Hiring.Camp

Security Risk Senior Analyst (Transparency Posting)

State of Colorado

·

2 days ago

Salary
$95k – $105k/yr
Location
Statewide, CO, CO, US
Department
Security
Seniority
Senior
Visa
Not sponsored
Source
GovernmentJobs

Description



Together, we innovate for a stronger Colorado

The work of employees at the Governor's Office of Information Technology (OIT) is challenging and diverse because the needs of agencies, customers and Coloradans constantly evolve. But our focus never changes: improve the lives of all Coloradans through innovation and collaboration. We're building one of the nation's leading government IT organizations by reimagining how we support agencies, building first-of-their-kind applications, and creating an inclusive, collaborative culture, together. Join us in the important work of providing equitable access to services.


Watch this video to learn more about how we're Serving People. Serving Colorado.



IMPORTANT NOTE: Please review your application to ensure completion. For the most equitable applicant experience, OIT’s hiring team considers only the contents of your application to review your qualifications. Please do not include any attachments (such as resume or cover letter) with your application as these items are not used by OIT’s hiring team.  



Transparency Posting: This position is intended for and will be filled with an existing resource. This posting is for notification purposes only under the Equal Pay for Equal Work Act.


Senior Risk Analyst is a pivotal role responsible for identifying, assessing, and managing cybersecurity risks across state systems, data assets, and third-party relationships. In this role, you will lead the development and maintenance of our risk management program, ensuring alignment with the NIST Cybersecurity Framework (CSF) and regulatory requirements (e.g., CJIS, HIPAA). 

The ideal candidate will conduct risk assessments, evaluate security controls, track remediation efforts, and translate technical findings into actionable guidance for leadership. This position offers a unique opportunity to collaborate across departments, ensuring risk-informed decision-making and protecting critical constituent data and public services. 


Essential Functions:
  • Risk management strategy & governance: Establish and maintain the organization's cybersecurity risk management strategy, risk appetite, and tolerance thresholds in line with NIST CSF Govern (GV) outcomes. Outcome: an approved risk appetite statement that guides prioritization decisions across the security program.

  • Roles, policy & oversight: Define risk-related roles, responsibilities, and reporting lines; maintain policies governing risk assessment cadence and escalation. Outcome: documented governance structure that passes audit scrutiny and clarifies accountability.

  • Asset & risk assessment: Using current inventory of critical assets, conduct regular risk assessments mapped to CSF Identify (ID) categories (Asset Management, Risk Assessment, Improvement). Outcome: a rationalized and living risk register with likelihood/impact scoring covering all critical assets.

  • Third-party & supply chain risk: Maintain a documented program and processes to assess vendor and partner cybersecurity posture as part of ID.SC (Supply Chain Risk Management). Outcome: documented due diligence and reduced third-party exposure, evidenced in vendor risk files.

  • Control evaluation & gap analysis: Evaluate existing safeguards against CSF Protect (PR) categories (Identity Management, Data Security, Platform Security) to identify control gaps. Outcome: prioritized remediation roadmap tied to residual risk reduction.

  • Threat & risk trend monitoring: Analyze threat intelligence and detection findings (CSF Detect/DE) to refine and recalibrate the risk model. Outcome: a risk register that reflects current threat activity, not static assumptions.

  • Incident risk analysis & remediation tracking: Partner with incident response teams to assess risk impact of incidents (CSF Respond/RS) and track remediation of resulting findings to closure. Outcome: closed-loop remediation with measurable mean-time-to-remediate metrics.

  • Recovery planning risk input: Contribute risk analysis to recovery planning and business continuity efforts (CSF Recover/RC), ensuring recovery priorities reflect actual risk exposure. Outcome: recovery plans that are risk-informed and tested.

  • Executive & stakeholder reporting: Translate risk findings across all six CSF functions into business-relevant reporting for agencies, executives, and stakeholders (legal, compliance). Outcome: informed resourcing decisions and improved organization-wide risk literacy.

  • Program maturity metrics: Define and track KPIs/KRIs mapped to CSF function maturity (e.g., % of assets assessed, control coverage, remediation velocity). Outcome: quantifiable, framework-aligned evidence of year-over-year program maturity. 


  •   Additional Functions: 


  • Self-Direction & Autonomy

    • Operates independently with minimal supervision; exercises sound judgment in ambiguous or evolving situations

    • Prioritizes and manages a complex workload across competing deadlines without day-to-day direction

    • Recognizes when to escalate versus when to resolve independently

  • Continuous Improvement Ownership

    • Proactively identifies gaps or inefficiencies in the risk program and drives improvements without being asked

    • Stays current on evolving threats, regulatory changes, and framework updates (e.g., NIST CSF revisions) and incorporates them into practice

    • Seeks feedback on their own work product and iterates on risk methodologies, templates, and reporting over time

  • Mentorship & Influence

    • Mentors other analysts and stakeholders 

    • Influences stakeholders and leadership without formal authority — builds credibility through sound analysis rather than positional power

    • Acts as a subject-matter resource other teams turn to for risk-related questions

  • Accountability & Ownership

    • Takes ownership of outcomes, not just tasks — follows through on remediation and reporting until issues are genuinely resolved

    • Willing to make and stand behind risk recommendations, including ones that are unpopular or involve trade-offs

    • Documents decisions and rationale clearly enough to withstand audit or leadership scrutiny

  • Judgment Under Ambiguity

    • Comfortable making risk-based recommendations with incomplete information

    • Balances competing priorities (security, budget, mission delivery, public accountability) rather than defaulting to a single lens

  • Communication & Composure

    • Communicates effectively under pressure, including during incidents or audit findings

    • Adapts communication style for technical staff, program managers, and non-technical executives or elected oversight bodies

  • Professional Development

    • Maintains and pursues relevant certifications (CISSP, CRISC, CISM) as a mark of ongoing self-investment

    • Participates in professional risk/security communities to bring outside perspective back into the agency





A wide salary range is posted for this position and any job offer is based upon a salary analysis to comply with the Colorado Equal Pay for Equal Work Act. The salary analysis considers relevant experience, education, certifications, and state seniority as compared to others doing substantially similar work. While most salary offers are made within the posted range, occasionally an offer is made below or above the posted range based upon this salary analysis.

This is a skills-based job announcement. The required minimum qualifications and/or education (if substituting for the proven experience, knowledge, and skills), are as follows:

Minimum Qualifications:


  • Minimum of five (5) years of experience managing cybersecurity risks across state systems, data assets, and third-party relationships.

  • Experience with the NIST Cybersecurity Framework (CSF) and applicable state and federal regulatory requirements (e.g., state IT security policies, CJIS, HIPAA, IRS Publication 1075, as applicable). 


Substitutions:


  • Additional appropriate education will substitute for the required experience on a year-for-year basis, but cannot completely substitute for these qualifications. 

  • Training or Certification related to the work assigned to the position will be assigned credit towards substitution for experience and/or education, but cannot completely substitute for these qualifications. 

  • If the minimum qualifications include a degree requirement, additional appropriate paid or unpaid experience will substitute for the required education on a year-for-year basis.



Preferred Qualifications:


  • Professional security certification.





Conditions of Employment:

OIT employees must comply with any screening procedures in place at state agency locations where they might perform work. 

A pre-employment background check will be conducted as part of the selection process. Post-employment background checks will be required for specific agencies as business needs dictate, which may include a polygraph exam, fingerprint-based criminal history search, reference checks, and a drug test.

This position may require travel within the specified geographic area, and to locations across the state as needed. 

This position may require on-call duties as needed by the position. 





If this posting indicates “remote from anywhere in CO” in the title, periodic reporting to the primary state work location designated for the position is required. All remote work must be performed in Colorado. 


While candidates from out of state will be considered for this role, the candidate selected for the position must relocate and reside in Colorado on the first day of their new position.  A reasonable timeframe for relocation will be established on an individual basis, while considering business needs, and determining a start date.

We know it's important to support each other, and that means having a healthy balance of work and personal time. Visit our benefits to learn more about some of our great offerings that allow us all to have fulfilling lives. 


Visit our How to Apply webpage to learn more about our application process and what to expect after you apply.

The State of Colorado strives to create a Colorado for All by building and maintaining workplaces that value and respect all Coloradans through a commitment to equal opportunity and hiring based on merit and fitness.  The State is resolute in non-discriminatory practices in everything we do, including hiring, employment, and advancement opportunities.

The Governor's Office of Information Technology is committed to the full inclusion of all qualified individuals. As part of this commitment, our agency will assist individuals who have a disability with any reasonable accommodation requests related to employment, including completing the application process, interviewing, completing any pre-employment testing, participating in the employee selection process, and/or to perform essential job functions where the requested accommodation does not impose an undue hardship. If you have a disability and require reasonable accommodation to ensure you have a positive experience applying or interviewing for this position, please direct your inquiries to our ADA Coordinator at [email protected] or call (303) 764-7900.

This posting may be used to fill multiple vacancies based upon business need. 

The Governor's Office of Information Technology does NOT offer sponsored Visas for employment purposes.



Skills

CybersecurityRisk ManagementComplianceHIPAACISSP

Similar Jobs

30

Senior Risk Manager, Central Monitoring, LATAM, Security Operations Group | Worldwide Operations Security

Amazon · Remote

4 days ago

Senior Manager, Information Security (Security Risk Management), APEC

Marriott Hotels & Resorts · Singapore, Singapore, SG

6 days ago

Sr. Principal Security, Risk, and OT Solution Architect

ServiceNow · Portland, Oregon, United States · Remote

1 week ago

Sr. Principal Security, Risk, and OT Solution Architect

ServiceNow · Chicago, Illinois, United States · Remote

1 week ago

Sr. Principal Security, Risk, and OT Solution Architect

ServiceNow · Dallas, Texas, United States · Remote

1 week ago

Senior Consultant, Digital Risk & Cyber Security

Baringa · London, United Kingdom

1 week ago

IS Security, Risk & Compliance Senior Consultant

Abb · Krakow, Malopolskie, Poland +1 · Hybrid

1 week ago

Sr. Research IT Security Risk and Compliance Analyst - Computing Services

Careers @ Carnegie Mellon · Pittsburgh, United States of America

1 week ago

Senior Specialist Risk & Security

Mmc · Cluj-Napoca - Decembrie, Romania · Hybrid

2 weeks ago

Senior Information Security Risk Analyst

Encora · Peru

2 weeks ago

Senior Solution Sales Executive - (Risk & Security)

ServiceNow · Frankfurt, Germany · Hybrid

2 weeks ago

Senior Solution Sales Executive - (Risk & Security)

ServiceNow · Munich, Germany · Hybrid

2 weeks ago

Senior Solution Sales Executive (Risk & Security)

ServiceNow · Wien, Austria · Hybrid

2 weeks ago

Senior BD Manager – Security Risk Consulting

Jensen Hughes · Riyadh, Saudi Arabia

3 weeks ago

Security Risk & Engineering - Tech and Cyber Risk & Compliance - Senior Manager

Pwc · New York - 300 Madison Avenue, United States of America +8

3 weeks ago

Security Risk & Engineering - Tech and Cyber Risk & Compliance - Senior Associate

Pwc · New York - 300 Madison Avenue, United States of America +8

4 weeks ago

Sr. Security Risk Analyst

Crane Worldwide Logistics · Houston, TX

4 weeks ago

Cyber Security Risk Governance Senior Associate

Depository Trust Company · TX, United States, US

4 weeks ago

Senior IT Security Risk Advisor

Basicfit · Hoofddorp, Netherlands

1 month ago

Senior Security Risk Management SME

CDO Technologies · Washington, DC

1 month ago

Senior Information Security Risk Analyst

Warnerbros · GA Atlanta 1050 Techwood Drive NW, United States of America · Hybrid

1 month ago

Senior Analyst, Security Risk

Twilio · Remote - US · Remote

1 month ago

Senior Analyst, Security Risk

Twilio · US +1 · Remote

1 month ago

Sr Information Security Analyst - Insider Risk

Regeneron · SLEEPY HOLLOW, United States of America · Onsite

1 month ago

Senior Information Security, Risk & Compliance Specialist

Geotab · z. Canada Job Post Template +1

1 month ago

Senior Delivery Consultant - Security, Risk, and Compliance, AWSI Professional Services

Amazon

1 month ago

Senior Delivery Consultant - Security, Risk, and Compliance, AWSI Professional Services

Amazon

1 month ago

Senior Data Security Engineer (Insider Risk Management – Engineering)

AbbVie · Cambridge, MA, United States · Hybrid

1 month ago

Senior Third-Party Cyber Security Risk Analyst

Toyota · Plano, United States of America

1 month ago

Senior Manager, IT Risk, Data Privacy & Security

EisnerAmper is one of the · Baton Rouge, United States of America

2 months ago