Jobs and Careers
NA

Information Technology Security Risk Control Management Analyst

Natixis Investment Managers
New York, United States, United Statesfull_timeVerifiedPosted 13 Feb 2025
💰 $170,000/yr($125,000/yr$170,000/yr)

About the role

The Information Technology Security Risk Control Management Analyst is a senior-level position focused on identifying, assessing, and mitigating information security risks within the organization. This role encompasses conducting risk control self-assessments (RCSAs), managing risk mitigation strategies, ensuring compliance with relevant regulations, and generating detailed risk reports. The Analyst will collaborate with multiple departments, including IT, Technology Risk Management (TRM), Regulatory Affairs, Legal, and Compliance, to promote cohesive risk management practices throughout the organization. Additionally, the development of metrics and management reports will be a key focus, as this role is vital for safeguarding the organization’s information assets and maintaining data integrity and confidentiality while continuously enhancing risk management and compliance practices.

Key Responsibilities:

  • Lead and coordinate the RCSA process to evaluate the effectiveness of current controls, identify gaps, develop new controls, and recommend enhancements.
  • Conduct regular risk assessments to identify potential threats and vulnerabilities impacting the organization’s information systems and data.
  • Analyze risk data to evaluate the potential impact and likelihood of identified risks.
  • Develop and implement strategies and controls to manage and mitigate identified risks, including recommending improvements to security policies and procedures.
  • Utilize Governance, Risk, and Compliance (GRC) tools to streamline risk management processes, track compliance, and ensure effective governance across the organization.
  • Ensure compliance with relevant regulations, standards, and best practices in information security.
  • Assist in responding to security incidents and breaches, including conducting investigations and recommending corrective actions.
  • Support the risk decision-making process by applying a risk-based approach.
  • Participate in the development and execution of risk treatment plans.
  • Prepare comprehensive risk assessment, RCSA, and GRC reports for senior management, highlighting key risk areas and suggesting actionable improvements.
  • Collaborate with various departments to ensure cohesive and effective risk management practices.
  • Develop and deliver risk control training and awareness programs for staff on information security practices and risk management.

 

The salary range for the VP position will be between $125,000 -$170,000. Natixis is required by law to include a reasonable estimate of the compensation range for this role. Actual base salary will vary and will be based on several factors including, but not limited to, relevant experience, education, skills set, applicable licensure and certifications, and other business and organizational needs. Base salary is only one component of our total rewards package. Natixis also offers a generous benefits package, and you may be eligible for a discretionary incentive award depending on company and individual performance.

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Natixis Investment Managers

View company profile →