Senior IT Risk & Security Analyst — Remote

Symetra Financial Corporation

Northern (KY)

Hybrid

USD 80,000 - 133,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Flexible hybrid schedule
401(k) matching
Paid time off & holidays
Company matching gifts

Job summary

Symetra seeks a Senior IT Risk and Security Analyst to lead IT risk management and information security efforts within a dynamic governance framework. You will coordinate with IT, audit services, and business teams to assess controls, report on risk, and drive remediation across the organization.

You will manage third-party risk, support ISO 27001 compliance, and develop executive dashboards communicating risk, audit results, and remediation progress to senior leadership.

Qualifications

  • You're an analytical problem solver with a strong understanding of information security, IT risk management, audit methodologies, compliance frameworks, and internal controls.
  • You have experience managing complex risk assessments, audit programs, and compliance initiatives, with the ability to translate technical risks into business-focused recommendations.
  • You're an effective communicator who can confidently collaborate with executives, auditors, IT leaders, business stakeholders, and external vendors to influence positive outcomes.
  • You thrive working independently while also serving as a trusted advisor, mentor, and subject matter expert for colleagues and cross-functional teams.
  • You possess strong organizational skills and attention to detail, enabling you to manage multiple priorities, maintain accurate documentation, and deliver high-quality results in a fast-paced environment.

Responsibilities

  • Serve as a trusted advisor to IT and business teams by identifying technology, security, and operational risks, recommending effective controls, and ensuring risks are properly assessed, documented, and mitigated.
  • Lead enterprise IT risk management activities, including annual risk assessments, risk committee facilitation, risk reporting, policy development, risk register management, and continuous improvement of the organization's risk management framework.
  • Support third-party technology risk management across the vendor lifecycle, including risk tiering, pre-contract due diligence, security assessments, and periodic monitoring. Evaluate SOC reports, ISO 27001 certifications, security questionnaires, penetration tests, external security ratings, encryption and data-handling practices, AI usage, contractual controls, and business continuity capabilities; document risk ratings and findings, drive remediation, and elevate unresolved risks in partnership with Procurement, Legal, business owners, and security teams.
  • Manage and enhance IT audit and compliance programs, including SOX IT General Controls (ITGCs), ISO 27001 security controls, regulatory requirements, and internal/external audit activities to ensure controls are designed and operating effectively.
  • Partner with control owners, auditors, and business stakeholders to track audit findings, drive remediation efforts, provide training, and ensure sustainable compliance across technology and business functions.
  • Evaluate third-party vendors, emerging technologies, and business initiatives to identify security and operational risks, implement monitoring controls, and support disaster recovery and business continuity planning efforts.
  • Develop executive-level reporting and dashboards that communicate risk exposure, audit results, compliance status, and remediation progress to senior leadership and governance committees.
  • Conduct reviews of information systems, business applications, infrastructure, and operational processes to assess security posture, control effectiveness, and alignment with company objectives.
  • Maintain ownership of risk management tools and processes, ensuring accurate documentation, reporting, workflow management, and ongoing program maturity.

Skills

Information security
IT risk management
Audit methodologies
Compliance frameworks
Internal controls
Stakeholder communication

Education

Bachelor's degree

Job description

Symetra seeks a Senior IT Risk and Security Analyst to lead IT risk management and information security efforts within a dynamic governance framework. You will coordinate with IT, audit services, and business teams to assess controls, report on risk, and drive remediation across the organization.

You will manage third-party risk, support ISO 27001 compliance, and develop executive dashboards communicating risk, audit results, and remediation progress to senior leadership.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior IT Risk & Security Analyst - Remote
Senior IT Risk & Security Analyst - Remote

Symetra • United States

Remote
USD 80,000 - 133,000
Flexible full-time or hybrid telecommu
401(k) with company matching up to 6%
Paid time off + holidays
+1
Senior Risk & Information Security Leader (Remote)
Senior Risk & Information Security Leader (Remote)

Omnissa, LLC in • Mountain View (CA)

On-site
USD 175,000 - 220,000
Health insurance
401(k) with matching
Paid time off
+2
Senior IT Security Analyst - Remote with IAM, SIEM & IR
Senior IT Security Analyst - Remote with IAM, SIEM & IR

Equity Resources, Inc • Town of Newark (WI)

Hybrid
USD 120,000 - 160,000
401(k) match
Pet insurance
Generous PTO
+2
Remote Senior IT Security Manager - Risk, Compliance & SOC
Remote Senior IT Security Manager - Risk, Compliance & SOC

Trinity Global Consulting • Springfield (VA)

Remote
USD 90,000 - 110,000
Information Security Risk Analyst
Information Security Risk Analyst

Compunnel, Inc. • San Francisco (CA)

On-site
USD 90,000 - 120,000
Remote Senior InfoSec GRC Analyst — ISO 27001 & SOC 2 Lead
Remote Senior InfoSec GRC Analyst — ISO 27001 & SOC 2 Lead

United States Digital Space LLC • United States

Remote
USD 127,000 - 205,000
Remote & Flexible
Annual kickoff and team meetups
Senior IT Security Analyst | Risk & Vulnerability Leader
Senior IT Security Analyst | Risk & Vulnerability Leader

TridentCare • United States

On-site
USD 110,000 - 150,000
Senior InfoSec & Risk Analyst – Hybrid/Remote
Senior InfoSec & Risk Analyst – Hybrid/Remote

CCSI CC Services, Inc. • United States

Hybrid
USD 94,400 - 129,800
Insurance benefits
Paid time off
Tuition assistance
+1
IT Risk & Governance Manager — Remote/Hybrid
IT Risk & Governance Manager — Remote/Hybrid

Wilson Sonsini Goodrich & Rosati, Professional Corporation • Palo Alto (CA)

Hybrid
USD 147,050 - 220,800
Discretionary year-end merit bonus
Executive IT Risk Operations Leader (Remote/Hybrid)
Executive IT Risk Operations Leader (Remote/Hybrid)

Jobgether • United States

Hybrid
USD 150,000 - 220,000
Competitive salary
Flexible remote or hybrid work
Professional development
+1