civicplus
civicplus1mo ago
New
$70,300 – $101,300/yr

Information Security Risk Analyst

United StatesUnited StatesRemotemid
OtherInformation Security
0 views0 saves0 applied

Quick Summary

Key Responsibilities

The Information Security Risk Analyst is responsible for identifying, assessing, tracking, and communicating information security risks across the organization.

Requirements Summary

Experience 4 – 6 Years of experience in information security, cybersecurity, risk management, or related field Working experience managing enterprise/third-party risk assessments, risk registers, and security training programs.

Technical Tools
awsazuregcpcybersecuritysaas

The Information Security Risk Analyst is responsible for identifying, assessing, tracking, and communicating information security risks across the organization. This role supports a maturing cybersecurity program by managing acceptable enterprise and third-party risks and leading security training initiatives. 

Nice to Have

~1 min read

At CivicPlus, we strive to bring our company vision to life through innovation and collaboration. Supported by approachable leadership and transparent communication, we're empowered to make an impact on local government and the residents they serve. Grow your career alongside great people, where authenticity is welcome, successes are celebrated, and potential is nurtured.

Responsibilities

~1 min read

As an InfoSec Risk Analyst, you will:

  • Identify and translate inherent and residual risk through likelihood, impact, treatment plans, and ownership.  
  • Define and track risk and awareness key metrics to measure program effectiveness and communicate to leadership and governance committees. 
  • Conduct and manage enterprise information security risk assessment through recognized frameworks (including NIST 800-30) and maintain an information security risk register.  
  • Lead third-party security risk assessments for vendors, partners, and service providers through analysis of assurance documentation, security testing summaries, and security questionnaires. 
  • Maintain the information security risk register and third-party vendor risk inventory to track and monitor ongoing risks and approved exceptions. 
  • Develop and lead enterprise security awareness training, including phishing simulations and targeted role-based training for security education and reporting. 
  • Support internal and external security and compliance assessments through risk evidence and documentation. 
  • Partner closely with organizational functions and key stakeholders to understand and address organizational risks across systems and processes, and ensure security risks are understood, prioritized, and treated in alignment with organizational risk appetite. 

We know that excellent candidates come from diverse backgrounds. Even if you don’t meet 100% of the listed requirements, we encourage you to apply!

Requirements

~1 min read

This role offers:

  • Shape how security risk is managed across CivicPlus. Identify, assess, and guide the treatment of enterprise and third-party risks that impact our platforms and customers.
  • Turn complex security risk into clear business insight. Partner with leaders across the organization to translate technical risk into actionable decisions.
  • Build a stronger security culture. Lead enterprise security awareness initiatives, including phishing simulations and role-based training that help employees stay ahead of threats.
  • Contribute to a growing cybersecurity program. Help mature risk management practices, frameworks, and reporting that strengthen CivicPlus’ overall security posture.

What We Offer

~1 min read
Estimated Salary Grade Range: $70,300 - $101,300Anticipated Hiring Range: $70,000 - $80,000
The actual salary offer will carefully consider a wide range of factors, including your skills, qualifications, experience and is based on a 40-hour work week.
Benefits: Comprehensive health insurance, dental insurance, vision insurance, Flexible Time Off, 401(k) plan, and more.
  • Introductory call with Talent Acquisition
  • Interview with the Hiring Manager
  • Interviews with Team Leadership (may include multiple conversations)
  • Offer

Note: The process may vary slightly depending on the role. 

  •  CivicPlus is currently unable to provide visa sponsorship for this position now or in the future. Applicants must be authorized to work in the US. 
  • We encourage you to apply as soon as possible, as applications will be reviewed on a rolling basis, and the posting may close earlier at the discretion of the Talent Acquisition team

CivicPlus is proud to be an Equal Employment Opportunity employer. We celebrate and support diversity for the benefit of our employees, products, clients, and communities. Reasonable accommodations are available during the interview process.

 

Location & Eligibility

Where is the job
United States
Remote within one country
Who can apply
US

Listing Details

Posted
March 12, 2026
First seen
May 7, 2026
Last seen
May 8, 2026

Posting Health

Days active
0
Repost count
0
Trust Level
23%
Scored at
May 7, 2026

Signal breakdown

freshnesssource trustcontent trustemployer trust
Newsletter

Stay ahead of the market

Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.

A
B
C
D
Join 12,000+ marketers

No spam. Unsubscribe at any time.

civicplusInformation Security Risk Analyst$70k–$101k