and broader information security issues. To fulfill this role, the individual will use modules in the ServiceNow platform for collecting and analyzing assessment survey results.
Responsibilities
- As part of a small team, participate in the day-to-day operations of the IT risk assessment team under the guidance of the Associate Director of IT Risk and Awareness and Lead IT Risk Analyst in the ISO
- Utilize data from ServiceNow dashboards for risk identification and mitigation
- Assist in documenting operations and business functions that may require risk mitigation assistance
- Contribute in identifying, developing, and participating in necessary IT risk training
- Maintain current understandings of administrative, technical, and operational controls needed for compliance requirements
- Understand information risk management concepts and their proper application
- Develop an understanding of information security concepts
- Assist in risk-related service requests
- Build relationships with colleagues across campus to identify and align best practices
- Understand the NIST Cyber Security Framework (CSF) guidelines
- Other duties as assigned in support of the ISO mission
- Participate in the development and upkeep of documentation for the ISO and campus risk assessment needs
- Participate in preparing and documenting risk assessment reports and metrics
- Assist in the identification, creation and delivery of risk and security related topics
Qualifications
Essential Qualifications
- At least 3 years of experience and the passion to collaborate with colleagues and customers from different levels of the organization and with varied levels of technical understanding
- Excellent and proven oral and written communications skills
- Strong time management and multitasking skills as well and attention to detail
- Experience in data analysis, and report generation
- Flexible, proactive, and possessing a can-do attitude, with a willingness and enthusiasm for learning new technologies and techniques that support evolving needs
- Education: Bachelor’s degree desired
Preferred Qualifications
- Experience in higher education
- Experience with ServiceNow, especially the modules of Security Incident Response and Integrated Risk Management, is preferred
- Familiarity with the NIST Cyber Security Framework is a plus
- Comfortable with impromptu tasking and loosely defined requirements
- Collaborative skills and the ability and desire to work in a diverse team of security professionals
- Possessing a blend of intellectual curiosity, creativity, persistence, commitment, passion, and optimism, with a continual desire for self-improvement and learning
- Comfort and desire to lead awareness and training sessions in both risk and basic security threats
Princeton University is an Equal Opportunity/Affirmative Action Employer and all qualified applicants will receive consideration for employment without regard to age, race, color, religion, sex, sexual orientation, gender identity or expression, national origin, disability status, protected veteran status, or any other characteristic protected by law. KNOW YOUR RIGHTS
Standard Weekly Hours
36.25Eligible for Overtime
NoBenefits Eligible
YesEssential Services Personnel (see policy for detail)
NoPhysical Capacity Exam Required
NoValid Driver’s License Required
NoExperience Level
Mid-Senior Level