IT Security and Risk Analyst
Listed on 2025-12-17
-
IT/Tech
Cybersecurity, Information Security
This position is based in Atlanta, Charlotte, Chicago, Dallas, and Houston only.
Why SeyfarthAt Seyfarth, we understand that great people are the key to our success, and we provide the opportunities to match. If you join us, you’ll work with state‑of‑the‑art technology in a friendly and professional environment, and we will continue to invest in your professional development. If you want the freedom to grow at a firm that is invested in your future, keep reading.
TheOpportunity
As an IT Security & Risk Analyst, you will support the Information Security Governance, Risk and Compliance function (ISGRC), ensuring the firm is able to address rapidly changing threats, technologies, and business conditions. You will be a member of the firm’s IT Security and Risk Department, reporting directly to the IT Security & Risk Lead.
The Day‑To‑DayOn any given day, you will be working with firm leadership, partners, and clients on a variety of security compliance requests and risk‑based initiatives. You will:
- Conduct and manage internal risk reviews of new or existing infrastructure and applications.
- Conduct and manage third‑party risk assessments.
- Assist and manage client audits and ongoing compliance to completion.
- Follow‑up on deficiencies identified in monitoring reviews, self‑assessments, automated assessments, and internal/external audits to ensure that appropriate remediation measures have been taken.
- Collaborate with control owners and key stakeholders to meet outside counsel guidelines or contractual requirements around information security standards.
- Produce metrics to monitor the completion of control objectives and tracking of deficiencies or gaps in program requirements.
- Provide consulting to internal projects and efforts on security requirements and potential risks.
- Propose changes to existing policies, standards, and procedures to minimize risk and ensure compliance to client and applicable regulatory requirements.
- Assist with Security Awareness initiatives.
- Maintain an up‑to‑date understanding of industry best practices, and monitor the legal and regulatory environment for developments that could require changes to established policies, standards, and practices.
- Bachelor's degree or equivalent work experience
- 3‑5 years of experience managing risk and supporting client audit engagements
- Any of the following certifications:
CRISC, CISM, PMP, CISSP, CISA, preferred. - Knowledge of emerging technology and the security governance implications.
- Demonstrated understanding of security risk management concepts, cyber security frameworks (NIST, ISO, etc.), control standards, secure coding principles, and security technologies.
- Knowledge of information security fundamentals, best practices and industry standards with prior responsibilities of protecting information assets.
- Knowledge of laws, regulations, and requirements related to information security.
- Strong organization and prioritization skills across multiple tasks.
- Commitment to continuous improvement and professional growth.
- Desire to ask questions, analyze, adapt, and make decisions grounded in doing what’s right for our clients and firm stakeholders.
Seyfarth provides competitive salary and benefits at all levels, and our culture embraces the entrepreneurial spirit of its professionals like no other firm. Our professional staff are a collaborative team, helping to define the unique client experience offered by the firm. We understand that it takes more than attorneys to build a successful legal practice; everyone participates in our commitment to excellence.
MoreAbout Seyfarth
With more than 975+ lawyers across 18 offices, Seyfarth Shaw LLP provides advisory, litigation, and transactional legal services to clients worldwide. Learn more about The Seyfarth Experience at
Seyfarth Shaw is committed to equal employment opportunity and providing reasonable accommodations to applicants with physical and/or mental disabilities. We value and encourage diversity and solicit applications from all qualified applicants without regard to race, color, gender, sex, age, religion, creed, national origin, ancestry, citizenship, marital status, sexual…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).