Jobs › IT Enterprise Risk Analyst
IT Enterprise Risk Analyst
Job at a glance
- Category
- Risk
- Work arrangement
- Hybrid
- Location
- Miami, FL
- Posted
- Jul 31, 2026
Free. One click to unsubscribe. We never share your address.
Holland & Knight is hiring a IT Enterprise Risk Analyst in Miami, FL. This is a Risk job in the governance, risk, and compliance field. Review the full details below and apply directly with Holland & Knight.
We are a Firm where people truly believe in what they do and strive to achieve the highest standards of performance and success. This position is based in the Firm's global operations center in Tampa, FL. General Description: We are seeking an IT Enterprise Risk Analyst to join our team. The IT Risk Analyst helps manage the Firm’s GRC and IT risk programs, focusing on information security for client data, attorney work, and privileged communications. Reporting to the IT Enterprise Risk Management Manager, the role maintains policies, assesses risks and controls, coordinates third-party reviews, drafts responses for client guidelines, prepares evidence for cyber insurance, and supports audits. Responsibilities align with ISO/IEC 27001/27002, NIST CSF, CIS Controls, SOC 2, HIPAA, GLBA, GDPR, and state privacy laws (e.g., CCPA/CPRA). Key Responsibilities and Essential Job Functions: Policy, Standards and Governance Support the development, review, and maintenance of information security and technology risk policies, standards, procedures, and guidance documents. Maintain the policy lifecycle process, including stakeholder reviews, approvals, publication, periodic review schedules, and version control. Map policies/standards to ISO, NIST, CIS Controls, SOC 2, HIPAA, GLBA, U.S. state privacy laws, and EU requirements, and to applicable client Outside Counsel Guidelines and contractual security addenda; maintain crosswalks and control documentation to support audit readiness. Administer policy exception and risk acceptance of workflows, ensuring justification, compensating controls, approvals, and defined expiration/renewal dates. Contribute to awareness materials and operational guidance to promote consistent implementation of requirements. Help maintain controls supporting ethical walls / information barriers, matter-level access restrictions, and legal hold obligations, under the direction of the Senior Analyst and in partnership with the Office of the General Counsel, Conflicts, and Records & Information Governance. Maintain awareness of the Firm’s professional responsibility obligations, including ABA Model Rules 1.1 (technology competence) and 1.6 (confidentiality of information), and apply that awareness to policy implementation and control activities. Information Security and Technology Risk Management Conduct or facilitate risk assessments for applications, infrastructure, cloud services, Firm-critical legal-industry platforms (document management,
Full responsibilities and requirements are on Holland & Knight's application page.
Apply for this job →Location and market context
This job is based in Miami, FL on a hybrid schedule. Local candidates benefit from being close to Holland & Knight's teams and regional hiring market, while the hybrid arrangement offers some flexibility. Confirm the exact in-office expectation and any relocation support with the employer.
About risk management jobs
Risk jobs own the methodology for identifying, assessing, and escalating enterprise, operational, and technology risk. Second-line teams set risk appetite and challenge the first line. Jobs like this one are typically evaluated against frameworks such as enterprise and operational risk frameworks, NIST AI RMF, and risk-appetite and escalation practices.
How to position yourself for this risk management job
Strong candidates emphasize risk assessment methodology, appetite and escalation, cross-functional partnership, and clear reporting to senior leadership and the board. In your resume and outreach, tie your experience to how Holland & Knight would apply enterprise and operational risk frameworks, NIST AI RMF, and risk-appetite and escalation practices, and lead with concrete outcomes rather than duties.
Similar GRC jobs
More GRC jobs: All GRC jobs · Search by category & location