Information Security Risk Analyst :: Raleigh, NC (REMOTE)

Remote: 
Full Remote
Contract: 
Work from: 

Offer summary

Qualifications:

Experience in IT risk management, cybersecurity, or information security assessment (5 years preferred)., Demonstrated knowledge of NIST SP 800-30, NIST SP 800-53 Rev. 5, and NIST Privacy Framework (5 years preferred)., Familiarity with HIPAA Security and Privacy Rules, and healthcare-specific risk domains (5 years preferred)., Strong written and verbal communication skills for technical and executive audiences (5 years preferred)..

Key responsibilities:

  • Lead the execution of the annual enterprise security risk assessment using NIST SP 800-30, ISO 27005, or FAIR methodologies.
  • Build and maintain a comprehensive risk register with treatment plans for risk mitigation.
  • Develop and deliver documentation, dashboards, and executive summaries for stakeholders.
  • Collaborate with internal stakeholders to validate findings and support security governance efforts.

ARK Solutions, Inc. logo
ARK Solutions, Inc. SME http://www.ARKSolutionsInc.com
201 - 500 Employees
See all jobs

Job description

Ark Solutions Inc is looking for Information Security Risk Analyst!


Position: Information Security Risk Analyst
Location: Raleigh, NC (REMOTE)
Duration: 12+ Months and possibility of extension

Description:

Seeking a skilled Information Security Risk Analyst on a contract basis to lead the execution of its annual enterprise security risk assessment.
  • This engagement ensures compliance with industry-standard frameworks, supports proactive risk mitigation, & positions HIEA for future HITRUST certification. Plan and conduct HIEA annual enterprise security risk assessment using NIST SP 800-30, ISO 27005, or FAIR methodologies.
  • Ensure full alignment with NIST SP 800-53 Revision 5, including: RA (Risk Assessment), AC (Access Control), SC (System Communications Protection), IR (Incident Response), and more.
  • Incorporate NIST Privacy Framework and NIST SP 800-53 Rev. 5 privacy control families (AP, AR, DI, DM, IP, SE, TR, UL).
  • Build and maintain a comprehensive risk register, with treatment plans for mitigation, transfer, acceptance, or avoidance.
  • Map risks and mitigation efforts to HITRUST CSF control domains to support future certification
  • Develop and deliver documentation, dashboards, and executive summaries.
  • Collaborate with internal stakeholders to validate findings and support security governance efforts.
 
Skills Required / Desired Experience
Experience in IT risk management, cybersecurity, or information security assessment Desired 5 Years
Demonstrated knowledge of NIST SP 800-30, NIST SP 800-53 Rev. 5, and NIST Privacy Framework. Desired 5 Years
Experience performing security and privacy risk assessments with documentation aligned to federal and state standards. Desired 5 Years
Familiarity with HIPAA Security and Privacy Rules, and healthcare-specific risk domains. Desired 5 Years
Experience with HITRUST CSF alignment or certification preparation. Desired 5 Years
Strong written and verbal communication skills for technical and executive audiences. Desired 5 Years

Required profile

Experience

Spoken language(s):
English
Check out the description to know which languages are mandatory.

Other Skills

  • Communication

Information Security Analyst Related jobs