Senior Information Security Risk Analyst

FM - Johnston, RI

Hiring: Senior Information Security Risk Analyst Company: FM Location: Johnston, RI Job Posted Time: 2026-09-12 13:03:12 Employment Type: On-site Target Skills & Keywords : AWS, Azure, IAM, Microsoft Office, PaaS, Risk Management, SOC, SOC 2, SaaS, Stakeholder Management, Systems Design About the job Experience: •5+ years of experience in cybersecurity, information security, or cyber risk, with a background in third-party risk management (TPRM), IT risk, audit, incident response, or access management. Required Skills: •This position requires on-site work one day per week at our Corporate Headquarters and flexibility to be on-site when needed based on the demands of the business •Relocation is not offered for this position. •Partner closely with business, technology, and procurement teams to identify risks and recommend practical, business-aligned mitigation strategies. •Lead end-to-end cybersecurity risk assessments of third-party vendors and solutions—going beyond standard due diligence to evaluate real-world risk across systems, data, and integrations. •Lead end-to-end third-party solution risk assessments and vendor security reviews across the vendor lifecycle, including due diligence, onboarding, ongoing monitoring, and reassessments. •Evaluate vendor security programs, control effectiveness, and governance, along with deep-dive assessment of the specific product being implemented including solution architecture, data flows, and integration points. •Identify and communicate inherent and residual cyber risks related to data protection, privacy, IAM, privileged access, system connectivity, and external attack surface exposure. •Review and interpret security documentation, including SOC 1/SOC 2 reports, ISO 27001 certifications, audit reports, architecture diagrams, data flow diagrams, and technical configurations. Qualifications: •In-depth knowledge of systems, networks, application architecture, cloud security, and secure system design across AWS, Azure, SaaS, PaaS, APIs, and enterprise integrations. •Knowledge of IAM, SSO, federation, privileged access, cyber threats, vulnerabilities, and attack methodologies. •Demonstrated capacity to interpret SOC 1, SOC 2, ISO certifications, and other third-party assurance artifacts to identify control gaps and residual risk. •Demonstrated capacity to identify, assess, and clearly communicate complex cyber risks, trade-offs, and residual risk. •Strong analytical judgment, attention to detail, and risk-based decision-making. •Demonstrated capacity to translate technical findings into clear, business-relevant insights and recommendations. •Strong stakeholder management and partnership across business, technology, procurement, and legal teams. •Collaborative, solutions-focused mindset with strong influencing skills in a fast-paced assessment environment. •High degree of professional skepticism and curiosity when evaluating vendor claims and evidence Compensation: •$106,000 - $152,000 / year Interested candidates, please apply directly through the job posting on company's career page or try via AI auto apply on this platform. Don't miss this opportunity to join a forward-thinking team!