Skip to content
AGJ, the AI governance job board
Menu

Job description template

Risk Analyst

The Risk Analyst identifies, measures, and monitors the risks that could affect the organization, and turns that analysis into clear reporting for decision makers. This template reflects how the role is scoped at organizations building or maturing a risk function, including risks introduced by AI and automated systems. Replace the [highlighted fields] with your specifics, trim what does not apply, and post.

Download PDF Download reference sheet

TitleRisk Analyst
DepartmentEnterprise Risk Management / Risk & Compliance
Reports to[Risk Manager / Director of Risk / Chief Risk Officer]
Location[Remote / Hybrid / On-site]
Employment typeFull-time
Salary[Salary range. Postings with a range perform significantly better, and several states require one.]

Position overview

The Risk Analyst supports [Company]'s risk management program by identifying and assessing risks, maintaining the risk register, monitoring key risk indicators, and preparing reporting for leadership. The role turns data and analysis into a clear view of the organization's risk profile.

The Risk Analyst works with business, technology, security, and finance teams to evaluate operational, technology, third-party, and emerging risks, and to track mitigation. As AI and automated systems become part of operations, the analyst helps assess and monitor the risks they introduce.

This role suits an analytical early to mid-career professional who is comfortable with data, frameworks, and translating findings into practical recommendations.

Key responsibilities

Risk identification and assessment

Risk register and monitoring

Maintain a clear, current view of the organization's risks:

Analysis and reporting

Control and framework support

Support the risk framework by mapping risks to controls, referencing standards such as ISO 31000, COSO ERM, and the NIST AI RMF, and helping keep methodology consistent.

Third-party and emerging risk

Assess third-party and vendor risk, and evaluate emerging risks including those from AI, automated decision systems, and new technology entering the environment.

Program support

Support risk committees, maintain risk documentation and methodology, and help embed risk awareness across business and technology teams.

Required qualifications

Preferred certifications

One or more of: FRM, PRM, CRISC, CRM, CISA, depending on the risk domain.

Technical knowledge

Enterprise and operational risk analysis, risk assessment, risk registers, key risk indicators, risk quantification and scenario analysis, third-party risk, risk reporting and dashboards, GRC platforms, and awareness of AI and automated-system risk.

About [Company]

[Two or three sentences about your organization, the maturity of your program, and what the first year looks like. Candidates in this field respond to honesty about whether they are joining a build or an established function.]

Post this role on GRC Careers

Reach professionals who specialize in enterprise and operational risk analysis rather than hoping they find you in a general feed. Hand reviewed, live within one business day.

Post this role

See how others are hiring

Review live GRC jobs postings to benchmark scope, level, and posted salary before you publish yours.

Browse GRC jobs

Stay close to the market

Frequently asked questions

What does a Risk Analyst do?

A Risk Analyst identifies, assesses, and monitors the risks facing an organization. They maintain the risk register, track key risk indicators, analyze risk data, and prepare reporting and dashboards for risk owners and leadership.

What qualifications and certifications does a Risk Analyst need?

Most Risk Analysts have a bachelor's degree or equivalent experience and 2 to 4 or more years in risk, audit, or analytics. Common certifications include FRM, PRM, CRISC, and CRM, depending on the risk domain.

Who does a Risk Analyst report to?

A Risk Analyst usually reports to a Risk Manager, a Director of Risk, or, in smaller organizations, directly to the Chief Risk Officer or head of enterprise risk.

What frameworks does a Risk Analyst use?

Common reference frameworks include ISO 31000 and COSO Enterprise Risk Management, alongside the NIST Cybersecurity Framework and the NIST AI Risk Management Framework for technology and AI-related risk.