Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy
Jobs / Job page
Information Security Risk & Compliance Analyst image - Rise Careers
Job details

Information Security Risk & Compliance Analyst

Description/Job Summary

The Information Security Risk & Compliance Analyst is responsible for oversite of the firm's data security compliance and risk assessment programs used to provide information security, ensure privacy and facilitate data governance. Reporting to the Director of Information Security, this role serves as the firm's compliance subject matter expert, performing risk assessments (internal and external) monitoring systems for potential risks; and evaluating and recommending technologies.

This role will work with the IS team on identifying vulnerabilities, emerging threats and newly introduced risks to firm systems. This role requires a proactive approach in continual assessment of firm security systems, providing recommendations for enhancements and adapting to new threats and vulnerabilities.

Responsibilities/Duties

  • Act as point person and subject matter expert on Information Security Risk Management principles, practices, rules and procedures
  • Assist team members in support of the Firm's ISO 27001, ISO 27701 and ISO 22301 Information Security Management programs
  • Monitor and maintain the firm's policies and procedures, recommend changes / enhancements, ensuring compliance
  • Conduct security audits (3rd party vendors) to ensure that security protocols are being followed and identify areas where improvements can be made
  • Coordinate third party technical risk assessments and related audit activities
  • Perform internal technical risk assessments and project reviews
  • Produce and maintain information security documentation, including but not limited to policies, procedures, standards, guidelines and diagrams
  • Review and respond to client audit / assessment requests in a timely manner
  • Drive continuous improvement through trend analysis reporting and metrics management
  • Monitor legal and regulatory changes and developments; advise Director and develop appropriate strategies, corrective actions, communications
  • Provide guidance to IT group members and firm personnel on related policies, firm procedures, regulatory rules and compliance
  • Coordinate activities within the firm's vulnerability management program
  • Proactively assesses potential risks and opportunities for improvement
  • Understand the role of systems and technology within the firm and promote a culture of information security risk & compliance across all business units
  • Co-manage the employee annual recertification for various firm policies
  • Perform other duties as assigned

Required Skills

  • 5+ years of experience in information security related responsibilities
  • Experience with ISO 270002 control framework, SIG-Lite Risk Assessments
  • Proficient knowledge of security implications involving a variety of technologies including but not limited to; Microsoft, Cisco, Unix/Linux, and other market leaders in technology solutions, including mobile devices.
  • Demonstrated knowledge of the global data security regulatory environment
  • Strong knowledge of technology risk management concepts and their application
  • Must be able to work collaboratively in a team environment and independently
  • Ability to handle sensitive and/or confidential material with discretion
  • Excellent interpersonal skills and a professional demeanor; ability to work effectively with all levels of Firm personnel and vendors
  • Excellent written and verbal communication skills, ability to communicate clearly and concisely
  • Strategic thinker with strong analytical and problem-solving skills
  • Demonstrated project management skills, organizational and execution skills with strong attention to detail
  • Ability to manage multiple concurrent objectives or activities, and effectively make judgments in prioritizing and time allocation
  • Must be flexible in order to respond quickly and positively to shifting demands

Preferred Skills

  • Industry certifications (for example CISSP, CISM, CISA or CGEIT)
  • 5+ year experience in information security risk management or governance role
  • 5+ year experience in information technology; ie. networking, desktop engineering, programming or systems administration
  • Strong knowledge of risk management frameworks including; ISO 27002, NIST and COBIT 5
  • Experience in a law firm environment a plus

Required Education

  • Bachelor's degree, IT related discipline

Preferred Education

  • Professional certifications, such as CISSP, CISA, or CISM

Details

Salary Information


The estimated base salary range for this position is $130k to $150k at the time of posting. The actual salary offered will depend on a variety of factors, including without limitation, the qualifications of the individual applicant for the position, years of relevant experience, level of education attained, certifications or other professional licenses held, and if applicable, the location in which the applicant lives and/or from which they will be performing the job. This role is exempt meaning it is not overtime pay eligible.

Simpson Thacher Glassdoor Company Review
4.1 Glassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star icon Glassdoor star icon
Simpson Thacher DE&I Review
No rating Glassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star icon
CEO of Simpson Thacher
Simpson Thacher CEO photo
William R. Dougherty
Approve of CEO

When the urge to merge strikes corporate America, Simpson Thacher & Bartlett is ready to serve. The firm's specialties include transactional work and litigation, and it has built a substantial mergers and acquisitions practice over the years. Othe...

10 jobs
MATCH
Calculating your matching score...
INDUSTRY
TEAM SIZE
DATE POSTED
June 10, 2023

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!
Other jobs