Skip to main content
Tallo logoTallo logo

Find Jobs

Find Jobs Near You – Available Work in Your Location

Skip to job details

Back to Results

Apply for this opportunity

To apply for this job, you'll continue to an external website or email application.

Insight Global

IT Enterprise Risk Analyst

Career Insights for Technical Consultant / Analyst

See where this job fits in the broader career landscape. Knowing your career path helps you see what's possible from here.

Scorecard

Based on Florida data

Review key factors to help you decide if this role fits your goals. How is this calculated?

Were these scores useful?

What they do

A Technical Consultant or Analyst provides information technology consulting services to businesses and organizations. Advises or manages installation or expansion of computer network systems; provides problem-solving assistance and staff training with new systems. May work independently or as part of a consulting team.

$93,923 / year median in Florida

-0% projected decline

Explore Career

Job Description

Job Description We are seeking an IT Enterprise Risk Analyst to join our team. The IT Risk Analyst helps manage the Firm's GRC and IT risk programs, focusing on information security for client data, attorney work, and privileged communications. Reporting to the IT Enterprise Risk Management Manager, the role maintains policies, assesses risks and controls, coordinates third-party reviews, drafts responses for client guidelines, prepares evidence for cyber insurance, and supports audits. Responsibilities align with
ISO/IEC 27001/27002, NIST CSF, CIS
Controls, SOC 2, HIPAA, GLBA, GDPR, and state privacy laws (e.g., CCPA/CPRA). We are a company committed to creating diverse and inclusive environments where people can bring their full, authentic selves to work every day. We are an equal opportunity/affirmative action employer that believes everyone matters. Qualified candidates will receive consideration for employment regardless of their race, color, ethnicity, religion, sex (including pregnancy), sexual orientation, gender identity and expression, marital status, national origin, ancestry, genetic factors, age, disability, protected veteran status, military or uniformed service member status, or any other status or characteristic protected by applicable laws, regulations, and ordinances. If you need assistance and/or a reasonable accommodation due to a disability during the application or recruiting process, please send a request to HR@insightglobal.com.

To learn more about how we collect, keep, and process your private information, please review
Insight Global's Workforce Privacy Policy:
https://insightglobal.com/workforce-privacy-policy/. Skills and Requirements
  • Strong written and verbal communication skills; ability to translate control requirements into clear documentation and actionable guidance.
  • Strong organizational skills and attention to detail.
  • Ability to manage multiple priorities and deadlines.
  • Knowledge or ability to learn Microsoft Office Suite, or Microsoft 365.
Required Qualifications & Education:
  • Bachelor's degree in information security, Information Technology, Risk Management, Business, or equivalent practical experience.
  • 3+ years of experience in GRC, information security, technology risk management, compliance, internal audit, or third-party risk management.
  • Working knowledge of
ISO/IEC 27000
Family concepts, NIST CSF/SP 800-53/800-171, and HIPAA.
  • Familiarity with EU information security and privacy requirements (e.g., GDPR security principles); familiarity with NIS2 is a plus where relevant.
  • Experience collecting, organizing, and validating control evidence and supporting audits/assessments.
Certifications -
ISACA:
CRISC (Certified in Risk and Information Systems Control) and/or CISA (Certified Information Systems Auditor). Prior exposure to GRC, IT risk, or information security work in a law firm, professional services firm, or other client-confidential environment is preferred. Familiarity with legal-industry technology (document management such as iManage or NetDocuments; time and billing such as 3E or Aderant; conflicts and new business intake such as Intapp; eDiscovery platforms such as Relativity) and with the data-sensitivity considerations they raise is a plus. Awareness of the ABA Model Rules of Professional Conduct (in particular Rules 1.1 and 1.6) and applicable state bar requirements relating to technology competence and client confidentiality is preferred. Familiarity with Controlled Unclassified Information (CUI) handling, NIST SP 800-171, CMMC, and
ITAR/EAR
data-handling concepts; prior exposure to federal, defense, or government-contracts client matters is a plus. Certifications -
ISACA:
COBIT Foundation, CDPSE, or CGEIT as applicable to governance, privacy, and enterprise risk responsibilities
ISO/IEC 27001
Internal Auditor, Lead Implementer, or Lead Auditor. Cloud and platform risk certifications such as
Microsoft Certified:
Security, Compliance, and Identity Fundamentals (SC-900), Azure Security Engineer Associate (AZ-500), or similar.

Benefits

  • Dental Insurance