Specialist, Risk Management

Posted 5 Hours Ago
Be an Early Applicant
2 Locations
Remote
Senior level
Edtech • Information Technology • Professional Services • Consulting
The Role
Supports information security, data privacy, PCI DSS, client assurance, and enterprise risk programs. Responsibilities include coordinating ISO 27001 audits, administering Vanta, maintaining risk registers, conducting vendor and project assessments, tracking remediation, monitoring privacy regulations, coordinating data subject requests, managing PCI documentation, responding to client security questionnaires, and reporting risk posture to governance forums. Partners with Legal and business stakeholders to strengthen controls, policies, compliance, training, and secure business practices.
Summary Generated by Built In
Summary 

In this role, the Risk Management Specialist III will support and strengthen our risk management and information security programs. You’ll help ensure the organization maintains effective protections across regulatory, contractual, and data privacy requirements while partnering cross-functionally to identify, assess, and mitigate risk. 


You’ll contribute to key initiatives including information security, vendor and project risk assessments, compliance frameworks (e.g., ISO 27001), and policy development, helping to drive continuous improvement and operational maturity. This role offers the opportunity to build hands-on experience in a collaborative environment while acting as a trusted partner to stakeholders across Lega, ICT, and the broader business. 


Requirements
Scope & Responsibilities 

Information Security 

  • Supports the deployment and continuous improvement of information security policies, standards, and technical controls  
  • Coordinates Prosci’s ISO 27001:2022 certification and audit activities, including audit scheduling, evidence collection, and external auditor coordination  
  • Administers compliance tooling (e.g., Vanta) to support the information security program and control monitoring  
  • Facilitates ISMS Governance Council activities, including maintaining the enterprise risk register and reporting on risk posture  
  • Conducts information security risk assessments for vendors, projects, and business changes  
  • Tracks, reports, and supports remediation of identified control gaps and audit findings  
  • Defines and monitors information security metrics to measure program effectiveness and progress  
  • Serves as a trusted advisor to stakeholders, partnering cross-functionally to support secure business practices 

Data Privacy 

  • Supports the implementation and ongoing management of Prosci’s global data privacy program  
  • Ensures alignment with applicable global privacy regulations (e.g., GDPR, CCPA, PIPEDA, LGPD) and monitors compliance across business practices  
  • Partners with Legal and internal stakeholders to interpret and apply privacy requirements to business operations  
  • Coordinates data subject request (DSR) processes and response activities  
  • Maintains internal privacy policies and external privacy notices  
  • Supports employee privacy training and awareness initiatives 

PCI Compliance 

  • Supports the PCI DSS compliance program for outsourced, card-not-present payments under SAQ A scope. 
  • Maintains documentation of PCI scope and ensures ongoing eligibility for SAQ A classification. 
  • Oversees third-party service providers (TPSPs), including maintaining vendor inventories and monitoring compliance status 
  • Supports completion of PCI assessments (SAQ A), including evidence collection, remediation tracking and reporting 
  • Provides guidance and training to internal stakeholders on PCI requirements and secure payment practices 
  • Serves as a point of contact for PCI compliance activities and coordination with internal and external  

Client Assurance 

  • Partners with internal stakeholders to understand client security and privacy requirements and expectations 
  • Supports client assurance activities, including responding to security questionnaires and sharing relevant compliance documentation (e.g., ISO certifications) 

Risk Evaluation 

  • Supports the development and execution of a structured risk evaluation process for projects and business changes 
  • Reviews initiatives for information security and data privacy risks and escalates findings as appropriate 
  • Provides regular updates to governance forums on risk posture and emerging concerns 

Competencies, Skills & Qualifications 

Competencies 

  • Communicates Effectively - Strong communication skills 
  • Language Requirements: Fluent/Native English
  • Plans and Aligns 
  • Respond timely to tasks/requests 
  • Ability to work independently and prioritize multiple risks and adapt to needed changes 
  • Balances Stakeholders - Ability to work with all levels of management/team members 
  • Decision Quality 
  • A need to assume responsibility for work 
  • Ability to pull together disparate pieces of information to analyze risk. 
  • Knowledge of and proven ability for attention to detail and strong organizational skills 
  • Analytical thinker 
  • A drive to exceed goals 

Qualifications 

  • 4 – 7 years’ experience in Risk Management, including knowledge of US/international data privacy regulations, implementation for/maintenance of ISO certification 27001 certification, risk evaluation of new projects and vendors, creation of risk management solutions, review of client DPA and security agreements, and related matters. 
  • Bachelor’s degree 
  • CIPM Certification 

Please note: Only applications and CVs submitted in English will be considered.
#LI-KC1 

Skills Required

  • 4–7 years of experience in risk management
  • Knowledge of U.S. and international data privacy regulations
  • Experience implementing or maintaining ISO 27001 certification
  • Experience evaluating risks for new projects and vendors
  • Experience creating risk management solutions
  • Experience reviewing client data processing agreements and security agreements
  • Bachelor’s degree
  • CIPM certification
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Fort Collins, CO
Year Founded: 1994

What We Do

Prosci is a global leader in change management, providing research, training, certification, and advisory services to help organizations build internal competency to lead change successfully.

Similar Jobs

Circle (circle.so) Logo Circle (circle.so)

Lead Product Designer

Artificial Intelligence • Consumer Web • Digital Media • Information Technology • Social Impact • Software
Easy Apply
Remote
31 Locations
250 Employees
140K-170K Annually

Circle (circle.so) Logo Circle (circle.so)

Lead Product Designer

Artificial Intelligence • Consumer Web • Digital Media • Information Technology • Social Impact • Software
Easy Apply
Remote
31 Locations
250 Employees
140K-170K Annually

Mondelēz International Logo Mondelēz International

Platform Engineer

Big Data • Food • Hardware • Machine Learning • Retail • Automation • Manufacturing
Remote or Hybrid
2 Locations
90000 Employees

Mondelēz International Logo Mondelēz International

Change Manager o9 MEU, Demand Planning

Big Data • Food • Hardware • Machine Learning • Retail • Automation • Manufacturing
Remote or Hybrid
9 Locations
90000 Employees

Similar Companies Hiring

Standard Template Labs Thumbnail
Artificial Intelligence • Information Technology • Software
New York, NY
25 Employees
NODA AI Thumbnail
Artificial Intelligence • Information Technology • Software • Cybersecurity
Sydney, AU
54 Employees
Golden Pet Brands Thumbnail
Digital Media • eCommerce • Information Technology • Marketing Tech • Pet • Retail • Social Media
El Segundo, California
178 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account