Senior Irm Analyst

MongoDB MongoDB · Enterprise · New York, NY · Govt Risk Compliance (GRC)

This role focuses on information security risk management and compliance within an enterprise setting, specifically ensuring adherence to regulations like DORA, FedRAMP, and NIS2. The Senior IRM Analyst will conduct risk assessments, evaluate control effectiveness, and report on risks to leadership, playing a key role in reducing organizational uncertainty and empowering business decisions within a regulated landscape.

What you'd actually do

  1. Lead the strategic roadmap to integrate the risk matrix into the risk framework
  2. Ensure the risk program complies with global regulations, specifically DORA (EU) regarding ICT registers and FedRAMP Rev 5 supply chain controls.
  3. Conduct annual enterprise security risk assessments and ad-hoc assessments as triggered by material changes, incidents, or new initiatives
  4. Identify risk scenarios for the in-scope assets by working with the asset and risk owners
  5. Assess the inherent risk and residual risk based on established risk assessment methodology and control assessments

Skills

Required

  • Information Security
  • Governance, Risk & Compliance (GRC)
  • enterprise-level security risk assessments
  • scoping
  • threat modeling
  • control evaluation
  • executive reporting
  • technical evidence (configs, logs, architecture diagrams)
  • risk assessment methodologies (NIST SP 800-30)
  • standard control frameworks (NIST CSF, NIST SP 800-53, ISO 27001, SOC 2, SIG Core/Lite, CAIQ)
  • DORA
  • NIS2
  • FedRAMP Rev 5 (Supply Chain/SCRM)
  • GDPR
  • PCI-DSS
  • executive-level risk reports
  • collaboration
  • influence change
  • CRISC
  • CCSP
  • CISSP
  • CISA

Nice to have

  • cloud certifications

What the JD emphasized

  • DORA
  • FedRAMP Rev 5
  • NIS2
  • regulatory landscape
  • risk methodology
  • risk identification
  • risk assessment
  • risk treatment
  • risk acceptance process
  • risk scoring formula
  • risk metrics
  • risk reports
  • risk acceptance process