Risk Analyst

Alera Group, Inc.

Lansing (MI)

Hybrid

USD 87,000 - 110,000

Full time

2 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Medical insurance
Dental insurance
Vision insurance
Life insurance
Disability coverage
401(k)
Paid time off
Professional development

Job summary

Alera Group, Inc. is seeking a Risk Analyst to perform third-party security and compliance risk assessments for new and existing vendors.

You will review SOC reports, audit documentation, and evidence to identify gaps, coordinate user access reviews, and document remediation plans within GRC platforms. You will partner with Information Security, Legal, Procurement, and other stakeholders to drive risk-based decisions and support audits and regulatory examinations.

Qualifications

  • 5+ years of experience in cybersecurity risk, IT risk, information security, governance, risk and compliance (GRC), third-party risk, IT audit, or a related field
  • Hands-on experience performing third-party or vendor security risk assessments
  • Experience coordinating or performing user access reviews, access certifications, or identity governance activities
  • Familiarity with cybersecurity and compliance frameworks such as NIST CSF, SOC 2, CIS Controls, HIPAA, or similar standards
  • Strong analytical, critical thinking, and communication skills with the ability to evaluate complex situations, identify underlying business and risk requirements, and effectively communicate recommendations to both technical and non-technical audiences
  • Experience working with GRC, ticketing, identity governance, or third-party risk management platforms
  • Exercise sound judgment when evaluating risk scenarios, identifying gaps in information, and determining appropriate next steps, stakeholders, and remediation activities

Responsibilities

  • Perform third-party security and compliance risk assessments for new and existing vendors, evaluating risk exposure, control effectiveness, business impact, and remediation requirements
  • Review SOC reports, security questionnaires, audit documentation, certifications, and other evidence to identify control gaps and potential business impacts
  • Coordinate and execute user access reviews, validating access appropriateness and ensuring identified issues are remediated promptly
  • Document risks, findings, recommendations, and remediation plans while maintaining accurate records within governance, risk, and compliance platforms
  • Serve as a trusted advisor to stakeholders by asking thoughtful questions, identifying underlying business needs, assessing potential risks, and translating ambiguous requests into clear risk assessment, governance, and compliance activities
  • Partner with Information Security, Technology, Legal, Procurement, and business stakeholders to identify requirements, resolve risk and compliance issues, and drive effective risk-based decision-making
  • Support internal and external audits, regulatory examinations, and compliance activities through evidence collection and documentation management
  • Develop risk metrics, reporting, and dashboards that drive visibility, support decision-making, and measure the effectiveness of third-party risk and governance programs
  • Identify opportunities to improve risk management processes, controls, reporting, governance practices, and automation capabilities

Skills

Third‑party risk assessments
SOC 2
NIST CSF
Audit support
Analytical thinking
Communication
GRC platforms

Tools

Identity governance
Access reviews

Job description

Overview

At Alera Group, our corporate teams play a critical role in supporting the success of colleagues and clients across the country. From Human Resources and Finance to Technology, Legal, Marketing, and Operations, these professionals ensure our organization runs efficiently while enabling our teams to deliver exceptional service.

Risk Analyst

Location - Deerfield, IL | Remote

Department - Corporate Services

About Alera Group

Founded in 2017, Alera Group has grown to become the 14th largest broker of U.S. business. We are passionate about our clients’ success in Employee Benefits, Property & Casualty Insurance, and Financial Services. With offices nationwide, our collaborative approach allows us to deliver national strength with local service.

We are always looking to connect with talented professionals who want to contribute to a collaborative, high-growth environment and help drive strategic initiatives across a national organization.

Why Join Alera Group?
  • Collaborate with purpose – Work alongside colleagues who believe the best results come from strong partnerships, shared expertise, and supporting one another.
  • Build your career – Expand your expertise through meaningful work, continuous learning, and opportunities to grow across a national organization.
  • Make an impact – Help clients navigate complex challenges while contributing to solutions that make a difference for their businesses, employees, and communities.
Responsibilities
  • Perform third-party security and compliance risk assessments for new and existing vendors, evaluating risk exposure, control effectiveness, business impact, and remediation requirements
  • Review SOC reports, security questionnaires, audit documentation, certifications, and other evidence to identify control gaps and potential business impacts
  • Coordinate and execute user access reviews, validating access appropriateness and ensuring identified issues are remediated promptly
  • Document risks, findings, recommendations, and remediation plans while maintaining accurate records within governance, risk, and compliance platforms
  • Serve as a trusted advisor to stakeholders by asking thoughtful questions, identifying underlying business needs, assessing potential risks, and translating ambiguous requests into clear risk assessment, governance, and compliance activities
  • Partner with Information Security, Technology, Legal, Procurement, and business stakeholders to identify requirements, resolve risk and compliance issues, and drive effective risk-based decision-making
  • Support internal and external audits, regulatory examinations, and compliance activities through evidence collection and documentation management
  • Develop risk metrics, reporting, and dashboards that drive visibility, support decision-making, and measure the effectiveness of third-party risk and governance programs
  • Identify opportunities to improve risk management processes, controls, reporting, governance practices, and automation capabilities
Required Qualifications
  • 5+ years of experience in cybersecurity risk, IT risk, information security, governance, risk and compliance (GRC), third-party risk, IT audit, or a related field
  • Hands‑on experience performing third‑party or vendor security risk assessments
  • Experience coordinating or performing user access reviews, access certifications, or identity governance activities
  • Familiarity with cybersecurity and compliance frameworks such as NIST CSF, SOC 2, CIS Controls, HIPAA, or similar standards
  • Strong analytical, critical thinking, and communication skills with the ability to evaluate complex situations, identify underlying business and risk requirements, and effectively communicate recommendations to both technical and non-technical audiences
  • Experience working with GRC, ticketing, identity governance, or third-party risk management platforms
  • Exercise sound judgment when evaluating risk scenarios, identifying gaps in information, and determining appropriate next steps, stakeholders, and remediation activities
Certifications
  • CISA, CGRC or equivalent preferred
Preferred Qualifications
  • Experience within a regulated industry such as insurance, financial services, or healthcare
  • Experience supporting SOC 2, HIPAA, NYDFS, or similar regulatory and compliance programs
  • Experience with automated identity governance, access certification, or third-party risk management solutions
  • Experience supporting internal or external security and compliance audits
  • Ability to independently research requirements, develop risk-based recommendations, and communicate findings to stakeholders
  • Demonstrated ability to gather and clarify ambiguous requirements, ask effective probing questions, and develop practical risk-based solutions in collaboration with business stakeholders
Compensation
  • Salary Range - $87,000 - $110,000 annually
  • Bonus Eligible - Yes
Benefits
  • Medical, dental, and vision insurance
  • Life and disability coverage
  • 401(k)
  • Generous paid time off
  • Professional development and career growth opportunities
Additional Information
Work Model

This role is Remote Preference for Central or Eastern Time Zone

Professional Development - Alera Group Academy

At Alera Group, growth isn't left to chance. Through Alera Group Academy, we provide structured development opportunities designed to help you expand your expertise and build a meaningful career.

You’ll have access to :

  • Role-specific learning paths
  • Leadership development programs
  • Technical and compliance training
  • Industry certifications and continuing education support
  • Peer learning and knowledge-sharing communities

Whether you’re deepening technical expertise or preparing for leadership, we’re invested in helping you grow.

We're an equal opportunity employer. All applicants will be considered for employment without attention to race, color, religion, sex, sexual orientation, gender identity, national origin, veteran or disability status, or any other protected class.

Alera Group is committed to protecting your privacy. Please review our Privacy Policy to understand what personal information we may collect and use as part of your application process.

Location Type

Hybrid - 2 or less days in office

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Risk Analyst
Risk Analyst

Alera Group, Inc. • Indianapolis (IN)

Hybrid
USD 87,000 - 110,000
Medical, dental, and vision insurance
Life and disability coverage
401(k)
+2
Risk Analyst
Risk Analyst

Socket.dev • Deerfield (IL)

Hybrid
USD 87,000 - 110,000
Medical, dental, and vision insurance
Life and disability coverage
401(k)
+2
Risk Analyst
Risk Analyst

Dickerson Group • Deerfield (IL)

Hybrid
USD 87,000 - 110,000
Medical, dental, and vision
Life and disability coverage
401(k)
+2
Remote Risk Analyst: Third-Party & IT Security Focus
Remote Risk Analyst: Third-Party & IT Security Focus

Alera Group, Inc. • United States

On-site
USD 87,000 - 110,000
Medical insurance
Dental insurance
Vision insurance
+3
Senior Third-Party Risk Analyst — Remote
Senior Third-Party Risk Analyst — Remote

Socket.dev • Deerfield (IL)

Hybrid
USD 87,000 - 110,000
Medical, dental, and vision insurance
Life and disability coverage
401(k)
+2
Remote Third-Party Risk Analyst
Remote Third-Party Risk Analyst

Alera Group, Inc. • Indianapolis (IN)

Hybrid
USD 87,000 - 110,000
Medical, dental, and vision insurance
Life and disability coverage
401(k)
+2
Remote Third-Party Risk & Compliance Analyst
Remote Third-Party Risk & Compliance Analyst

Dickerson Group • United States

On-site
USD 87,000 - 110,000
Remote work
Bonus eligibility
Professional development
Benefits Coordinator
Benefits Coordinator

Dickerson Group • Deerfield (IL)

Hybrid
USD 55,000 - 65,000
Medical benefits
Dental benefits
Vision benefits
+1
Benefits Coordinator
Benefits Coordinator

Dickerson Group • Town of Deerfield (WI)

Hybrid
USD 55,000 - 65,000
Medical, dental, vision coverage
401(k)
Generous PTO
+1
Senior Benefit Consultant
Senior Benefit Consultant

Dickerson Group • Devon (PA)

Hybrid
USD 115,000 - 150,000
Medical, dental, and vision coverage
401(k) plan
Generous PTO
+1