IT Enterprise Risk Analyst

Holland & Knight

Tampa (FL)

On-site

USD 85,000 - 110,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Medical, dental and vision plans
401(k) and profit-sharing
Paid holidays and leave for new parents

Job summary

Holland & Knight in Tampa, FL seeks an IT Enterprise Risk Analyst to manage the firm's GRC and IT risk programs with a focus on information security. The candidate will support policy development, conduct risk assessments, and manage third-party security due diligence.

The ideal applicant will hold a Bachelor's degree in information security or a related field and have at least three years of relevant experience. They will also possess strong communication skills and familiarity with ISO standards.

Qualifications

  • Bachelor’s degree in information security, technology risk management, or relevant field.
  • 3+ years of experience in GRC, information security, or risk management.
  • Working knowledge of ISO/IEC27000 family and NIST CSF.

Responsibilities

  • Support development and maintenance of information security policies.
  • Conduct risk assessments for applications and infrastructure.
  • Perform third-party security due diligence based on vendor criticality.

Skills

Strong written and verbal communication skills
Strong organizational skills
Knowledge of Microsoft Office Suite or Microsoft365

Education

Bachelor’s degree in information security or equivalent
3+ years of experience in information security
Certifications: ISACA CRISC and/or CISA

Job description

Overview

We are a firm that strives for the highest standards of performance and success. This position, based in the firm’s global operations center in Tampa, FL, seeks an IT Enterprise Risk Analyst to join our team. The role manages the firm’s GRC and IT risk programs, focusing on information security for client data, attorney work, and privileged communications.

Key Responsibilities
  • Policy, Standards and Governance: support development, review, and maintenance of information security and technology risk policies, standards, procedures, and guidance documents; maintain policy‑lifecycle processes, stakeholder reviews, approvals, version control; map policies to ISO, NIST, CIS, SOC2, HIPAA, GLBA, GDPR, CCPA, CPRA, and client Outside Counsel Guidelines; administer policy exceptions and risk acceptance workflows; contribute to awareness materials and operative guidance.
  • Information Security and Technology Risk Management: conduct or facilitate risk assessments for applications, infrastructure, cloud services, and firm‑critical legal‑industry platforms; maintain risk register, including inherent and residual ratings and treatment plans; partner with control owners for remediation; support risk monitoring, key risk indicators, and control health metrics; draft risk reporting for governance forums; support incident response activities and post‑incident lessons learned.
  • Vendor/Third‑Party Risk Management (TPRM): perform third‑party security due diligence based on vendor criticality and risk tiering; coordinate security questionnaires and evidence collection; review SOC reports, ISO certificates, penetration test summaries, and other assurance artifacts; identify gaps, recommend remediation, track vendor action plans; partner with Procurement/Legal on contract security requirements; support periodic vendor reassessments; draft responses to inbound client security questionnaires.
  • Audit, Assurance and Compliance: support internal and external audits by coordinating evidence collection, control walkthroughs, and audit responses; assist with gap assessments and control testing against ISO27001/27002, NIST CSF/SP800‑53/800‑171, SOC2, GLBA, HIPAA, GDPR, NIS2, and CUI/ITAR/EAR requirements; track audit findings and corrective action plans; maintain audit artifacts; support EU compliance activities and controlled unclassified information (CUI) handling; compile control attestations for cyber‑insurance applications.
Expected Work Schedule

Maintain a regular and predictable work schedule and full attention during business hours, except as otherwise approved or required by law.

Required Skills
  • Strong written and verbal communication skills, ability to translate control requirements into clear documentation and actionable guidance.
  • Strong organizational skills, meticulous attention to detail, and the ability to manage multiple priorities and deadlines.
  • Knowledge or ability to learn Microsoft Office Suite or Microsoft365.
Required Qualifications & Education
  • Bachelor’s degree in information security, information technology, risk management, business, or equivalent practical experience.
  • 3+ years of experience in GRC, information security, technology risk management, compliance, internal audit, or third‑party risk management.
  • Working knowledge of ISO/IEC27000 family, NIST CSF/SP800‑53/800‑171, and HIPAA.
  • Familiarity with EU information security and privacy requirements (e.g., GDPR) and NIS2 concerns.
  • Experience collecting, organizing, and validating control evidence and supporting audits/assessments.
  • Certifications: ISACA CRISC and/or CISA.
Preferred Qualifications & Education
  • Prior exposure to GRC, IT risk, or information security work in a law firm, professional services firm, or client‑confidential environment.
  • Familiarity with legal‑industry technology (e.g., iManage, NetDocuments, 3E, Aderant, Intapp, Relativity) and data‑sensitivity considerations.
  • Awareness of ABA Model Rules of Professional Conduct (Rules1.1 and1.6) and applicable state bar requirements.
  • Familiarity with CUI handling, NIST SP800‑171, CMMC, and ITAR/EAR data‑handling; prior exposure to federal, defense, or government‑contract client matters.
  • Certifications: ISACA COBITFoundation, CDPSE, CGEIT; ISO/IEC27001 internal auditor, lead implementer, or lead auditor; cloud/platform risk certifications (Microsoft SC‑900, AZ‑500, etc.).
Physical Requirements

Ability to sit or stand for extended periods; moderate to advanced keyboard usage.

Benefits
  • Medical (PPO and HDHPs), dental and vision plans; life and AD&D insurance; short‑ and long‑term disability insurance.
  • Tax‑advantaged health accounts (FSA, HSA), dependent‑care FSA; health advocacy services; behavioral health and counseling resources for all family members.
  • 401(k) and profit‑sharing; backup dependent care; senior care planning support; paid holidays and other paid time off, including paid leave for new parents.
Equal‑Opportunity Employer

Holland & Knight is an Equal Opportunity Employer and does not discriminate on the basis of race, color, religion, sex (including pregnancy, childbirth or related conditions, transgender status and sexual orientation), national origin, age, disability, genetic information, veteran status or any other factor prohibited by law. Applicants who require accommodations during the application process should contact ApplicantAccommodations@hklaw.com.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

IT Enterprise Risk Analyst
IT Enterprise Risk Analyst

Holland & Knight • Miami (FL)

On-site
USD 80,000 - 140,000
Privacy and Compliance Analyst
Privacy and Compliance Analyst

Holland & Knight LLP • Tampa (FL)

On-site
USD 65,000 - 95,000
Medical insurance (PPO & HDHP)
Dental and vision plans
Life and AD&D insurance
+3
IT Service Desk Support Senior Specialist
IT Service Desk Support Senior Specialist

Holland & Knight • Tampa (FL)

On-site
USD 60,000 - 80,000
Comprehensive medical, dental, and vision plans
401(k) and profit sharing
Paid holidays and parental leave
InfoSec Risk & Compliance Analyst
InfoSec Risk & Compliance Analyst

Holland & Knight • Miami (FL)

On-site
USD 80,000 - 140,000
Governance Risk and Compliance Analyst
Governance Risk and Compliance Analyst

Ice Miller LLP • Philadelphia

On-site
USD 75,000 - 100,000
Health insurance
Vision and Dental Insurance
401k (employer match)
+1
IT GRC Lead Analyst
IT GRC Lead Analyst

Westfield Insurance • Westfield Center (OH)

Hybrid
USD 130,000 - 170,000
IT Risk and Compliance Analyst
IT Risk and Compliance Analyst

GT Restructuring • Town of Florida (NY)

Hybrid
USD 75,000 - 100,000
Competitive compensation
Excellent benefits package
Innovative work environment
Human Resources Manager
Human Resources Manager

Holland & Knight LLP • Tampa (FL)

On-site
USD 80,000 - 120,000
Comprehensive medical, dental and vision plans
401(k) and profit sharing
Paid holidays and time off
Manager, Information Security Governance, Risk, and Compliance
Manager, Information Security Governance, Risk, and Compliance

Steptoe LLP • Washington

Hybrid
USD 148,000 - 161,000
Medical, Dental, Vision
401K Plan
Profit-Sharing
+2
IT Risk & GRC Analyst
IT Risk & GRC Analyst

Holland & Knight • Tampa (FL)

On-site
USD 85,000 - 110,000
Medical, dental and vision plans
401(k) and profit-sharing
Paid holidays and leave for new parents