×
Register Here to Apply for Jobs or Post Jobs. X

Risk Analyst

Job in Montgomery, Montgomery County, Alabama, 36117, USA
Listing for: Alera Group
Full Time position
Listed on 2026-08-24
Job specializations:
  • IT/Tech
    Information Security & Data Protection, Cybersecurity, IT Business Analyst
Job Description & How to Apply Below

Risk Analyst

Location:

Deerfield, IL | Remote

At Alera Group, our corporate teams play a critical role in supporting the success of colleagues and clients across the country. From Human Resources and Finance to Technology, Legal, Marketing, and Operations, these professionals ensure our organization runs efficiently while enabling our teams to deliver exceptional service.

Founded in 2017, Alera Group has grown to become the 14th largest broker of U.S. business. We are passionate about our clients' success in Employee Benefits, Property & Casualty Insurance, and Financial Services. With offices nationwide, our collaborative approach allows us to deliver national strength with local service.

We are always looking to connect with talented professionals who want to contribute to a collaborative, high-growth environment and help drive strategic initiatives across a national organization.

Collaborate with purpose – Work alongside colleagues who believe the best results come from strong partnerships, shared expertise, and supporting one another.

Build your career – Expand your expertise through meaningful work, continuous learning, and opportunities to grow across a national organization.

Make an impact – Help clients navigate complex challenges while contributing to solutions that make a difference for their businesses, employees, and communities.

Perform third-party security and compliance risk assessments for new and existing vendors, evaluating risk exposure, control effectiveness, business impact, and remediation requirements

Review SOC reports, security questionnaires, audit documentation, certifications, and other evidence to identify control gaps and potential business impacts

Coordinate and execute user access reviews, validating access appropriateness and ensuring identified issues are remediated promptly

Document risks, findings, recommendations, and remediation plans while maintaining accurate records within governance, risk, and compliance platforms

Serve as a trusted advisor to stakeholders by asking thoughtful questions, identifying underlying business needs, assessing potential risks, and translating ambiguous requests into clear risk assessment, governance, and compliance activities

Partner with Information Security, Technology, Legal, Procurement, and business stakeholders to identify requirements, resolve risk and compliance issues, and drive effective risk-based decision-making

Support internal and external audits, regulatory examinations, and compliance activities through evidence collection and documentation management

Develop risk metrics, reporting, and dashboards that drive visibility, support decision-making, and measure the effectiveness of third-party risk and governance programs

Identify opportunities to improve risk management processes, controls, reporting, governance practices, and automation capabilities

Required Qualifications

5+ years of experience in cybersecurity risk, IT risk, information security, governance, risk and compliance (GRC), third-party risk, IT audit, or a related field

Hands-on experience performing third-party or vendor security risk assessments

Experience coordinating or performing user access reviews, access certifications, or identity governance activities

Familiarity with cybersecurity and compliance frameworks such as NIST CSF, SOC 2, CIS Controls, HIPAA, or similar standards

Strong analytical, critical thinking, and communication skills with the ability to evaluate complex situations, identify underlying business and risk requirements, and effectively communicate recommendations to both technical and non-technical audiences

Experience working with GRC, ticketing, identity governance, or third-party risk management platforms

Exercise sound judgment when evaluating risk scenarios, identifying gaps in information, and determining appropriate next steps, stakeholders, and remediation activities

Certifications

CISA, CGRC or equivalent preferred

Preferred Qualifications

Experience with in a regulated industry such as insurance, financial services, or healthcare

Experience supporting SOC 2, HIPAA, NYDFS, or similar regulatory and compliance programs

Experience with automated…

To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary