IT Risk and Compliance Analyst

Reposted 2 Days Ago
Miramar, FL, USA
In-Office
Junior
Legal Tech
The Role
Lead third-party risk management by performing vendor risk assessments, responding to security RFPs, conducting due diligence, tracking mitigation, developing KPIs/policies, and collaborating on the firm's information security and BCP/DR programs.
Summary Generated by Built In

Greenberg Traurig (GT), a global law firm with locations across the world in 15 countries, has an exciting employment opportunity for you. We offer competitive compensation and an excellent benefits package, along with the opportunity to work within an innovative and collaborative environment.

 

Join our Technology Team as an IT Risk and Compliance Analyst located in our Miramar office.

 

We are seeking a professional who thrives in a fast-paced, deadline-driven environment. The ideal candidate possesses strong problem-solving and decision-making abilities, ensuring efficiency and accuracy in every task. With a dedicated work ethic and a can-do attitude, you will take initiative and approach challenges with confidence and resilience. Excellent communication skills are essential for collaborating effectively across teams and delivering exceptional client service. If you are someone who demonstrates initiative, adaptability, and innovation, we invite you to join our team.

 

This role will be based in our Miramar office on a hybrid basis. This role reports to the Technology Security Manager.

 

Position Summary

 

The IT Risk and Compliance Analyst will take a lead in the ongoing design, development, and management of the firm’s third-party risk management program.  The position will consist of developing, monitoring, and assessing risks regarding vendor and partner relationships.

 

Key Responsibilities

  • Completes vendor risk assessments submitted by clients and prospective clients (RFP)

  • Responds to client Requests for Proposals (RFPs) and questionnaires related to security

  • Performs information security due diligence on third party vendors to determine the effectiveness of their controls to protect the firm’s data, identify any discrepancies and provide recommendations to management

  • Assesses client needs against security concerns and resolves various risk issues

  • Develops, implements, assigns, and monitors third party vendor assessments

  • Executes and documents assessment activities following established processes and procedures

  • Performs third party reviews to assess vendor information security posture and practices

  • Keeps abreast of regulatory and compliance related information to enhance the third-party due diligence program

  • Collaborates with team members to provide subject matter expertise with respect to the Firm’s third-party risk management program and to create and update documents and presentations that can be used to inform internal employees, external auditors, or internal auditors about the Firm’s third-party risk management program

  • Contributes to the continuous improvement, including automation where possible, of all aspects of the third-party risk management program based on expert knowledge, industry best practices, business objectives, and risk tolerance, keeping the program relevant and in alignment with the business objectives

  • Leads third party risk threat notification to third party vendors by assessing vendor risk, impact, and response to third (e.g., assessing Log4Shell vendor impact and response communications)

  • Tracks vendor mitigation progress of identified threats and risks

  • Develops, implements, monitors KPI, KRI for third party risk management program

  • Develops and updates third party risk management program policies, procedures, and best practices

  • Actively participates in outside Third-Party Risk Management communities

  • Works with the security team to develop, manage, and maintain the Firm’s Information Security Program, security awareness programs, insider threat programs, etc.

  • Identifies Information Security & Business Continuity risks to senior management & make recommendations for corrective actions/mitigation of risks

  • Works assess BCP/DR compliance status of third-party vendors and communicates their status/impact to the firm’s BCP/DR team

  • Performs other related duties as required and assigned

 

Qualifications

Skills & Competencies

  • Understanding information security (IS) concepts, IT, information security awareness and third-party risk management processes, methodologies, and practices

  • Experience working with compliance issues dealing with sensitive data preferred

  • Strong analytical and problem-solving capabilities, with the ability to identify and resolve issues independently and effectively while exercising sound judgment

  • Strong interpersonal, written, and verbal communication skills, with the ability to interact effectively at all levels of the organization from analyst level to C-suite

  • Explain and articulate technical concepts to non-technical stakeholders and follow basic troubleshooting steps to work through issues

  • Demonstrate basic project management and documentation skills to manage multiple parallel work streams

  • Ability to multitask and perform effectively under pressure, completing assignments with short lead times and tight deadlines while delivering superior service to clients and stakeholders

  • As a specialist on complex technical and business matters, work is highly independent. May assume a team leader role as needed

  • Proficiency with Microsoft Office suite

  • Recognizes confidential, sensitive, and proprietary information and maintain such information as confidential

  • Must be available outside normal working hours to participate in emergency events such as security incidents, breaches, investigations, etc.

 

Education & Prior Experience

  • Bachelor’s degree in information technology, Information Systems, Information Security, Business Administration, or Risk Management (or equivalent experience) or 3+ years of work experience in relevant information risk position in lieu of degree

  • 1-3 years of experience in implementing and/or supporting IT risk management processes

  • 1-3 years of experience in responding to vendor IT risk assessments

  • Experience working with IT audits, findings, and tracking and remediating to resolution

  • Working knowledge of cloud technologies (any of these, Azure, AWS, Alibaba, GCP, IBM cloud) and software delivery models (SaaS, PaaS, IaaS)

  • Industry certifications preferred (e.g., TPRA, CTPRP, CTPRA, CEH, CISA, CISM); candidates who do not already hold these certifications will be expected to work toward obtaining relevant certifications during their employment

  • Working knowledge of security exchanges (e.g., ProcessUnity, OneTrust, UpGuard, CyberGRX, Prevalent, Archer, LogicManager, etc.)

  • Proficiency with standard information gathering tools (e.g., DDQ, SIG, etc.)

  • Proficiency with Windows-based software and Microsoft Office suite

  • Working knowledge of A.I. & Cloud fundamentals (e.g., AI-900 certification)

  • Working knowledge of A.I. technologies (Gen AI), CoPilot, ChatGPT, etc.

GT is an EEO employer with an inclusive workplace committed to merit-based consideration and review without regard to an individual’s race, sex, or other protected characteristics and to the principles of non-discrimination on any protected basis. 

Skills Required

  • Bachelor's degree in IT, Information Systems, Information Security, Business Administration, Risk Management or equivalent experience (3+ years in lieu of degree)
  • 1-3 years implementing and/or supporting IT risk management processes
  • 1-3 years responding to vendor IT risk assessments
  • Experience working with IT audits, tracking findings and remediating to resolution
  • Working knowledge of cloud technologies (Azure, AWS, Alibaba Cloud, GCP, IBM Cloud)
  • Working knowledge of software delivery models (SaaS, PaaS, IaaS)
  • Working knowledge of third-party risk/security platforms (ProcessUnity, OneTrust, UpGuard, CyberGRX, Prevalent, Archer, LogicManager)
  • Proficiency with standard information gathering tools (DDQ, SIG)
  • Proficiency with Windows-based software and Microsoft Office suite
  • Strong analytical, problem-solving, written and verbal communication, documentation and basic project management skills
  • Ability to explain technical concepts to non-technical stakeholders and perform basic troubleshooting
  • Must be available outside normal working hours for security incidents, breaches and investigations
  • Working knowledge of AI & cloud fundamentals (e.g., AI-900) and familiarity with AI technologies (Gen AI, CoPilot, ChatGPT)
  • Industry certifications (TPRA, CTPRP, CTPRA, CEH, CISA, CISM) or willingness to obtain relevant certifications during employment

Greenberg Traurig Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Greenberg Traurig and has not been reviewed or approved by Greenberg Traurig.

  • Fair & Transparent Compensation Pay is characterized as competitive at “market” levels for junior associates in major offices, with predictable early-career compensation in larger markets.
  • Parental & Family Support Parental leave is described as up to 18 weeks for primary caregivers and up to 6 weeks for secondary caregivers, alongside adoption/surrogacy reimbursement up to a $35,000 lifetime maximum and fertility coverage caps.
  • Healthcare Strength Health coverage is described as comprehensive, with comments pointing to strong medical/dental/vision offerings and high employer coverage of healthcare costs in some plans.

Greenberg Traurig Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Miami, FL
4,877 Employees
Year Founded: 1967

What We Do

Greenberg Traurig, LLP has more than 2650 attorneys in 45 locations in the United States, Europe and the Middle East, Latin America, and Asia. The firm is a 2022 BTI “Highly Recommended Law Firm” for superior client service and is consistently among the top firms on the Am Law Global 100 and NLJ 250. Greenberg Traurig is Mansfield Rule 6.0 Certified Plus by The Diversity Lab. The firm is recognized for powering its U.S. offices with 100% renewable energy as certified by the Center for Resource Solutions Green-e® Energy program and is a member of the U.S. EPA’s Green Power Partnership Program. The firm is known for its philanthropic giving, innovation, diversity, and pro bono. Web: www.gtlaw.com.

Similar Jobs

HealthPartners Logo HealthPartners

Compliance Analyst

Healthtech • Information Technology
In-Office or Remote
2 Locations
5537 Employees

Narmi Logo Narmi

Sales Engineer

Enterprise Web • Fintech • Payments • Software • Financial Services
Remote or Hybrid
2 Locations
140 Employees
80K-95K Annually
Hybrid
Daytona Beach, FL, USA
289097 Employees

Similar Companies Hiring

Eve Thumbnail
Legal Tech • Software • Generative AI
San Mateo, CA
180 Employees
GC AI Thumbnail
Artificial Intelligence • Legal Tech
San Mateo, California
100 Employees
Legora Thumbnail
Artificial Intelligence • Legal Tech • Software
Chicago, Illinois
700 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account