AlixPartners

Information Security GRC – Risk & Compliance Senior Analyst (Contract)

AlixPartners  •  Detroit, MI (Remote)  •  5 hours ago
Apply
AI can make mistakes so check important info. Chat history is never stored.

Job Description

At AlixPartners, we solve the most complex and critical challenges by moving quickly from analysis to action when it really matters; creating value that has a lasting impact on companies, their people, and the communities they serve. By understanding, respecting, and honoring the needs of our employees, clients, and communities, AlixPartners actively promotes an inclusive environment. We strongly believe in the value that diversity brings to our experiences and are committed to the perpetual enhancements of initiatives, policies, and practices. We hold ourselves accountable by providing space for authenticity, growth, and equity for everyone.

Location: Southfield, MI (contract/hybrid)

Assignment duration: through December 2026 with potential to extend

MUST BE CURRENTLY AUTHORIZED TO WORK IN THE UNITED STATES. NO VISA OR IMMIGRATION SPONSORSHIP FOR THIS ROLE, NOW OR IN THE FUTURE. (e.g., H-1B, STEM OPT, TN, etc.)

About the Role

As a member of the Information Security team, the IS GRC Senior Analyst - Risk & Compliance will be responsible for understanding the firm’s security risk and compliance requirements. You will manage and maintain the risk register, analyze risk, and process risk assessments via the risk assessment platform. The IS GRC – Risk & Compliance will help set up and monitor control testing to support audit activities. This role will consult and interface with IT leadership, IT staff, and non-IT departments to conduct risk analysis and monitor controls.

The Information Security Governance, Risk & Compliance Senior Analyst (Risk & Compliance) is a full-time, contract position located in Southfield, MI reporting to the Information Security Governance, Risk, & Compliance Manager. Paid relocation and benefits are not available for this position.

What you’ll do

Security Risk Management:

  • Support the CISO in the completion of the annual risk assessment required to support client and compliance audits, as well as periodic risk assessments as determined
  • Manage the review and analysis of risk register ensuring accuracy, completeness, and timely updates
  • Conduct risk assessments including evaluation of risk and control effectiveness
  • Track remediation actions to closure with assigned control owners, maintain due dates, escalate overdue items, and report status to leadership
  • Interview subject matter experts and gather information for conducting risk assessments
  • Collaborate with cross-functional teams to develop risk mitigation strategies
  • Conduct security assessments of third-party suppliers, including review of security questionnaires, supporting documentation, and independent audit reports
  • Identify third-party supplier gaps, risk ratings, and required mitigations

Control Framework and Testing:

  • Design, execute, and monitor control tests to assess compliance with contractual, regulatory, and internal requirements
  • Partner with control owners across IT and business functions; ensure roles and responsibilities are clearly communicated and understood
  • Prepare audit request materials and upload documentation for internal or external auditors
  • Measure and report metrics to IS GRC Risk & Compliance Manager, IS GRC Director and CISO
  • Improve security efficiency, streamline, and automate work processes while working collaboratively with other team members and IT staff to accomplish objectives
  • Additional responsibilities as identified. This description is not designed to encompass a comprehensive listing of required activities, duties, or responsibilities.

What You’ll Bring

  • Bachelor’s degree in Information Technology or related field preferred; relevant work experience may be considered in lieu of education
  • Minimum 3 years of professional work experience
  • Experience within Information Security, Risk, Compliance, Audit, or Information Technology is required
  • Experience with ISO 27001, SOC 2, PCI, HIPAA, or other global standards or regulations is highly preferred
  • Certified Information Systems Security Professional (CISSP) and/or Certified Information Systems Auditor (CISA) desired, but not required
  • Willingness to increase knowledge and credibility through obtaining training and/or certifications (CISSP, CISA, CRISC, etc.)
  • Attention to detail with the ability to manage and prioritize responsibilities effectively, adapt to changing circumstances to meet key deadlines under time constraints so work is completed in an accurate, timely manner
  • Excellent written and oral communication skills in English
  • Highly effective inter-personal and collaboration skills to support security programs and interface with people at all levels
  • Excellent problem-solving ability and ability to resolve issues under tight time frames
  • Experience using MS Office Suite (Word, Excel, PowerPoint, SharePoint etc.)
  • Experience using ServiceNow preferred
  • Highly organized with excellent organizational skills with experience operating in time-sensitive, ambiguous environments, balancing competing priorities with sound judgment and discretion.
  • Core working hours are generally 8:30 AM – 5:30 PM, Monday - Friday; willingness to work outside of normal U.S. business hours, and as unique projects/needs arise
  • Ability to work full time in an office and remote environment; physically able to sit/stand at a computer and work in front of a computer screen for significant portions of the workday
  • Must become familiar with, and promote and abide by, our Core Values as defined by the AlixPartners’ Code of Conduct and foster an inclusive environment with people at all levels of an organization

AlixPartners has embraced a hybrid work model to provide flexibility and support our employees’ work-life integration. Our hybrid model combines a mix of in-person at an AlixPartners office on Tuesday, Wednesday, and Thursday, with remote working options on Monday and Friday.

AlixPartners is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to, among other things, race, color, religion, sex, sexual orientation, gender identity, national origin, age, status as a protected veteran, or disability. AlixPartners is a proud Gold Level award-winning Veteran Friendly Employer.

#LI-KL2

#LI-Hybrid

AlixPartners

About AlixPartners

For more than forty years, AlixPartners has helped businesses around the world respond quickly and decisively to their most critical challenges – circumstances as diverse as urgent performance improvement, accelerated transformation, complex restructuring and risk mitigation.

These are the moments when everything is on the line – a sudden shift in the market, an unexpected performance decline, a time-sensitive deal, a fork-in-the-road decision. But it’s not what we do that makes a difference, it’s how we do it.

Tackling situations when time is of the essence is part of our DNA – so we adopt an action-oriented approach at all times. We work in small, highly qualified teams with specific industry and functional expertise, and we operate at pace, moving quickly from analysis to implementation. We stand shoulder to shoulder with our clients until the job is done, and only measure our success in terms of the results we deliver.

Our approach enables us to help our clients confront and overcome truly future-defining challenges. We partner with you to make the right decisions and take the right actions. And we are right by your side. When it really matters.

Recent Awards & Recognition:

- Best Firm to Work For – Consulting Magazine, 2023

- Best Places to Work For LGBTQ+ Equality – Human Rights Campaign, 2022

- Best Management Consulting Firms – Forbes, 2021

- Ranked in the Top 10 in UHLALA Group’s Pride Index

Industry
Consulting & Advisory
Company Size
1,001-5,000 employees
Headquarters
New York, NY
Year Founded
Unknown
Social Media