Home
/
Comprehensive
/
Information Security Risk & Compliance Analyst
Information Security Risk & Compliance Analyst-March 2024
New York
Mar 28, 2026
About Information Security Risk & Compliance Analyst

  Description/Job Summary

  The Information Security Risk & Compliance Analyst will play a pivotal role in ensuring the seamless and effective management of client audit requests within our Firm. Reporting to the Director of Information Security, you will be responsible for managing and responding to client audit requests in a timely and accurate manner. This position requires a detail-oriented professional with strong organizational and communication skills to facilitate timely and accurate responses to client inquiries. This individual will collaborate with internal teams, coordinate the gathering of information, and craft comprehensive audit responses that align with legal and regulatory standards. Success in this role contributes to positive client relationships, regulatory compliance, and the overall reputation of the organization.

  Responsibilities/Duties

  Serve as the primary point of contact for clients during the audit response process

  Collaborate with internal teams to gather relevant documentation and information needed for the audit response

  Foster effective collaboration with internal teams, including legal, finance, and compliance to gather necessary information for audit responses

  Act as point person and subject matter expert on Information Security Risk Management principles, practices, rules, and procedures

  Develop and maintain a centralized repository for audit-related documentation, ensuring easy retrieval and access for future reference

  Uphold positive relationships with clients throughout the audit response process

  Improve and maintain key performance indicators (KPIs) to measure the efficiency and effectiveness of the audit response process

  Communicate proactively with clients, addressing inquiries and providing updates on the status of the audit response

  Assist team members in support of the Firm's ISO 27001, ISO 27701 and ISO 22301 Information Security Management programs

  Help in the conducting of security audits (3rd party vendors) to ensure that security protocols are being followed and identify areas where improvements can be made

  Monitor legal and regulatory changes and developments; advise Director and develop appropriate strategies, corrective actions, communications.

  Provide guidance to IT group members and firm personnel on related policies, firm procedures, regulatory rules and compliance

  Proactively assesses potential risks and opportunities for improvement

  Perform other duties as assigned

  Required Skills

  Experience with ISO 270002 control framework, SIG-Lite Risk Assessments

  Demonstrated knowledge of security implications involving a variety of technologies including but not limited to; Microsoft, Cisco, Unix/Linux, and other market leaders in technology solutions, including mobile devices.

  Demonstrated knowledge of the global data security regulatory environment

  Strong knowledge of technology risk management concepts and their application

  Must be able to work collaboratively in a team environment and independently

  Ability to handle sensitive and/or confidential material with discretion

  Excellent interpersonal skills and a professional demeanor; ability to work effectively with all levels of Firm personnel and vendors

  Excellent written and verbal communication skills

  Strategic thinker with strong analytical and problem-solving skills

  Demonstrated project management skills, organizational and execution skills with strong attention to detail

  Ability to manage multiple concurrent objectives or activities, and effectively make judgments in prioritizing and time allocation

  Must be flexible in order to respond quickly and positively to shifting demands

  Preferred Skills

  Industry certifications (for example CISSP, CISM, CISA or CGEIT)

  Strong knowledge of risk management frameworks including; ISO 27002, NIST and COBIT 5

  Required Experience

  5+ years of experience in Information Security related responsibilitiesPreferred Experience

  5+ years' experience in Information Security Risk Management or Governance role

  5+ years' experience in Information Technology; ie. networking, desktop

  Experience in a law firm environment a plus

  Required Education

  Bachelor's degree, IT related disciplinePreferred Education

  Professional certifications, such as CISSP, CISA, or CISMDetails

  Salary Information

  The estimated base salary range for this position is $100k to $120k at the time of posting. The actual salary offered will depend on a variety of factors, including without limitation, the qualifications of the individual applicant for the position, years of relevant experience, level of education attained, certifications or other professional licenses held, and if applicable, the location in which the applicant lives and/or from which they will be performing the job. This role is exempt meaning it is not overtime pay eligible.

  Privacy Notice

  For information about how Simpson Thacher & Bartlett LLP collects and processes your personal information, please refer to our Privacy Notice available at https://www.stblaw.com/other/privacy-notice.

Comments
Welcome to zdrecruit comments! Please keep conversations courteous and on-topic. To fosterproductive and respectful conversations, you may see comments from our Community Managers.
Sign up to post
Sort by
Show More Comments
SIMILAR JOBS
Restaurant Manager
Overview At Cracker Barrel, you’ll be joining a special group of people called the Cracker Barrel Family where we value what everyone brings to the table. We care about your wellbeing and success and
Settlements Analyst
SMBC Group is a top-tier global financial group. Headquartered in Tokyo and with a 400-year history, SMBC Group offers a diverse range of financial services, including banking, leasing, securities, c
Senior Coding Specialist
Facility:Work From Home - OhioDepartment:HIM - Hospital CodingSchedule:Full timeHours:40Job Details:The Senior Coding Specialist supports the outpatient coding team by performing claim edit resolutio
Section Chief, Thoracic Imaging NYU Grossman School of Medicine
The NYU Grossman School of Medicine Department of Radiology invites applications for Section Chief of the Thoracic Imaging Section. This is a unique opportunity to head a leading thoracic imaging sec
SMC Comms Specialist I
GCI's SMC Comms Specialist I is responsible to monitor and support critical network elements that maintain continuous operation of network and system infrastructure. Perform proactive network status
Postdoctoral Fellow
Postdoctoral Fellow Bookmark this Posting | Print Preview | Apply for this Job Posting Details Position Details About MSM Morehouse School of Medicine ( MSM ) is a place of distinction, serving as th
(USA) Freezer/Cooler/Deli
Position Summary... Why do people love shopping for fresh food at Sam's Club? Our members tell us one of the biggest reasons is our hard-working and happy-to-help fresh food associates. Join our free
Crew Member
The Wolak Group is currently hiring for a Crew Member to join our network! We are an established Dunkin’ Franchise with 90+ locations and growing. Nothing makes us happier than providing our guests w
Support Escal Eng
With over 17,000 employees worldwide, the Microsoft Customer Experience & Success (CE&S) organization is responsible for the strategy, design, and implementation of Microsoft’s end-to-end cus
Food Service Aide
JOB REQUIREMENTS: Food Service Aide Job ID 273287 Location US-WI-MadisonExperience (Years) 0 Category Food Preparation and Serving - DietaryStreet Address 801 Braxton Place Company Select Specialty H
Copyright 2023-2026 - www.zdrecruit.com All Rights Reserved