Lead Security Risk Assessment Analyst
Listed on 2026-08-29
-
IT/Tech
Information Security & Data Protection, Cybersecurity, IT Consultant
Lead Security Risk Assessment Analyst
This position will develop and conduct information security risk assessments on parties external to Lincoln Financial Group to ensure that information security risks associated with those relationships are within acceptable tolerances. The Sr. Analyst will provide direction and guidance to stakeholders concerning risks associated with assessment findings and adherence to applicable procedures, regulations, and/or laws.
Performs complex risk assessments of external party information security controls to ensure they meet or exceed Lincoln's information security risk management requirements for the services to be provided. Determines information security risk profiles for various vendor and business partner services using questionnaires and knowledge of Lincoln policy and relevant industry best practices and standards. Recommends mitigation plans/solutions to eliminate, reduce, or mitigate risk, and communicates said solutions to both external parties and internal business stakeholders.
Effectively escalates and challenges risks, exceptions, and concerns using a fact-based, solution-oriented approach while maintaining productive working relationships. Assists in creating and enforcing information security standards, policies and procedures. Researches and maintains current knowledge regarding information security issues, trends, and legislation related to information security. Communicates complex security and risk concepts in a professional, constructive, and audience-appropriate manner, adapting messaging to various levels of technical expertise, organizational role, and business need.
Builds credibility, trust, and productive working relationships through effective stakeholder engagement, active listening, respectful professional communication, and demonstrated openness to differing perspectives. Demonstrates sound judgment and organizational awareness when communicating concerns, advocating positions, and navigating disagreement, ensuring productive outcomes and positive stakeholder experiences. Responds to incoming requests from external parties for information concerning Lincoln's information security practices by providing appropriately scoped and accurate information in a timely and professionally written manner.
Reports status of engagements to Information Security management, project managers, and other business stakeholders as appropriate. Develops, analyzes, and leverages metrics, trends, and key performance indicators (KPIs) to measure program effectiveness, identify opportunities for continuous improvement, and influence leadership decision-making. Records pertinent documentation and communications for all assessments in Lincoln's online information technology (IT) governance, risk, and compliance platform. Evaluates and identifies security risks of third-party artificial intelligence (AI) solutions to provide guidance to internal stakeholders based on Lincoln policies and industry best practices.
Applies working knowledge of AI technologies, including generative AI, to evaluate third-party risk, identify emerging security considerations, and support responsible adoption within the organization. Maintains knowledge of emerging AI trends, technologies, and associated security risks to support innovation and responsible adoption within the organization.
Must Haves: 4 Year/Bachelor's degree in Information Systems, IT Audit, Information Security, Information Risk Management, or related field or equivalent – OR - Work experience (Minimum 4 years of experience in lieu of Bachelor's) 5+ years of experience in IT Security, IT Audit or Information Risk Management that directly aligns with the specific responsibilities for this position. 2+ years of experience in Artificial Intelligence that directly aligns with the specific responsibilities for this position.
Nice to Haves:
CompTIA Security+ certification or greater preferred
Applications will be accepted through September 30, 2026, and the posting may be taken down early due to applicant volume.
The pay range for this position is $120,375 - $192,600 with anticipated pay for new hires between the minimum…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).