About the Role
The IT Risk & Compliance Analyst safeguards Trinity’s technology environment by managing cybersecurity risk, regulatory compliance, and business continuity. This role involves ensuring compliance with standards like PCI DSS, overseeing disaster recovery, monitoring for cyber threats, and coordinating incident response. The Analyst supports policy development, manages security assessments, and maintains documentation for audits, while also providing technical oversight for log reviews, vulnerability scans, and threat monitoring. The goal is to strengthen the organization’s resilience and readiness through a security-aware culture and continuous improvement.
Responsibilities
- Develop and coordinate vendor risk management frameworks, policies, and processes.
- Compile metrics for reporting threats, risks, and control success to leadership.
- Coordinate the creation, approval, maintenance, and updating of security policies.
- Coordinate periodic access reviews.
- Develop and maintain a methodology to identify and prioritize threats, quantify risk, and recommend mitigation methods.
- Work with risk owners to develop and monitor risk response plans.
- Develop and maintain a risk register.
- Coordinate periodic management reviews and manage exception requests.
- Research emerging threats and vulnerabilities to aid in network incident identification.
- Coordinate management of vendor, supplier, and third-party risk.
- Facilitate assessments of new and existing third-parties.
- Evaluate statements of work from partners to ensure adequate security protections.
- Assess provider documentation.
- Report identified risks to management and vendor management teams.
- Work with third-parties to develop appropriate risk response plans and monitor plans to closure.
- Coordinate, maintain, and continuously improve security awareness and role-based security training programs.
- Educate stakeholders on cybersecurity matters to increase awareness and improve culture.
- Create and coordinate plans for role-based security training.
- Work with Legal to maintain an understanding of internal and external regulatory compliance requirements.
- Assist in responding to findings from external audits, penetration tests, and vulnerability assessments.
- Conduct security control gap assessments of internal systems, third-party and internally-developed applications, and IT infrastructure.
- Work with technical teams to develop remediation plans and track approved plans to completion.
- Serve as the designated backup Incident Manager.
- Lead the end-to-end response to security incidents, coordinating with external partners as needed.
- Initiate and direct the security incident response process when activated.
- Exercise decision-making authority within the scope of the role to ensure timely and effective resolution of security incidents.
Requirements
- Strong understanding of IT risk frameworks, compliance requirements, and security standards (e.g., PCI DSS, NIST, ISO 27001).
- Experience supporting internal audits, managing risk registers, and working with external compliance assessors.
- Excellent communication and interpersonal skills with both technical and non-technical stakeholders.
- Highly organized with attention to detail, especially in documenting controls and producing reports.
- Knowledge of disaster recovery planning and operational resilience practices.
- Strong communications and interpersonal skills with a customer-service orientation, including listening, written, and verbal communication.
- Strong informal or formal project management skills with a proven history of getting projects done and meeting project goals utilizing teams.
- Familiarity with threat detection platforms, endpoint security, vulnerability scanning tools, and log analysis.
- Ability to conduct root cause analysis and support containment, eradication, and recovery efforts.
- Strong ability to effectively prioritize work.
- Must be able to work independently.
- Distinctive blend of business, IT, financial and communication skills.
- Knowledge of project management methodology and experience or familiarity with major, defined program management approaches.
- Knowledge of project planning/scheduling tools, with a solid track record of practical application.
- Effective influencing and negotiating skills in an environment where this role may not directly control resources.
- Strong knowledge and understanding of business needs, with the ability to establish and maintain a high level of customer trust and confidence.
- Ability to communicate ideas in both technical and user-friendly language.
- Good analytical and problem-solving abilities.
- Highly self-motivated and directed.
- Experience working in a team-oriented, collaborative environment.
- Additional working hours as required.
Skills
- Cybersecurity
- Risk Management
- Regulatory Compliance
- Business Continuity
- PCI DSS
- Disaster Recovery Planning
- Incident Response
- Security Policies
- Security Assessments
- Remediation
- Audit Documentation
- Log Reviews
- Vulnerability Scanning
- Threat Monitoring
- NIST
- ISO 27001
- Vendor Risk Management
- Threat Detection Platforms
- Endpoint Security
- Root Cause Analysis
- Project Management
- Communication
- Interpersonal Skills
- Analytical Skills
- Problem-Solving
Experience Level
- Minimum 3–5 years of experience in IT risk management, information security, cybersecurity operations, or IT audit.
Education Level
- Bachelor’s degree in Cybersecurity, Information Systems, or a related field, or equivalent experience.
- Preferred certifications: CISA, CRISC, CISSP, or equivalent.
Salary/Compensations
- $126,100 to $157,900
About the Company
- Trinity’s technology environment
