Description
Key Skills: IT Risk Management, Cybersecurity, Third Party Risk, Technical Risk Assessment, Risk Analysis, Compliance, Cloud Security, SaaS Security, Risk Documentation, Risk Remediation
Good to Have Skills: Experience with technical risk assessments, third party reviews, or vendor due diligence. Familiarity with cloud, infrastructure, SaaS, or application environments. Experience supporting remediation tracking, risk documentation, or reporting activities. Interest in risk management, governance, and technology controls. Strong organizational skills and a proactive attitude. Eagerness to learn and grow in a technical risk or third party risk role. Ability to work independently on routine tasks while knowing when to escalate.
Roles & Responsibilities:
- Support technical risk assessments across infrastructure, applications, cloud environments, endpoints, SaaS solutions, and supporting platforms.
- Help identify control gaps and potential risk concerns by reviewing technical documentation, evidence, and system information.
- Assist teams with risk management activities and provide feedback on necessary outstanding tasks to ensure proper resolution.
- Escalate complex issues or concerns to more senior team members for review and decision-making when required.
- Assist in maintaining the risk register, ensuring risks are documented accurately and tracked through resolution processes.
- Support the development and tracking of risk treatment plans and remediation actions across various technical domains.
- Assist with third party technical assessments by reviewing vendor documentation, evidence, and control descriptions thoroughly.
- Help assess SaaS and other technology solutions for basic security, resilience, data handling, access management, logging, and recovery considerations.
- Work with senior team members to document findings, track issues, and follow up on remediation progress regularly.
- Help prepare risk metrics, dashboards, and reporting materials for leadership and governance forums as needed.
- Assist with the improvement of risk workflows, evidence collection, and reporting processes to enhance team efficiency.
- Review technical documentation, architecture diagrams, and system summaries to help identify risk exposure and vulnerabilities.
- Support issue management, remediation tracking, and risk acceptance documentation to maintain comprehensive risk oversight.
- Contribute to the development of standards, templates, and guidance for risk management activities across the organization.
- Assist with AI-related technical risk reviews and related governance activities as needed for emerging technologies.
- Communicate clearly with internal stakeholders and vendors to gather information and support comprehensive risk assessments.
Experience Required: 1–3 years of experience in technical risk, cybersecurity, IT risk, third party risk, audit, compliance, or related field. Basic understanding of cybersecurity, IT risk, and third party risk management concepts. Familiarity with risk registers, issue tracking, remediation plans, or reporting tools. Ability to review technical documentation and identify potential gaps or concerns. Strong attention to detail and analytical thinking. Good written and verbal communication skills. Ability to work collaboratively with technical and non-technical stakeholders. Willingness to learn about security controls, cloud services, SaaS applications, and modern infrastructure environments. Ability to manage multiple tasks and follow through on deadlines. Comfort working in a large, complex, and cross-functional environment