- Company Name
- Robertson & Company Ltd.
- Job Title
- Information Risk Management Analyst III
- Job Description
-
**Job Title:** Information Risk Management Analyst III
**Role Summary:**
Conducts comprehensive information risk assessments for technology initiatives, ensuring alignment with security policies and standards. Provides recommendations to security teams, participates in system go‑live acceptance reviews, and reports assessment findings. Works on a variety of infrastructures, including on‑prem, virtual, and cloud, focusing on architecture controls and threat mitigation.
**Expectations:**
- Perform risk analyses from a technical security perspective for up to 12 months.
- Lead or support security requirement validation for project teams.
- Deliver clear, structured risk assessment reports to stakeholders.
- Collaborate with service areas on acceptance reviews and standard methodology implementation.
**Key Responsibilities:**
- Identify, validate, and document security requirements for projects.
- Execute in‑depth risk assessments across Windows, Unix, Linux, virtual, network, and cloud environments.
- Provide input to ETS Service Areas on security requirements and methodologies.
- Participate in go‑live acceptance reviews for new infrastructure and services.
- Report assessment findings per internal templates and deadlines.
- Perform additional information risk management tasks as assigned.
**Required Skills:**
- 5+ years of information security and risk management experience.
- Knowledge of security architecture and controls across Windows, Unix, RH Linux, virtual hosting, networking, endpoint, and cloud (IaaS, PaaS, SaaS).
- Familiarity with security systems: privilege management, SIEM, NAC, vulnerability management, PKI, encryption, APT tools (FireEye, Z‑scaler), firewall/IPS, WAF.
- Understanding of frameworks and methodologies: OWASP, SANS, penetration testing.
- Experience with application security standards, secure coding, and testing techniques.
- Hands‑on experience with Azure, AWS, or GCP; Windows services such as AD, DNS, IIS, MSSQL, ADFS, SAML; and collaboration platforms (Office 365, SharePoint).
- Awareness of AI technologies and deployment models.
**Required Education & Certifications:**
- Bachelor’s degree in Computer Science, Technology, or related field.
- Certifications such as CISSP, CISA, CISM, or CEH are advantageous.
---