Risk Management Analyst - Business Continuity and Information Assurance

Corporate Opportunities Folsom, California


Description

Salary Range: $89,400.00 - $111,800.00
Exact compensation may vary based on skill, experience and location.
 
 
POSITION PURPOSE 
The Risk & Assurance Analyst within the Enterprise Risk Management (ERM) department plays a pivotal role in supporting Business Continuity Management and Information Assurance at SAFE.   By conducting thorough analyses and recommending robust risk management strategies, this role helps to ensure the continuity of critical business processes and the protection of sensitive information assets. Through proactive identification of potential threats and vulnerabilities, the Risk & Assurance Analyst contributes to the overall resilience and security posture of the organization, to help promote strategic & sustainable growth. Works with all levels of the organization in facilitating the implementation and integration of the risk management activities related to the above programs. The role includes collaborating with IT management and business partners to determine gaps, identifying technical risks of new technology. Executes continuous monitoring reviews, as assigned, and seeks to improve the quality of the programs. 
 
 
ESSENTIAL FUNCTIONS AND BASIC DUTIES 
 
Business Continuity (40%) 
  • Assist in the coordination of annual vendor management review process.
  • Complete other duties and special projects, as assigned.
  • Assist in maintaining an effective business continuity program and assess the maturity levels of the program against goals.
  • Facilitate and coordinate the completion of the Business Impact Analysis review process.
  • Participate in developing and providing business continuity management awareness education to business partners.
  • Participate in the creation, coordination, facilitation, and communication of business continuity exercises, including but not limited to table-top exercises, simulation testing, and full-scale exercises.
  • Assist in evaluating the effectiveness of the disaster recovery planning and testing.
  • Manage and Control SAFE’s business continuity software.
 
Information Assurance (40%) 
  • Supporting the Vendor Risk Committee with the oversight and risk mitigation of vendor relationships and vendor due diligence vetting.
  • Supporting member of the Technical Review Board providing oversight and risk mitigation of new technology and conducting due diligence.
  • Assist in developing risk related training materials.
  • Conduct entity-level phishing campaigns, analyzing results, and preparing monthly reporting materials.
  • Perform regular reviews on SAFE’s Information Security Program to ensure compliance with established security policies and application standards including, but not limited to, Application User Access Review, Terminated Access Reviews, GLBA IT Risk Assessment, and Entitlement Reviews.
  • Manage and Control SAFE’s phish testing software.
  • Validate SOC Report End User Control Responses.
 
Audit and Compliance      (20%)  
  • Assist internal and external auditors as required.
  • Responsible for post examination tracking response specifically for IT audits, ensuring accuracy and compliance with relevant policies and regulations.
 
QUALIFICATIONS 
 
Education/Certification: 
Bachelor’s degree or equivalent from a four-year college or university, at least five years of related experience, with increasing job responsibilities. 
Certification:  
  • CRISC or CISA certification desired, or ability to obtain over the next 36 months.
  • ABCP or CBCP certification desired, or ability to obtain over the next twelve months.
 
Required Knowledge:            
At least one year in a financial institution environment preferred. Sound understanding of various network protocols, firewalls, penetration testing, remote access, network operating systems and vulnerabilities, PC operating systems and vulnerabilities, and network management tools. 
 
Experience Required:            
To perform this job successfully, an individual must be able to perform each essential duty satisfactorily. The requirements listed below are representative of the knowledge, skill, and/or ability required. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions. 
 
Skills/Abilities: 
  • Excellent verbal and written communication skills.
  • Excellent interpersonal, communication, and leadership skills, as success in this position depends on building rapport and credibility with multiple stakeholders across the organization.
  • Superior critical thinking and analytical skills.
  • Ability to research and interpret a variety of professional standards and regulatory guidelines for vendor risk management, business continuity, and information assurance areas.
  • Knowledgeable in major areas of credit union operations, and of regulatory guidelines for vendor risk management, business continuity management, and information security.
  • Ability to work independently, as well as part of department and project teams.
  • Must have strong prioritization skills and be able to multitask.
  • Proficient Excel skills.
 
WORK ENVIRONMENT/PHYSICAL DEMANDS SUMMARY 
 
LANGUAGE SKILLS 
  • Excellent communication skills (verbal, written, listening skills, and empathy).
  • Expert ability to build relationships with other leaders, business partners, and stakeholders.
  • Ability to write reports, business correspondence, and procedure manuals.
  • Ability to effectively present information and respond to questions from groups of managers.
 
MATHEMATICAL SKILLS AND REASONING ABILITY 
  • Ability to interpret a variety of instructions furnished in written, oral, or schedule form.
  • Ability to solve practical problems and deal with a variety of concrete variables in situations where only limited standardization exists.
 
PHYSICAL DEMANDS AND WORK ENVIRONMENT 
The physical demands described here are representative of those that must be met by an employee to successfully perform the essential functions of this job.   
 
  • While performing the duties of this job, the employee is regularly required to sit and talk or hear, and use hands to finger, handle, or feel objects, tools, or controls.
  • The employee is occasionally required to stand; walk; reach with hands and arms; and stoop, kneel, crouch, or crawl.
  • The employee must occasionally lift and/or move up to 10 pounds.
  • Specific vision abilities required by this job include close vision.
  • The noise level in the work environment is usually moderate