← all jobs

Information Security Risk Analyst

Work from home Full-time role Hiring

Description Your Impact The Information Security Risk Analyst is responsible for identifying, assessing, tracking, and communicating information security risks across the organization. This role supports a maturing cybersecurity program by managing acceptable enterprise and third-party risks and leading security training initiatives. About CivicPlus At CivicPlus, we strive to bring our company vision to life through innovation and collaboration. Supported by approachable leadership and transparent communication, we're empowered to make an impact on local government and the residents they serve. Grow your career alongside great people, where authenticity is welcome, successes are celebrated, and potential is nurtured. What You’ll Do As an InfoSec Risk Analyst, you will:

  • Identify and translate inherent and residual risk through likelihood, impact, treatment plans, and ownership.
  • Define and track risk and awareness key metrics to measure program effectiveness and communicate to leadership and governance committees.
  • Conduct and manage enterprise information security risk assessment through recognized frameworks (including NIST 800-30) and maintain an information security risk register.
  • Lead third-party security risk assessments for vendors, partners, and service providers through analysis of assurance documentation, security testing summaries, and security questionnaires.
  • Maintain the information security risk register and third-party vendor risk inventory to track and monitor ongoing risks and approved exceptions.
  • Develop and lead enterprise security awareness training, including phishing simulations and targeted role-based training for security education and reporting.
  • Support internal and external security and compliance assessments through risk evidence and documentation.
  • Partner closely with organizational functions and key stakeholders to understand and address organizational risks across systems and processes, and ensure security risks are understood, prioritized, and treated in alignment with organizational risk appetite.

What We’re Looking For We know that excellent candidates come from diverse backgrounds. Even if you don’t meet 100% of the listed requirements, we encourage you to apply! Experience Preferred Qualifications:

  • 4 – 6 Years of experience in information security, cybersecurity, risk management, or related field
  • Working experience managing enterprise/third-party risk assessments, risk registers, and security training programs.
  • Working experience supporting compliance audits and certifications, including NIST 800-53 (FedRAMP/GovRAMP), ISO 27001, PCI, and/or SOC 2

Certifications

  • Security+, GSEC, or equivalent
  • Bachelor’s degree in Cybersecurity, Information Security, Information Systems, Risk Management, or a related field (preferred)

Skills

  • Strong understanding of cybersecurity risk management principles and methodologies (such as NIST 800-30), modern security control frameworks (such as NIST 800-53), and Cloud / SaaS risk management and considerations (AWS, Azure, GCP)
  • Ability to translate and communicate technical risks into clear business impact for non-technical stakeholders, including metrics (KPIs/KRIs) reporting and presentation
  • Development of risk management and assessment policy and procedure documentation
  • Inquisitive mindset for continuous monitoring and improvement within a mature security program

Why CivicPlus? This Role Offers

  • Shape how security risk is managed across CivicPlus. Identify, assess, and guide the treatment of enterprise and third-party risks that impact our platforms and customers.
  • Turn complex security risk into clear business insight. Partner with leaders across the organization to translate technical risk into actionable decisions.
  • Build a stronger security culture. Lead enterprise security awareness initiatives, including phishing simulations and role-based training that help employees stay ahead of threats.
  • Contribute to a growing cybersecurity program. Help mature risk management practices, frameworks, and reporting that strengthen CivicPlus’ overall security posture.

Compensation

And Benefits

  • Estimated Salary Grade Range: $70,300 - $101,300
  • Anticipated Hiring Range: $70,000 - $80,000
  • The actual salary offer will carefully consider a wide range of factors, including your skills, qualifications, experience and is based on a 40-hour work week.
  • Benefits: Comprehensive health insurance, dental insurance, vision insurance, Flexible Time Off, 401(k) plan, and more.

More open positions

Capital Markets Risk BSA

Work from home Full-time role

Associate Principal Analyst, Risk Monitoring - All Finra Locations

Work from home Full-time role

Risk Analyst (with Osint) - Information Security, Moodle - US (remote)

Work from home Full-time role

Fraud Risk Analyst

Work from home Full-time role

Senior Credit Risk Analyst - CECL & Stress Testing - Remote 2358278 | Draper, UT | Remote

Work from home Full-time role

Account Specialist

Work from home Full-time role

Sales, Account Manager - General Imaging Ultrasound (North Carolina)

Work from home Full-time role

Civil Litigation Associate | California | Remote | $125k–$185k | Defense Litigation

Work from home Full-time role

Adjunct, Graduate Applied Behavior Analysis Program, Department of Teaching, Learning, & Behavioral Studies

Work from home Full-time role

Remote Customer Service Representative – Work‑From‑Home (Singapore) – Frontline Support for careerzynith Retail Operations

Work from home Full-time role

[Remote] Senior Managing SAP Consultant MDG

Work from home Full-time role

Don't See a Role For You? Submit an application anyway!

Work from home Full-time role

Part-Time Evening Remote Data Entry Specialist – Flexible Home‑Based Role with Competitive Pay at careerzynith

Work from home Full-time role

Institutional Marketing Coordinator

Work from home Full-time role

HR Coordinator, Talent Acquisition & Projects

Work from home Full-time role

[Remote] Oracle EBS Techno-Functional Consultant

Work from home Full-time role

Sr. Director, Cloud & Network Infrastructure (Remote)

Work from home Full-time role

[Remote] Legal Engineer - Workflows Specialist (Large Law)

Work from home Full-time role

Account Manager - Gaming/Brand EMEA

Work from home Full-time role

[Remote] Account Associate - State Farm Agent Team Member

Work from home Full-time role

Mainframe DevOps Migration Consultant

Work from home Full-time role