Lead Security Analyst
GartnerAbout the role
About Gartner IT:
Join a world-class team of skilled engineers and analysts who build creative digital solutions to support our colleagues and clients. We make a broad organizational impact by delivering cutting-edge technology solutions that power Gartner. Gartner IT values its culture of nonstop innovation, an outcome-driven approach to success, and the notion that great ideas can come from anyone on the team.
About the role:
Gartner is looking for a well-rounded and motivated Lead Security Analyst to join its Governance Risk Management team which is responsible for providing IT Risk Management; IT Policies, Standards and Controls; and Audit/Governance oversight. The Lead Security Analyst should have extensive experience with developing and implementing risk frameworks, understanding regulatory requirements, and assessing control compliance.
What you will do:
Responsible for supporting Gartner’s security control environment by managing risk associated with Information Technology, Information Security, Privacy, Regulatory Compliance and Governance.
This individual will play an integral role in: (i) working closely with Information Security partners, and technology stakeholders to audit/test controls; (ii) ensuring risks are identified and understood; and (iii) developing and tracking risk remediation plans across our various business units.
Serve as subject matter expert and manage Risk Reviews / Risks / Risk Exception Requests
Assess our control effectiveness and conduct control gap analysis against key Frameworks/Standards such as NIST, SOX, CMMC, ISO 27001, GDPR, etc.
Track and monitor remediation and risk treatment plans.
Develop testing routines and schedules for our key regulatory requirements.
Understand and consider all relevant trade-offs required to manage different levels of risk tolerance and risk exposure across the organization and be able to communicate to responsible team members.
Partner with internal Security Operations and Engineering to ensure risks are well understood and proposed countermeasures are effective at mitigating risk.
Coordinate with technology, audit, ERM, and information security stakeholders to assess, implement, and monitor information security-related risks/threats.
Support and advise business-led projects on information security-related risks and standards compliance.
Lead efforts to implement and maintain security policies and remediation processes.
Perform proactive technical research to detect emerging risks and threat trends.
Understand “voice of the customer” and develop mechanisms to proactively sense adoption and usage patterns of current or emerging consumer technologies so that policy can align with need.
Provide leadership/peers/business with reporting and timely updates that tells the story needed for the audience.
Continuously look for ways to improve (quality and efficiency) the process.
Take ownership of assignments & drive them to completion.
Work collaboratively across functional areas for innovation to turn new ideas into reality.
Assist others on the team for Policy and Certification/Assessment efforts, Client support including contract reviews.
What you will need:
Ideal candidates have experience in IT with a strong understanding of Information Security. Candidates should have strong communication and attention to detail. Strong communication to partner with many departments within Gartner as well as occasionally working directly with clients. Strong attention to detail to ensure we provide accurate and consistent Risk Reviews, Audit Assessments, answers to stakeholders (including clients), as well as thorough reviews of contracts/documents.
Bachelor's or master's degree in computer science, information systems, cybersecurity or a related field.
7-10 years of experience in IT and/or Information Security.
Proven communication, collaboration, critical thinking skills and attention to detail.
Familiarity with technical security controls, guidelines, certifications, regulations and framework (e.g., NIST CSF, NIST 800-171, SOX, CMMC, ISO 27001, GDPR).
Experience with Risk Registry, Risk Exceptions, Audit Process, Policy/Standard/Controls.
Ability to define and communicate risk in a business-relevant language and to non-technical audiences.
Deep technical expertise in at least one additional area of Information Security.
Experience with Information Security, Physical Security, Legal, and other IT processes and functions.
Experience with implementing national and international r
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s