| Title | Enterprise Risk Analyst |
|---|---|
| Department | Enterprise Risk Management |
| Reports to | [Risk Manager / VP of Enterprise Risk Management / Chief Risk Officer] |
| Location | [Remote / Hybrid / On-site] |
| Employment type | Full-time |
| Salary | [Salary range. Postings with a range perform significantly better, and several states require one.] |
Position overview
The Enterprise Risk Analyst supports [Company]'s enterprise risk management program with analysis, data, and reporting. This role helps identify, assess, and monitor risks across the organization.
The analyst works with risk leaders and business units to run risk assessments, maintain the risk register, track Key Risk Indicators, and prepare reporting for leadership and risk committees.
As a key contributor to the ERM function, the Enterprise Risk Analyst helps keep the organization's view of risk accurate, timely, and useful for decision making, in line with COSO ERM and ISO 31000.
Key responsibilities
Risk assessments
Support enterprise risk assessments across the organization, including:
- Gathering inputs from business units and functions
- Documenting risks, causes, and impacts
- Rating likelihood and impact with owners
- Capturing mitigation plans and actions
Risk register
- Maintain and update the enterprise risk register.
- Ensure risk data is accurate and current.
- Track risk owners, ratings, and actions.
- Support periodic risk reviews and refreshes.
Key Risk Indicators
Help define, collect, and monitor Key Risk Indicators (KRIs), flagging threshold breaches and emerging trends to risk leadership.
Analysis and research
- Analyze risk data and identify trends.
- Research emerging risks and regulatory developments.
- Support scenario and impact analysis.
- Prepare summaries and briefing materials.
Reporting
Prepare enterprise risk reporting, dashboards, and heat maps for leadership and risk committees, ensuring clarity and accuracy.
Program support
Support the ERM program through documentation, coordination, and administration of the GRC platform and risk workflows.
Required qualifications
- Bachelor's degree in Risk Management, Finance, Business, Economics, Data Analytics, or a related discipline.
- 2 to 5 years of experience in risk, audit, compliance, analytics, or a related field.
- Strong analytical, documentation, and communication skills.
- Working knowledge of risk concepts and frameworks.
- Proficiency with spreadsheets and reporting tools.
- Experience with GRC platforms a plus.
Preferred certifications
One or more of: CRISC or FRM, or progress toward these certifications.
Technical knowledge
Enterprise risk concepts, risk assessment support, risk register maintenance, Key Risk Indicators, risk data analysis, reporting and dashboards, research, and GRC platforms, aligned to COSO ERM and ISO 31000.
About [Company]
[Two or three sentences about your organization, the maturity of your program, and what the first year looks like. Candidates in this field respond to honesty about whether they are joining a build or an established function.]
Post this role on GRC Careers
Reach professionals who specialize in enterprise risk analysis rather than hoping they find you in a general feed. Hand reviewed, live within one business day.
See how others are hiring
Review live GRC jobs postings to benchmark scope, level, and posted salary before you publish yours.
Stay close to the market
Job alerts
Get new GRC jobs roles sent to you as they post.
Newsletter
Hiring trends, salary signals, and new templates from GRC Careers.
Frequently asked questions
What does an Enterprise Risk Analyst do?
The Enterprise Risk Analyst supports the ERM program with analysis, data, and reporting. They help run risk assessments, maintain the risk register, track Key Risk Indicators, and prepare reporting for leadership and risk committees.
What qualifications and certifications does an Enterprise Risk Analyst need?
Most bring 2 to 5 years in risk, audit, compliance, or analytics, with strong analytical skills. Helpful certifications include CRISC and FRM, or demonstrated progress toward them, along with a relevant degree.
Who does an Enterprise Risk Analyst report to?
The role typically reports to a Risk Manager, the VP of Enterprise Risk Management, or the Chief Risk Officer, and works closely with business units and other functions.
What frameworks does an Enterprise Risk Analyst use?
The role works primarily from COSO ERM and ISO 31000 for enterprise risk, supported by COSO Internal Control and the NIST Cybersecurity Framework for technology-related risk.