Talent.com
Trinity Church NYC
IT Risk & Compliance AnalystTrinity Church NYC • New York, NY, United States
IT Risk & Compliance Analyst

IT Risk & Compliance Analyst

Trinity Church NYC • New York, NY, United States
9 days ago
Salary
$126,100.00–$157,900.00 yearly
Job type
  • Full-time
Job description

IT Risk & Compliance Analyst

The IT Risk & Compliance Analyst plays a critical role in safeguarding Trinity's technology environment by managing cybersecurity risk, regulatory compliance, and business continuity programs. In addition to ensuring compliance with standards such as PCI DSS and overseeing disaster recovery planning, this role monitors Trinity's IT environment for emerging cyber threats and coordinates incident response efforts.

As a hybrid security and compliance role, the Analyst supports the development and enforcement of security policies, manages security assessments and remediation, and maintains documentation for internal governance and external audits. The role also provides hands-on technical oversight of log reviews, vulnerability scans, and threat monitoring activities. By promoting a security-aware culture and enabling continuous improvement, the IT Risk & Compliance Analyst strengthens the organization's resilience and readiness in the face of evolving threats.

The annual salary range for this position is $126,100 to $157,900.

Essential Duties and Responsibilities:

  • Governance: Develop and coordinates vendor risk management frameworks, policies and processes within a broader enterprise, operational and IT risk management model.
  • Compile metrics for reporting threats, risks, and success of operating controls to leadership.
  • Coordinate creation, approval, maintenance and updating of security policies.
  • Coordinate periodic access reviews.
  • Risk Management: Develop and maintain a methodology to identify and prioritize internal and external threats, quantify the risk to the organization, and recommend methods to mitigate or remediate risk. Work with risk owners to develop appropriate risk response plans; monitor plans to closure.
  • Develop and maintain a risk register. Coordinate periodic management reviews and manage exception requests.
  • Research emerging threats and vulnerabilities to aid in the identification of network incidents.
  • Third-Party Risk Management: Coordinate management of vendor, supplier and other third-party risk.
  • Facilitate assessments of new and existing third-parties. Evaluate statements of work from partners to ensure that adequate security protections are in place. Assess provider documentation (e.g., security assessment questionnaire responses, SOC 1 or SOC 2 audit reports, or other sources).
  • As risks are identified, report risks to management and vendor management teams; work with third-parties to develop appropriate risk response plans; and monitor plans to closure.
  • Security Awareness and Training: Coordinate, maintain and continuously improve security awareness and role-based security training programs, to mitigate human risks.
  • Educate stakeholders on cybersecurity-related matters to increase awareness and improve culture.
  • Create and coordinate plans for role-based security training.
  • Audit and Compliance: Work with Legal to maintain an understanding of internal and external regulatory compliance requirements.
  • Assist in responding to findings from external audits, penetration tests and vulnerability assessments.
  • Conduct security control gap assessments of internal systems, third-party and internally-developed applications, and IT infrastructure. Work with technical teams as they develop remediation plans and track approved plans to completion.
  • Security Monitoring and Incident Response: Serve as the designated backup Incident Manager when the primary manager is unavailable. Lead the end to end response to security incidents, coordinating with external partners as needed (such as cyber insurance carriers, digital forensics teams, and root cause analysis specialists). When activated, initiate and direct the security incident response process and exercise decision making authority within the scope of the role to ensure timely and effective resolution.

Required Knowledge, Skills, and Activities:

  • Strong understanding of IT risk frameworks, compliance requirements, and security standards (e.g., PCI DSS, NIST, ISO 27001).
  • Experience supporting internal audits, managing risk registers, and working with external compliance assessors.
  • Excellent communication and interpersonal skills with both technical and non-technical stakeholders.
  • Highly organized with attention to detail, especially in documenting controls and producing reports.
  • Knowledge of disaster recovery planning and operational resilience practices.
  • Strong communications and interpersonal skills with a customer-service orientation, including listening, written, and verbal communication
  • Strong informal or formal project management skills with a proven history of getting projects done and meeting project goals utilizing teams
  • Familiarity with threat detection platforms, endpoint security, vulnerability scanning tools, and log analysis.
  • Ability to conduct root cause analysis and support containment, eradication, and recovery efforts.
  • Strong ability to effectively prioritize work
  • Must be able to work independently
  • Distinctive blend of business, IT, financial and communication skills, because this is a highly visible position with substantial impact
  • Knowledge of project management methodology and experience or familiarity with major, defined program management approaches.
  • Knowledge of project planning/scheduling tools, with a solid track record of practical application.
  • Effective influencing and negotiating skills in an environment in which this role may not directly control resources
  • Strong knowledge and understanding of business needs, with the ability to establish and maintain a high level of customer trust and confidence
  • Ability to communicate ideas in both technical and user-friendly language.
  • Good analytical and problem-solving abilities.
  • Highly self-motivated and directed.
  • Experience working in a team-oriented, collaborative environment.
  • Additional working hours as required

Required and Preferred Education, Experience, and Credentials:

Required:

  • Bachelor's degree required or an equivalent combination of training or experience.
  • Minimum 35 years of experience in IT risk management, information security, cybersecurity operations, or IT audit.

Preferred:

  • Background in security architecture is a plus.
  • Preferred certifications: CISA, CRISC, CISSP, or equivalent.
  • Experience supporting disaster recovery planning and regulatory compliance efforts.

Equal Opportunity Employer This employer is required to notify all applicants of their rights pursuant to federal employment laws. For further information, please review the Know Your Rights notice from the Department of Labor.

Create a job alert for this search

IT Risk & Compliance Analyst • New York, NY, United States

Similar jobs

Security Risk Analyst

RIT SolutionsNew York, NY, United States
Full-time

Onsite at 55 Water Street, NYC.Long Term Contract / Potential several years with Right to Hire GRC focused Security role / Risk management, etc.The EITS Security Risk Analyst will interface between... Show more

 • Promoted

Head of Risk

Soft2BetFort Lee, NJ, United States
Full-time

Are you a Head of Risk who thrives on protecting the business, leading high-performing teams, and building strong risk, fraud, and KYC operations in a regulated environment?.Soft2Bet is a platform ... Show more

 • Promoted

Director of Compliance

VIP Community ServicesBronx, NY, United States
Full-time

The Director of Compliance serves as a senior member of the VIP Compliance Department, functioning as the operational and supervisory bridge between frontline compliance staff and the SVP/Chief Com... Show more

 • Promoted

Business Analyst - IT Compliance

StaffingNew York, NY, United States
Full-time

Business Analyst - IT Compliance.In this role you will lead various project's requirements management process in Corporate IT.This is a challenging position requiring a strong, proven experience in... Show more

 • Promoted

IT Business Analyst

PeopleSERVE, Inc.New York, NY, United States
Full-time

Front Office Equity And Option It Business Analyst.We are seeking one Front Office Equity and Option IT Business Analyst to support various external and internal applications for trade execution, t... Show more

 • Promoted

Compliance Analyst

FernNew York, NY, United States
Full-time

We are looking for a hands-on Compliance Analyst to join our Compliance team with a primary focus on KYC and KYB onboarding operations.This is a do-er role - you will be in the queue every day revi... Show more

 • Promoted

Risk Management Analyst

BizTek PeopleHoboken, NJ, United States
Full-time

One of the leading financial institutions is seeking a Risk Management Analyst who will be analyzing risk management activities and creating various reports related risks.Responsibilities: Prepare ... Show more

 • Promoted

Asset Protection Specialist

Home Depot (Retail)Hazlet, NJ, United States
Full-time

Asset Protection Specialist | Home Depot.The Asset Protection Specialist is primarily responsible for preventing financial loss caused by theft and fraud and supporting safety and environmental pro... Show more

 • Promoted

IT Risk & Compliance Analyst

Trinity Church NYCNew York, NY, United States
Full-time

The IT Risk & Compliance Analyst plays a critical role in safeguarding Trinity's technology environment by managing cybersecurity risk, regulatory compliance, and business continuity programs.In ad... Show more

 • Promoted

Risk Assessment Compliance Analyst

ExperisJersey City, NJ, United States
Full-time

Risk Assessment Compliance Analyst.Our client is seeking a Risk Assessment Compliance Analyst to join their team.As a Risk Assessment Compliance Analyst, you will be part of the Compliance and Priv... Show more

 • Promoted

IT Risk Manager

PGM TEK, Inc.New York, NY, United States
Full-time

Job Opening Status In-progress.Welcome to PGMTEK, Inc where we help candidates find the opportunities that best match with their career goals.Responsibilities: Identify, assess and monitor the IT r... Show more

 • Promoted

AI Risk & Compliance Analyst

EXPERISNew York City, NY, United States
Full-time

Our client, a major communications firm is seeking an AI Risk and Compliance Analyst to join their team.W2 Candidates only - no C2C candidates.Right To Hire Location:NYC or Charlotte, NC (Hybrid 3 ... Show more

 • Promoted

Information Technology Professional

US NavyTinton Falls, NJ, US
Full-time

Job Title: Information Technology Professional (IT/CTN/IS).Category / Component: Enlisted • Both.Information Systems Technicians, Cryptologic Technician Networks, and Intelligence Specialists keep... Show more

 • Promoted • New!

Loss Prevention Clerk

Costco Wholesale CorporationHazlet, NJ, United States
Full-time

Protects company assets from internal and external theft.Reviews individual warehouse inventory numbers and assists in creating / executing a plan of action to reduce shrink.Is familiar with variou... Show more

 • Promoted

Loss Prevention Clerk

Costco Wholesale Corp.Asbury Park, NJ, United States
Full-time

Responsibilities: Protect company assets by reducing shrink and preventing theft; Patrol warehouse and perimeter to monitor safety and security; Investigate theft, detain suspects when warranted, a... Show more

 • Promoted

Compliance Analyst

BAMM StaffingJersey City, NJ, United States
Full-time

Senior Business Analyst RCM Connectivity Testing & Data Mapping Support.The Senior Business Analyst will lead User Acceptance Testing (UAT) activities for Regulatory Change Management (RCM) connect... Show more

 • Promoted

Loss Prevention Clerk

CostcoAsbury Park, NJ, United States
Full-time

Protects company assets from internal and external theft.Observes and reports potential safety and security hazards.For additional information about pay ranges, click here.We offer a comprehensive ... Show more

 • Promoted

Governance Risk Compliance Lead

Eleven RecruitingNew York, NY, United States
Full-time

Governance Risk Compliance Lead.Our client, a global investment firm, is seeking a Governance Risk Compliance Lead to join their team in New York, NY!.Lead the design, implementation, and continuou... Show more

 • Promoted

Analyst, Compliance

Columbia UniversityNew York, NY, United States
Full-time

The Analyst, Compliance is responsible for assisting with oversight and advancement of CUIMC's professional fee compliance, billing integrity, and regulatory adherence programs.This position serves... Show more

 • Promoted

Senior Manager, IT Operations

LOG-NET, Inc.Asbury Park, NJ, United States
Full-time

Operations And Compliance Manager.LOG-NET is a leader in the global autonomous logistics marketplace.Our platform powers some of the largest brands in the world in the global distribution of their ... Show more