Senior Irm Analyst

MongoDB MongoDB · Enterprise · New York, NY · Govt Risk Compliance (GRC)

This role is for a Senior Information Risk Analyst at MongoDB, focusing on managing internal and third-party risk programs. The analyst will be responsible for the full lifecycle of risk identification, assessment, and treatment, ensuring compliance with global regulations like DORA and FedRAMP. Key responsibilities include implementing risk assessment methodologies, maintaining risk management plans, conducting technical security risk assessments, and reporting on risk metrics. The role requires extensive experience in information security, GRC, and a deep understanding of various risk assessment frameworks and regulatory requirements.

What you'd actually do

  1. Lead the strategic roadmap to integrate the risk matrix into the risk framework
  2. Ensure the risk program complies with global regulations, specifically DORA (EU) regarding ICT registers and FedRAMP Rev 5 supply chain controls Maintain the Supply Chain Risk Management (SCRM) plan and oversee strict boundary protections for the "Atlas for Government" environment
  3. Maintain the Information Risk Management Procedure (ISQMS), ensuring that risk identification, assessment, and treatment processes are documented, updated annually, and followed consistently across the organization
  4. Experience conducting technical security risk assessments (infrastructure, cloud, application-level). Including experience in evaluating control effectiveness through technical evidence (configurations, logs, architecture diagrams)
  5. Own the end-to-end risk assessment process

Skills

Required

  • Information Security
  • Governance, Risk & Compliance (GRC)
  • enterprise-level security risk assessments
  • scoping
  • threat modeling
  • control evaluation
  • executive reporting
  • technical evidence evaluation
  • risk assessment methodologies (NIST SP 800-30)
  • standard control frameworks (NIST CSF, NIST SP 800-53, ISO 27001, SOC 2, SIG Core/Lite, CAIQ)
  • DORA
  • NIS2
  • FedRAMP Rev 5
  • GDPR
  • PCI-DSS
  • executive-level risk reports
  • collaboration
  • influence change

Nice to have

  • CRISC
  • CCSP
  • CISSP
  • CISA
  • relevant cloud certifications

What the JD emphasized

  • DORA
  • FedRAMP Rev 5
  • NIS2
  • Supply Chain Risk Management (SCRM)
  • Atlas for Government