Job description
JOB DESCRIPTION
We are currently looking to fill an IT Risk Analyst position. This position works to ensure that IOPS technology risks and controls are identified, monitored and reported on a periodic basis. They maintain awareness of emerging risk and ensure compliance with company Information Security policies. They work across the IT team to track mitigation efforts to reduce and manage technology risks.
As an IT Risk Analyst, a typical day might include the following:
- Defines, documents, reports and tracks technology risk across IOPS.
- Reviews technology controls across IOPS to identify potential vulnerabilities and weaknesses.
- Works across the IT Team to help identify technology risks and mitigation initiatives for existing technologies and systems.
- Conducts risk assessments for all new technology projects, applications and services, identifying risks and agreeing mitigation actions.
- Works closely with Corporate Information Security, to ensure technology risk and controls are aligned with regulatory and compliance requirements across the company.
- Monitors and tracks identified risks and mitigation actions.
- Verification/auditing of controls and risk/control indicators.
- Helps mitigate key risks by identifying and recommending changes to policies and procedures.
- Maintains awareness of emerging security risks and trends and raises awareness of risks where appropriate.
- Supports Regulatory and Internal audits related to Technology Risk and Information Security.
- Assists with third party Security Risk Assessments.
- Works across IT to ensure security best practices are identified and coordinated into all facets of projects including designs/configuration, and implementations.
- Assists in documenting standards, processes, and procedures for security incident response.
- Adheres to IOPS requirements around compliance, training, timecards and continuous improvement.
This role may be for you if you:
- Proven track record in technology risk identification and management.
- Strong oral and written communication and presentation skills.
- Solid understanding and experience of the wider technology space, such as infrastructure, databases, networking, mobile device management, cloud services, etc.
- Strong analytical skills with the capability to assess the information provided, and provide clear and appropriate direction.
To be considered you must have the following education and requirements.
- Principal IT Risk Analyst Requires BS/BA in Information Technology or related field with 8 years’ Risk or Cyber Security experience or equivalent combination of education and experience.
- Staff IT Risk Analyst Requires BS/BA in Information Technology or related field with 10 years’ Risk or Cyber Security experience or equivalent combination of education and experience.
- Cybersecurity certification (CISSP, CISM, CISA, CRISC, etc.) preferred.
- Experience in a regulated environment (GxP, HIPAA/HITECH, FERPA, FISMA, Sarbanes-Oxley, etc.) highly desired.
- Experience with information security best practices and frameworks (ISO 27001:2013, NIST Cyber Security Framework, NIST 800-53, COBIT, etc.).
- Experience with vulnerability management, IT service management and SIEM platforms.
Level is determined based on qualifications relevant to the role
Does this sound like you? Apply now to take your first steps toward living the Regeneron Way! We have an inclusive and diverse culture that provides comprehensive benefits including health and wellness programs, fitness centers and equity awards, annual bonuses, and paid time off for eligible employees at all levels!
Regeneron is an equal opportunity employer and all qualified applicants will receive consideration for employment without regard to race, color, religion or belief (or lack thereof), sex, nationality, national or ethnic origin, civil status, age, citizenship status, membership of the Traveler community, sexual orientation, disability, genetic information, familial status, marital or registered civil partnership status, pregnancy or parental status, gender identity, gender reassignment, military or veteran status, or any other protected characteristic in accordance with applicable laws and regulations. We will ensure that individuals with disabilities are provided reasonable accommodations to participate in the job application process. Please contact us to discuss any accommodations you think you may need.
The salary ranges provided are shown in accordance with U.S. law and apply to U.S. based positions, where the hired candidate will be located in the U.S. If you are outside the U.S, please speak with your recruiter about salaries and benefits in your location.
Salary Range (annually)