Information Security Risk & Compliance Analyst

Wright-Patt Credit Union

Beavercreek (OH)

On-site

USD 90,000 - 118,000

Full time

41 hours ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Wright-Patt Credit Union is seeking an Information Security Risk & Compliance Analyst to support the enterprise risk program, including Third-Party Risk Management. You will assess vendor risks, document due diligence, and work with Legal on contractual risk terms, while documenting findings in risk systems and guiding remediation efforts.

The role requires experience with risk methodologies, MITRE/NIST, and SOC reporting; travel is expected to various locations.

Qualifications

  • Bachelor’s degree or equivalent work experience in IT, information security, or risk management.
  • Certification in information security or vendor management (CISSP, CRISC, CTPRP, CRVPM or equivalent) preferred.
  • 3+ years in IT or information security, with at least 2 years in third-party/vendor risk management.
  • Familiarity with MITRE framework, PCI-DSS, and NIST RMF.
  • Ability to interpret SOC reports and cybersecurity controls.

Responsibilities

  • Lead Third-Party Risk Management (TPRM) program activities and risk evaluations.
  • Conduct risk assessments for products/technologies using CIS, NIST, MITRE ATT&CK, and OWASP Top 10.
  • Collaborate with Legal and IT to ensure contracts reflect risk due diligence and SLAs.
  • Document findings and residual risks; escalate as needed.
  • Develop and maintain risk assessment methodologies for emerging tech including AI.
  • Support policy updates and governance reporting; manage risk mitigation progress.
  • Coordinate with business units to understand business impacts of identified risks.

Skills

SOC reports interpretation
Vendor risk management
Information security risk management
Third-party risk management
MITRE framework familiarity
PCI-DSS familiarity
NIST RMF familiarity
Certification: CISSP/CRISC/CTPRP/CRVPM

Education

Bachelor’s degree in IT/security/risk

Job description

Department

Enterprise Risk Management

Job Location

3560 Pentagon Blvd, Beavercreek, Ohio, United States

Additional Locations
  • Cincinnati
  • Columbus
Position Type

Full-Time/Regular

Work Type

Variable

NMLS Required

No

Pay Classification

Exempt (Salary)

Grade and Compensation Band

PG 18: $84,427.20 – $126,568.00 (Annually)

Target Compensation

$90,000 - $115,000

Job Overview

The Information Security Risk & Compliance Analyst is responsible for the day-to-day tactical support of WPCU’s Information Security Risk program and Third-Party Risk Management (TPRM) program. The position performs risk assessments for products and technologies following industry recognized frameworks such as CIS, NIST, MITRE ATT&CK and OWASP Top 10. This role is required to work closely with business units, Information Technology, and Enterprise Risk Management. They serve as the Information Security Subject Matter Expert (SME) for vendor risk management and will conduct evaluations of new and existing third-party relationships including but not limited to: conducting document due diligence; supporting contract reviews; and identifying risks associated with vendors. They are responsible for ensuring all risks identified either through Information Security Risk Assessments or TPRM program are properly documented in the Issue Management, seeking regular updates towards resolution, and escalating concerns when needed.

Responsibilities
  • Third Party Risk Management (TPRM) program (40%)
  • Evaluate technology and cybersecurity risks presented by new and existing vendors, disaster recovery, or business continuity.
  • Collaborate with Vendor Risk Management under Enterprise Risk to determine required risk tiers and execute workflows to capture corresponding due diligence requirements.
  • Review and assess due diligence documents for adequacy, control effectiveness, and gaps.
  • Coordinate with business units to understand business impacts of risks identified during the vendor due diligence process.
  • Collaborate with Legal to ensure contract terms are commensurate with vendor due diligence requirements such as identifying Service Level Agreements (SLA), Data Residency requirements, and Data Breach.
  • Document findings, residual risks, and recommendations within the TRPM tools and Issue Management platform.
  • Provide thought leadership on maturing the Information Security components of TPRM.
  • Risk Assessment Methodology (40%)
  • Development of new risk assessments that address emerging technologies such as Artificial Intelligence (AI). Risk Assessment methodology must be based on industry standards such as MITRE and NIST CSF.
  • Execution of existing risk assessments on their assigned basis to determine drift or changes from previous assessments. This may include identification of new risks, updating existing risks, or identifying new / changed / removed controls.
  • Develop and maintain a consistent process for identifying the inherent likelihood, inherent impact, and control effectiveness. Process must be applicable to individual assets, groups of assets, or process.
  • Collaborate with the Information Security team to identify where changes in control effectiveness impact existing risks.
  • Collaborate with Information Security Analysts to build and maintain a control library that properly documents all active/available controls.
  • Ensures proper policies, procedures, risk mitigation activities, and operating controls are followed. Reports gaps in policies, procedures, and operating controls to leadership to ensure member impact and risk is mitigated.
  • Issue Management (20%)
  • Ensure risks exceeding enterprise risk appetite are properly entered into the Issue Management system in a timely fashion.
  • Complete timely and recurring reviews of risk mitigation or remediation plans identified during the risk assessment.
  • Ensure risks identified during projects or Control Effectiveness Reviews are properly tracked in Issue Management.
  • Provide thought leadership on monitoring / reporting of Issue Management.
Required Skills
  • Bachelor’s Degree in information technology, information security, or risk management is required. Candidates without a bachelor’s degree will be considered who can demonstrate equivalent work experience or training.
  • One of the following certifications is required: CISSP, CRISC, CTPRP, CRVPM or similar information security or vendor management certification. Candidates without this certification will be considered, however they will be required to obtain certification within the first year of employment.
  • 3+ years of experience in information technology or information security field required. Must include at least 2 years of experience in third-party risk management, vendor risk management, and information security or cybersecurity risk management.
  • Must have familiarity with MITRE framework, PCI-DSS, and NIST RMF.
  • Must demonstrate the ability to interpret SOC reports and cybersecurity controls.

Valid driver’s license is required as the position will be required to travel to various locations to complete assessments.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Information Security Risk & Compliance Analyst
Information Security Risk & Compliance Analyst

Socket.dev • Beavercreek (OH)

On-site
USD 80,000 - 110,000
Information Security Risk & Compliance Analyst
Information Security Risk & Compliance Analyst

Wright-Patt Credit Union Inc. • Beavercreek (OH)

On-site
USD 90,000 - 120,000
(On-site) Information Security Vendor Management Analyst
(On-site) Information Security Vendor Management Analyst

Centreville Bank • Warwick (RI)

On-site
USD 70,000 - 90,000
Analyst, Third Party Risk Management
Analyst, Third Party Risk Management

Intercontinental Exchange (ICE) • Jacksonville (FL)

On-site
USD 110,000 - 140,000
Analyst, Third Party Risk Management
Analyst, Third Party Risk Management

ICE Clear Europe Limited • Northern (KY)

Hybrid
USD 90,000 - 120,000
Analyst, Third Party Risk Management
Analyst, Third Party Risk Management

Intercontinental Exchange Holdings, Inc. • Atlanta (GA)

On-site
USD 80,000 - 120,000
IT Risk & Compliance Analyst
IT Risk & Compliance Analyst

Trinity Church NYC • New York (NY)

Hybrid
USD 126,000 - 158,000
Information Security Risk & Third-Party Compliance Analyst
Information Security Risk & Third-Party Compliance Analyst

Socket.dev • Beavercreek (OH)

On-site
USD 80,000 - 110,000
Analyst, Third Party Risk Management
Analyst, Third Party Risk Management

ICE • Atlanta (GA)

On-site
USD 85,000 - 120,000
InfoSec Risk & Compliance Specialist
InfoSec Risk & Compliance Specialist

Wright-Patt Credit Union Inc. • Beavercreek (OH)

On-site
USD 90,000 - 120,000