Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy
Jobs / Job page
Risk Analyst image - Rise Careers
Job details

Risk Analyst

We believe it takes great people to create a great product. That’s why our team lives our company values, and we hire based on them, too. Since 2010, Pipedrive has been on a mission to support sales and marketing teams with easy-to-use, powerful tools that make everyday work faster and easier. Today, our cloud-based software is trusted by over 100,000 companies and used in 179 countries. We have grown from a five-person team to a truly international company of over 850+ people, representing more than 50 nationalities, with ten offices distributed across Europe and the US. In 2020, Pipedrive received a majority investment from Vista Equity Partners, a global investment firm that invests exclusively in enterprise software, data, and technology-enabled businesses, making Pipedrive the fifth unicorn from Estonia.


The risk analyst is a dual-role position that combines the responsibilities of a security incident manager and a generalist role covering Information Security initiatives, including security awareness and training. This role will be integral in managing security incidents while also supporting various InfoSec activities across the organisation.

If you are someone who will take a proactive approach to identifying and mitigating security risks, enhancing employee awareness, and ensuring the organisation’s compliance with security policies and standards, we'd love to meet you!


The position requires participation in a rotating on-call schedule for incident management to ensure continuous coverage for critical security events.



Your new adventure:
  • Act as an on-call Security Incident Manager (IM), responsible for managing and coordinating responses to security incidents
  • Participate in a rotating on-call schedule and handovers between incident managers
  • Provide clear and timely communication during incidents to all stakeholders, ensuring transparency and coordination across teams
  • Lead post-incident analysis to identify root causes, develop mitigation strategies, and report on incident lessons learned
  • Develop and improve incident management playbooks and processes to ensure efficient and repeatable workflows
  • Monitor and respond to evolving security threats and trends, ensuring appropriate preventive measures are in place
  • Drive the design and implementation of an overall InfoSec awareness program
  • Analyze patterns from security incidents and vulnerabilities to identify potential risks and recommend proactive measures
  • Provide risk assessments and data-driven insights to support leadership in making informed security-related decisions
  • Track and report on key security performance indicators (KPIs) related to both incident management and awareness programs
  • Ensure alignment with regulatory requirements (ISO27001, SOC2 Type 2) and compliance standards by developing training and mitigation strategies for identified risks


Does this sound like you?
  • Bachelor’s degree in a STEM field (Science, Technology, Engineering, or Mathematics), Cybersecurity or Information Security
  • 2+ years of experience in security incident management, incident response, or a similar role in information security
  • Familiarity with security frameworks (e.g., SOC2, ISO 27001) and incident management protocols
  • Excellent written and verbal communication skills
  • Ability to engage with technical and non-technical audiences
  • Strong interpersonal skills
  • Ability to handle high-pressure situations, provide effective communication, and collaborate with cross-functional teams
  • Proactive and adaptable, with the ability to balance multiple responsibilities and manage time effectively
  • Experience in security awareness program management, with a focus on training, phishing campaigns, and program development is a plus


Why Pipedrive:
  • A value-driven work environment where people come first
  • A lively bunch of colleagues from over 50 different countries, with offices in Tallinn, Tartu, Lisbon, Prague, London, Dublin, New York, Florida, Riga and Berlin
  • A team serious about getting things done while not taking ourselves too seriously
  • A world-class working environment full of perks like parties, craft workshops, snacks and, of course, office dogs
  • Flexible working hours as long as you’re there for your team members
  • Freedom to execute your ideas with a passionate and motivated team supporting you
  • Lots of room for personal and career development, with internal and external training opportunities
  • Competitive salary and bonus system and all the benefits you’d expect from a great employer (health and accident insurance, health days, a quarterly contribution to sports, in-house coaches, employee discounts and more) 


Based on this role's access to certain data, Pipedrive might conduct a pre-employment background investigation in conjunction with your application for employment with our company.  Such data will be handled in accordance with Pipedrive's Privacy Policy for Recruitment.

Pipedrive is an equal opportunity employer. We encourage diversity in the workplace regardless of age, gender, race, religion, disability, sexual orientation, gender identity or veteran status.

#LI-Hybrid #LI-LR2


We are looking for a Risk Analyst to join our team in Tallinn.


Pipedrive Glassdoor Company Review
3.6 Glassdoor star iconGlassdoor star iconGlassdoor star icon Glassdoor star icon Glassdoor star icon
Pipedrive DE&I Review
No rating Glassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star icon
CEO of Pipedrive
Pipedrive CEO photo
Dominic Allon
Approve of CEO

Average salary estimate

$60000 / YEARLY (est.)
min
max
$50000K
$70000K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

What You Should Know About Risk Analyst, Pipedrive

If you're ready to dive into the world of Information Security, then the Risk Analyst position at Pipedrive in Tallinn is the adventure you've been waiting for! At Pipedrive, we believe that great people create great products, and we are on a mission to support sales and marketing teams worldwide with powerful, user-friendly tools. As a Risk Analyst, you will play a crucial role in safeguarding our systems while managing security incidents and contributing to our broader InfoSec initiatives. You'll wear two hats—acting as a Security Incident Manager, coordinating responses to security incidents, and engaging in tasks like refining our security awareness programs and developing training strategies. This isn't just a job; it's a chance to proactively identify risks, enhance employee awareness, and ensure compliance with industry regulations. You'll collaborate with a vibrant, multinational team, engage with various departments, and handle fast-paced situations with professionalism. The position requires you to be on call during certain rotations, but don’t worry—we ensure significant support to help you succeed. If you have a STEM degree and a couple of years of relevant experience, along with a knack for clear communication and collaboration, you might just be a perfect fit for Pipedrive. Together, let’s make a positive impact on our organizational security and bring peace of mind to our amazing team of over 850 people in beautiful Tallinn!

Frequently Asked Questions (FAQs) for Risk Analyst Role at Pipedrive
What are the main responsibilities of a Risk Analyst at Pipedrive?

As a Risk Analyst at Pipedrive, your main responsibilities include acting as an on-call Security Incident Manager, coordinating responses during security incidents, and supporting various Information Security initiatives. You'll develop Incident Management playbooks, lead post-incident analysis, and create awareness programs to ensure employee compliance with security standards.

Join Rise to see the full answer
What qualifications do I need to apply for the Risk Analyst position at Pipedrive?

To apply for the Risk Analyst role at Pipedrive, you should have a Bachelor's degree in a STEM field or Information Security. Having at least 2 years of experience in security incident management or a related area is essential, as well as familiarity with security frameworks like SOC2 and ISO 27001.

Join Rise to see the full answer
How does Pipedrive ensure compliance with security regulations like ISO27001 for the Risk Analyst role?

In the Risk Analyst position at Pipedrive, compliance with security regulations like ISO27001 is achieved through the development of training and mitigation strategies for identified risks. You will be responsible for tracking key security performance indicators and ensuring alignment with compliance standards across the organization.

Join Rise to see the full answer
What skills are important for succeeding as a Risk Analyst at Pipedrive?

To excel as a Risk Analyst at Pipedrive, strong communication and interpersonal skills are vital to effectively engage with both technical and non-technical stakeholders. Additionally, the ability to handle high-pressure situations, a proactive mindset, and experience in managing security awareness programs will contribute to your success in this role.

Join Rise to see the full answer
What kind of work environment can I expect as a Risk Analyst at Pipedrive?

At Pipedrive, you can expect a value-driven work environment with colleagues from over 50 countries. The setting is dynamic, encouraging collaboration, creativity, and personal and professional growth. We prioritize flexibility, team support, and a few perks like snacks, workshops, and office dogs to keep things enjoyable!

Join Rise to see the full answer
Common Interview Questions for Risk Analyst
Can you explain your experience with incident response as a Risk Analyst?

In your response, detail your past role in managing security incidents, emphasizing specific incidents you've handled, your responsibilities, and the outcomes. Discuss how you coordinated teams, communicated with stakeholders, and applied learnings to improve incident response protocols.

Join Rise to see the full answer
How do you stay current with emerging security threats?

Share methods you utilize to keep updated, such as following industry blogs, participating in webinars, and being part of professional networks. Mention any certifications or courses you've completed to enhance your knowledge of security trends.

Join Rise to see the full answer
What strategies would you implement to enhance security awareness within the organization?

Discuss your approach, focusing on customizable training sessions, regular phishing simulations, and year-round engagement campaigns. Highlight the importance of making training relatable and easy to absorb for non-technical staff.

Join Rise to see the full answer
Describe a time you identified a security risk and how you addressed it.

Provide a specific example, explaining how you identified the risk, the analysis process you conducted, and steps you took to mitigate it. Emphasize collaboration with teams and the impact of your solutions on the organization’s security posture.

Join Rise to see the full answer
How do you prioritize tasks in a high-pressure environment?

Explain your methodologies for prioritization, emphasizing task urgency, potential impacts, and team collaboration. Share any tools or frameworks you utilize to stay organized and efficient under pressure.

Join Rise to see the full answer
What incident management tools are you familiar with?

List the specific tools and platforms you have used for incident management, explaining your level of expertise with each. Discuss how these tools enhanced your ability to track incidents and communicate with stakeholders.

Join Rise to see the full answer
How do you conduct post-incident analysis?

Outline the steps you follow for conducting post-incident analyses, such as gathering data, identifying root causes, and developing recommendations. Illustrate your examples using cases from your previous experiences and how they led to improved incident management.

Join Rise to see the full answer
What role does communication play in incident management?

Discuss the critical nature of communication during security incidents, emphasizing transparency and clarity with stakeholders. Explain how you adapt your communication style to various audiences and ensure stakeholders are continually informed.

Join Rise to see the full answer
Can you share your experience with compliance requirements like SOC2 and ISO27001?

Talk about your hands-on experience with compliance frameworks, highlighting any audits you've participated in and the specific processes you implemented to ensure adherence to these standards. Mention how you've contributed to policy development or training around these regulations.

Join Rise to see the full answer
What motivates you to work in Information Security?

Share your passion for the field of Information Security, discussing the challenges it presents and how you enjoy solving complex problems. Explain how your values align with Pipedrive's mission to deliver exceptional security in support of its global teams.

Join Rise to see the full answer
Similar Jobs
Photo of the Rise User
Posted 12 days ago
Photo of the Rise User
Pipedrive Remote Czech Republic, Prague
Posted 12 days ago
Photo of the Rise User
Posted 21 hours ago
Photo of the Rise User
Posted 14 days ago
Photo of the Rise User
HackerOne Remote No location specified
Posted 9 days ago
Photo of the Rise User
Posted yesterday

Pipedrive is the easy and effective CRM for small and medium-sized companies. We empower SMBs to unlock their business potential and scale with our easy-to-use, affordable and effective CRM. With Pipedrive, you can track your sales pipeline, manag...

35 jobs
MATCH
Calculating your matching score...
FUNDING
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
EMPLOYMENT TYPE
Full-time, hybrid
DATE POSTED
December 4, 2024

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!