Senior Risk Analyst

Xerox Corporation

Northern (KY)

Hybrid

USD 146,000 - 195,000

Full time

24 hours ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Xerox Holdings Corporation is seeking a Sr. Risk Analyst to support and lead cybersecurity risk initiatives within our GRC organization. You will assess, monitor, and report on cybersecurity and third-party risk using CIS Controls and the NIST CSF.

The role focuses on Third-Party Risk Management, CMMC and FedRAMP compliance, risk register management, and executive-level reporting. Remote work within the United States is supported.

Qualifications

  • Bachelor’s degree in a related field or equivalent practical experience.
  • 5+ years of information security, IT risk management, audit, or compliance experience.
  • Experience leading or mentoring analysts or project teams.
  • Strong knowledge of CIS Critical Security Controls and the NIST Cybersecurity Framework.
  • Experience with third-party/vendor risk management programs and due diligence.

Responsibilities

  • Lead and perform cybersecurity risk assessments using CIS Controls and the NIST CSF.
  • Mature Third-Party Risk Management processes, including vendor questionnaires and ongoing monitoring.
  • Review SOC 2 reports, security questionnaires, certifications, and due diligence materials.
  • Support CMMC compliance efforts, including SSPs and readiness assessments.
  • Advise on FedRAMP authorization and continuous monitoring for cloud services.
  • Maintain risk registers, dashboards, and executive risk reporting.

Skills

Cybersecurity
Risk management
Leadership
Communication
NIST CSF
CMMC knowledge

Education

Bachelor’s degree in Cybersecurity

Tools

ServiceNow GRC
OneTrust

Job description

The salary range above represents the low and high end in the local currency of Xerox’s salary range for this position and is reflected in an annualized amount.Actual salaries will vary based onfactorsincluding, but not limited to, geographic location, market competition, and/or the successful applicant’s education, experience,knowledge, skills,and abilities. The range listed is just one component of Xerox’s total compensation package for employees.Employees are also afforded acomprehensive suite of benefits, to view those details please visit Xerox Careers for your applicable country.If you are not reviewing this job posting on Xerox Careers , we cannot guarantee the validity of this posting. For a list of our current internal postings, please visit Xerox Careers .

Description & Requirements

About Xerox Holdings Corporation
For more than 100 years, Xerox has continually redefined the workplace experience. Harnessing our leadership position in office and production print technology, we’ve expanded into software and services to sustainably power the hybrid workplace of today and tomorrow. Today, Xerox is continuing its legacy of innovation to deliver client-centric and digitally-driven technology solutions and meet the needs of today’s global, distributed workforce. From the office to industrial environments, our differentiated business and technology offerings and financial services are essential workplace technology solutions that drive success for our clients. At Xerox, we make work, work.Learn more about us at www.xerox.com .

Location: Remote - United States, Eastern or Central Time Zone
Schedule: Full-Time, Days
Compensation: $146,000-$195,000 based on experience

Overview

Xerox is seeking a Sr. Risk Analyst to support and lead key cybersecurity risk initiatives within our Governance, Risk, and Compliance organization. This role will help assess, monitor, and report on cybersecurity and third-party risk using industry-standard frameworks, including the CIS Critical Security Controls and the NIST Cybersecurity Framework.

The Sr. Risk Analyst will play a key role in Xerox’s Third-Party Risk Management program, CMMC and FedRAMP compliance initiatives, security policy exception process, risk register management, and executive-level risk reporting. This position is ideal for an experienced risk, audit, or compliance professional who is ready to take ownership of complex programs, mentor others, and help mature enterprise cybersecurity risk practices.

What You’ll Do

  • Lead and support cybersecurity risk assessments using frameworks such as CIS Critical Security Controls and the NIST Cybersecurity Framework.
  • Support and mature Xerox’s Third-Party Risk Management program, including vendor security questionnaires, third-party risk assessments, ongoing monitoring, and escalation of high-risk findings.
  • Review vendor-submitted evidence, including SOC 2 reports, security questionnaires, certifications, and due diligence materials.
  • Support CMMC compliance efforts, including control documentation, System Security Plan development, readiness assessments, and leadership reporting.
  • Advise on FedRAMP authorization and continuous monitoring activities for applicable cloud services.
  • Manage the security policy exception process, including intake, risk scoring, compensating control review, and leadership approval preparation.
  • Provide direction, guidance, and quality review for risk analysts and related GRC workstreams.
  • Partner with Security Governance, Security Architecture, Global Sourcing, Internal Audit, and business leaders on risk-related matters.
  • Maintain the security risk register, ensuring risks are documented, prioritized, tracked, and driven toward closure.
  • Develop dashboards, metrics, and reports that translate technical risk findings into clear business risk narratives.
  • Support internal and external audits, including ISO 27001, SOC 2, and customer security assessments.
  • Track changes in cybersecurity regulations, frameworks, and compliance requirements, including NIST, CMMC, and FedRAMP updates.
  • Help establish and maintain risk assessment methodologies, templates, standards, and scalable processes.
  • Support GRC tooling and identify opportunities to improve efficiency, consistency, and program coverage.

Who You Are

  • Bachelor’s degree in Cybersecurity, Information Systems, Computer Science, or a related field; equivalent practical experience will also be considered.
  • 5+ years of experience in information security, IT risk management, audit, compliance, or a related field.
  • Experience leading, mentoring, or providing guidance to analysts or project teams.
  • Strong working knowledge of CIS Critical Security Controls and the NIST Cybersecurity Framework.
  • Experience with third-party/vendor risk management programs, including questionnaires, due diligence, and ongoing monitoring.
  • Working knowledge of CMMC requirements and NIST SP 800-171.
  • Working knowledge of FedRAMP requirements and authorization processes, including SSPs, SARs, and POA&Ms.
  • Experience with security policy exception processes, risk-based decision-making, and compensating controls.
  • Strong communication and presentation skills, with the ability to explain technical risk findings to senior leadership and business stakeholders.

Preferred Qualifications

  • Relevant certification such as CISSP, CRISC, CRMA, CISA, CCSK, or a CMMC-related credential.
  • Direct experience supporting or leading a CMMC or FedRAMP assessment or authorization effort.
  • Experience with SOC 2, ISO 27001, or similar audit frameworks.
  • Experience with GRC or risk management tools such as ServiceNow GRC, OneTrust, or similar platforms.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Penetration Tester
Security Penetration Tester

Xerox Corporation • United States

On-site
USD 90,000 - 140,000
Chief Security Officer
Chief Security Officer

Xerox • United States

On-site
USD 300,000 - 420,000
Senior Cybersecurity Risk & Governance Analyst
Senior Cybersecurity Risk & Governance Analyst

Mortgage-Trade-Holding-Company,-LL • Oxford (MS)

On-site
USD 110,000 - 150,000
CRO - Information Security & Risk Oversight Lead
CRO - Information Security & Risk Oversight Lead

Bloomberg • New York (NY)

On-site
USD 140,000 - 180,000
Senior Cybersecurity Risk & Governance Analyst
Senior Cybersecurity Risk & Governance Analyst

mTrade, LLC. • Oxford (MS)

On-site
USD 110,000 - 160,000
IT Risk & Compliance Analyst
IT Risk & Compliance Analyst

Trinity Church NYC • New York (NY)

Hybrid
USD 126,000 - 158,000
Senior Cybersecurity Risk & Governance Analyst
Senior Cybersecurity Risk & Governance Analyst

mTrade • Oxford (MS)

On-site
USD 110,000 - 160,000
Sr. Cyber Risk Assurance Analyst
Sr. Cyber Risk Assurance Analyst

McKesson • Atlanta (GA)

On-site
USD 99,000 - 167,000
Annual bonus opportunities
Competitive compensation package
Diverse work environment
Senior Enterprise Security Architect
Senior Enterprise Security Architect

Xerox • Oak Brook (IL)

On-site
USD 150,000 - 190,000
Senior Director, Cloud Solutions
Senior Director, Cloud Solutions

Xerox Corporation • Northern (KY)

Hybrid
USD 180,000 - 240,000
Competitive compensation
Comprehensive benefits
Performance incentives