- Company Name
- OP Consulting Group LLC
- Job Title
- Technical Security Risk & Governance Analyst
- Job Description
-
**Job Title**
Technical Security Risk & Governance Analyst
**Role Summary**
Execute risk assessments, control testing, and governance for enterprise systems, applications, networks, and cloud services. Partner with IT, business owners, and audit teams to design, implement, and monitor security controls in line with NIST, CIS, ISO/IEC 27001, and relevant regulatory frameworks (CJIS, HIPAA, PCI DSS). Deliver recommendations, track remediation, and report metrics to leadership and regulators.
**Expectations**
- Bachelor’s degree in Information Security, Computer Science, or related field.
- 1‑3 years of experience in information security, risk management, audit, or a technical security role.
- Demonstrated knowledge of NIST CSF/800-53, CIS Controls, ISO/IEC 27001, and at least one regulatory domain (e.g., HIPAA, PCI DSS).
**Key Responsibilities**
- Conduct technical security risk assessments for on‑prem, cloud (IaaS/PaaS/SaaS), and hybrid environments; document risk likelihood, impact, and mitigation.
- Perform control design and operating‑effectiveness testing against NIST, CIS, ISO, and agency standards.
- Support Authority to Operate processes, security attestations, and continuous monitoring activities.
- Facilitate threat modeling, security architecture reviews, and advise on secure design patterns (segmentation, IAM, least privilege, encryption, logging).
- Maintain and update security policies, procedures, and control libraries, aligning with legislative and regulatory changes.
- Map agency controls to mandates (CJIS, IRS, HIPAA, FERPA, PCI DSS, state statutes), track gaps, and drive remediation.
- Coordinate internal and external audits, lead evidence collection, responses, and remediation plans.
- Administer or contribute to GRC tools for issue tracking, risk registers, and exception management.
- Establish vulnerability management governance: SLAs, exception handling, and patching progress monitoring.
- Perform third‑party vendor/security reviews (e.g., SOC 2, ISO) and negotiate security clauses.
- Develop dashboards and KPIs for risk posture, control maturity, and vulnerability closure; brief leadership on trends.
- Produce clear, actionable reports for technical and non‑technical stakeholders.
- Support incident response with risk‑informed guidance and review changes for security impact.
**Required Skills**
- Technical assessment and control testing, including configuration validation and scan result interpretation.
- Risk analysis, documentation, and practical risk treatment planning.
- Proficiency with GRC platforms, workflow construction, and risk register maintenance.
- Data analysis and dashboarding (Excel, Power BI).
- Concise report writing and executive presentation skills.
- Knowledge of IAM, network security, endpoint security, vulnerability management, SIEM, PKI, secure DevOps, and cloud security concepts (shared responsibility model, CSPM, KMS/CMKs, zero trust).
**Required Education & Certifications**
- Bachelor’s degree in Information Security, Computer Science, Information Systems, or related field.
- Preferred certifications: CISSP, CISM, CRISC, CGRC, Security+, CCSK/CCSP, CISA, AWS/Azure/GCP security specialties.
Harrisburg, United states
On site
18-02-2026