| Title | Risk Analyst |
|---|---|
| Department | Enterprise Risk Management / Risk & Compliance |
| Reports to | [Risk Manager / Director of Risk / Chief Risk Officer] |
| Location | [Remote / Hybrid / On-site] |
| Employment type | Full-time |
| Salary | [Salary range. Postings with a range perform significantly better, and several states require one.] |
Position overview
The Risk Analyst supports [Company]'s risk management program by identifying and assessing risks, maintaining the risk register, monitoring key risk indicators, and preparing reporting for leadership. The role turns data and analysis into a clear view of the organization's risk profile.
The Risk Analyst works with business, technology, security, and finance teams to evaluate operational, technology, third-party, and emerging risks, and to track mitigation. As AI and automated systems become part of operations, the analyst helps assess and monitor the risks they introduce.
This role suits an analytical early to mid-career professional who is comfortable with data, frameworks, and translating findings into practical recommendations.
Key responsibilities
Risk identification and assessment
- Identify and assess operational, technology, third-party, and emerging risks.
- Evaluate likelihood, impact, and existing controls.
- Recommend risk treatment and mitigation options.
- Support scoping of new and periodic assessments.
Risk register and monitoring
Maintain a clear, current view of the organization's risks:
- Keep the risk register accurate and up to date.
- Track key risk indicators and thresholds.
- Monitor mitigation actions and escalate overdue items.
- Flag changes in the risk profile as conditions shift.
Analysis and reporting
- Analyze risk data and identify trends and concentrations.
- Prepare risk reports, heat maps, and dashboards.
- Support scenario analysis and risk quantification.
- Present findings clearly to risk owners and leadership.
Control and framework support
Support the risk framework by mapping risks to controls, referencing standards such as ISO 31000, COSO ERM, and the NIST AI RMF, and helping keep methodology consistent.
Third-party and emerging risk
Assess third-party and vendor risk, and evaluate emerging risks including those from AI, automated decision systems, and new technology entering the environment.
Program support
Support risk committees, maintain risk documentation and methodology, and help embed risk awareness across business and technology teams.
Required qualifications
- Bachelor's degree in Finance, Business, Economics, Data Science, Information Systems, or a related field, or equivalent experience.
- 2 to 4+ years of experience in risk, audit, analytics, or a related function.
- Working knowledge of risk frameworks such as ISO 31000 or COSO ERM.
- Experience with risk assessments, risk registers, and reporting.
- Strong analytical, quantitative, and communication skills.
- Comfort working with data and translating it into clear findings.
Preferred certifications
One or more of: FRM, PRM, CRISC, CRM, CISA, depending on the risk domain.
Technical knowledge
Enterprise and operational risk analysis, risk assessment, risk registers, key risk indicators, risk quantification and scenario analysis, third-party risk, risk reporting and dashboards, GRC platforms, and awareness of AI and automated-system risk.
About [Company]
[Two or three sentences about your organization, the maturity of your program, and what the first year looks like. Candidates in this field respond to honesty about whether they are joining a build or an established function.]
Post this role on GRC Careers
Reach professionals who specialize in enterprise and operational risk analysis rather than hoping they find you in a general feed. Hand reviewed, live within one business day.
See how others are hiring
Review live GRC jobs postings to benchmark scope, level, and posted salary before you publish yours.
Stay close to the market
Job alerts
Get new GRC jobs roles sent to you as they post.
Newsletter
Hiring trends, salary signals, and new templates from GRC Careers.
Frequently asked questions
What does a Risk Analyst do?
A Risk Analyst identifies, assesses, and monitors the risks facing an organization. They maintain the risk register, track key risk indicators, analyze risk data, and prepare reporting and dashboards for risk owners and leadership.
What qualifications and certifications does a Risk Analyst need?
Most Risk Analysts have a bachelor's degree or equivalent experience and 2 to 4 or more years in risk, audit, or analytics. Common certifications include FRM, PRM, CRISC, and CRM, depending on the risk domain.
Who does a Risk Analyst report to?
A Risk Analyst usually reports to a Risk Manager, a Director of Risk, or, in smaller organizations, directly to the Chief Risk Officer or head of enterprise risk.
What frameworks does a Risk Analyst use?
Common reference frameworks include ISO 31000 and COSO Enterprise Risk Management, alongside the NIST Cybersecurity Framework and the NIST AI Risk Management Framework for technology and AI-related risk.