- Salary
- $95k – $105k/yr
- Location
- Statewide, CO, CO, US
- Department
- Security
- Seniority
- Senior
- Visa
- Not sponsored
- Source
- GovernmentJobs
Description
Together, we innovate for a stronger Colorado
The work of employees at the Governor's Office of Information Technology (OIT) is challenging and diverse because the needs of agencies, customers and Coloradans constantly evolve. But our focus never changes: improve the lives of all Coloradans through innovation and collaboration. We're building one of the nation's leading government IT organizations by reimagining how we support agencies, building first-of-their-kind applications, and creating an inclusive, collaborative culture, together. Join us in the important work of providing equitable access to services.
Watch this video to learn more about how we're Serving People. Serving Colorado.
IMPORTANT NOTE: Please review your application to ensure completion. For the most equitable applicant experience, OIT’s hiring team considers only the contents of your application to review your qualifications. Please do not include any attachments (such as resume or cover letter) with your application as these items are not used by OIT’s hiring team.
Transparency Posting: This position is intended for and will be filled with an existing resource. This posting is for notification purposes only under the Equal Pay for Equal Work Act.
Senior Risk Analyst is a pivotal role responsible for identifying, assessing, and managing cybersecurity risks across state systems, data assets, and third-party relationships. In this role, you will lead the development and maintenance of our risk management program, ensuring alignment with the NIST Cybersecurity Framework (CSF) and regulatory requirements (e.g., CJIS, HIPAA).
The ideal candidate will conduct risk assessments, evaluate security controls, track remediation efforts, and translate technical findings into actionable guidance for leadership. This position offers a unique opportunity to collaborate across departments, ensuring risk-informed decision-making and protecting critical constituent data and public services.
Essential Functions:
Risk management strategy & governance: Establish and maintain the organization's cybersecurity risk management strategy, risk appetite, and tolerance thresholds in line with NIST CSF Govern (GV) outcomes. Outcome: an approved risk appetite statement that guides prioritization decisions across the security program.
Roles, policy & oversight: Define risk-related roles, responsibilities, and reporting lines; maintain policies governing risk assessment cadence and escalation. Outcome: documented governance structure that passes audit scrutiny and clarifies accountability.
Asset & risk assessment: Using current inventory of critical assets, conduct regular risk assessments mapped to CSF Identify (ID) categories (Asset Management, Risk Assessment, Improvement). Outcome: a rationalized and living risk register with likelihood/impact scoring covering all critical assets.
Third-party & supply chain risk: Maintain a documented program and processes to assess vendor and partner cybersecurity posture as part of ID.SC (Supply Chain Risk Management). Outcome: documented due diligence and reduced third-party exposure, evidenced in vendor risk files.
Control evaluation & gap analysis: Evaluate existing safeguards against CSF Protect (PR) categories (Identity Management, Data Security, Platform Security) to identify control gaps. Outcome: prioritized remediation roadmap tied to residual risk reduction.
Threat & risk trend monitoring: Analyze threat intelligence and detection findings (CSF Detect/DE) to refine and recalibrate the risk model. Outcome: a risk register that reflects current threat activity, not static assumptions.
Incident risk analysis & remediation tracking: Partner with incident response teams to assess risk impact of incidents (CSF Respond/RS) and track remediation of resulting findings to closure. Outcome: closed-loop remediation with measurable mean-time-to-remediate metrics.
Recovery planning risk input: Contribute risk analysis to recovery planning and business continuity efforts (CSF Recover/RC), ensuring recovery priorities reflect actual risk exposure. Outcome: recovery plans that are risk-informed and tested.
Executive & stakeholder reporting: Translate risk findings across all six CSF functions into business-relevant reporting for agencies, executives, and stakeholders (legal, compliance). Outcome: informed resourcing decisions and improved organization-wide risk literacy.
Program maturity metrics: Define and track KPIs/KRIs mapped to CSF function maturity (e.g., % of assets assessed, control coverage, remediation velocity). Outcome: quantifiable, framework-aligned evidence of year-over-year program maturity.
Additional Functions:
Self-Direction & Autonomy
Operates independently with minimal supervision; exercises sound judgment in ambiguous or evolving situations
Prioritizes and manages a complex workload across competing deadlines without day-to-day direction
Recognizes when to escalate versus when to resolve independently
Continuous Improvement Ownership
Proactively identifies gaps or inefficiencies in the risk program and drives improvements without being asked
Stays current on evolving threats, regulatory changes, and framework updates (e.g., NIST CSF revisions) and incorporates them into practice
Seeks feedback on their own work product and iterates on risk methodologies, templates, and reporting over time
Mentorship & Influence
Mentors other analysts and stakeholders
Influences stakeholders and leadership without formal authority — builds credibility through sound analysis rather than positional power
Acts as a subject-matter resource other teams turn to for risk-related questions
Accountability & Ownership
Takes ownership of outcomes, not just tasks — follows through on remediation and reporting until issues are genuinely resolved
Willing to make and stand behind risk recommendations, including ones that are unpopular or involve trade-offs
Documents decisions and rationale clearly enough to withstand audit or leadership scrutiny
Judgment Under Ambiguity
Comfortable making risk-based recommendations with incomplete information
Balances competing priorities (security, budget, mission delivery, public accountability) rather than defaulting to a single lens
Communication & Composure
Communicates effectively under pressure, including during incidents or audit findings
Adapts communication style for technical staff, program managers, and non-technical executives or elected oversight bodies
Professional Development
Maintains and pursues relevant certifications (CISSP, CRISC, CISM) as a mark of ongoing self-investment
Participates in professional risk/security communities to bring outside perspective back into the agency
A wide salary range is posted for this position and any job offer is based upon a salary analysis to comply with the Colorado Equal Pay for Equal Work Act. The salary analysis considers relevant experience, education, certifications, and state seniority as compared to others doing substantially similar work. While most salary offers are made within the posted range, occasionally an offer is made below or above the posted range based upon this salary analysis.
This is a skills-based job announcement. The required minimum qualifications and/or education (if substituting for the proven experience, knowledge, and skills), are as follows:
Minimum Qualifications:
Minimum of five (5) years of experience managing cybersecurity risks across state systems, data assets, and third-party relationships.
Experience with the NIST Cybersecurity Framework (CSF) and applicable state and federal regulatory requirements (e.g., state IT security policies, CJIS, HIPAA, IRS Publication 1075, as applicable).
Substitutions:
Additional appropriate education will substitute for the required experience on a year-for-year basis, but cannot completely substitute for these qualifications.
Training or Certification related to the work assigned to the position will be assigned credit towards substitution for experience and/or education, but cannot completely substitute for these qualifications.
If the minimum qualifications include a degree requirement, additional appropriate paid or unpaid experience will substitute for the required education on a year-for-year basis.
Preferred Qualifications:
Professional security certification.
Conditions of Employment:
OIT employees must comply with any screening procedures in place at state agency locations where they might perform work.
A pre-employment background check will be conducted as part of the selection process. Post-employment background checks will be required for specific agencies as business needs dictate, which may include a polygraph exam, fingerprint-based criminal history search, reference checks, and a drug test.
This position may require travel within the specified geographic area, and to locations across the state as needed.
This position may require on-call duties as needed by the position.
If this posting indicates “remote from anywhere in CO” in the title, periodic reporting to the primary state work location designated for the position is required. All remote work must be performed in Colorado.
While candidates from out of state will be considered for this role, the candidate selected for the position must relocate and reside in Colorado on the first day of their new position. A reasonable timeframe for relocation will be established on an individual basis, while considering business needs, and determining a start date.
We know it's important to support each other, and that means having a healthy balance of work and personal time. Visit our benefits to learn more about some of our great offerings that allow us all to have fulfilling lives.
Visit our How to Apply webpage to learn more about our application process and what to expect after you apply.
The State of Colorado strives to create a Colorado for All by building and maintaining workplaces that value and respect all Coloradans through a commitment to equal opportunity and hiring based on merit and fitness. The State is resolute in non-discriminatory practices in everything we do, including hiring, employment, and advancement opportunities.
The Governor's Office of Information Technology is committed to the full inclusion of all qualified individuals. As part of this commitment, our agency will assist individuals who have a disability with any reasonable accommodation requests related to employment, including completing the application process, interviewing, completing any pre-employment testing, participating in the employee selection process, and/or to perform essential job functions where the requested accommodation does not impose an undue hardship. If you have a disability and require reasonable accommodation to ensure you have a positive experience applying or interviewing for this position, please direct your inquiries to our ADA Coordinator at [email protected] or call (303) 764-7900.
This posting may be used to fill multiple vacancies based upon business need.The Governor's Office of Information Technology does NOT offer sponsored Visas for employment purposes.