Risk, Compliance & Auditing Analyst
City of Boston
Risk, Compliance & Auditing Analyst
- Req ID
- 2024-28155
- Dept
- Dpt of Innovation & Technology
- Position
- Regular Full-Time
- Location
- ASD-Mgmt Information Systems
- Salary Min
- 63,517.01
- Salary Max
- 95,115.57
- Union
- SE1
- Openings
- 1
- Posting End Date
- 3/11/2025
- Contact Email
- estelle.tshitenge@boston.gov
Overview:
The City of Boston Department of Innovation and Technology (DoIT) Cyber Security Team is actively growing and seeking to hire a Risk, Compliance & Auditing Analyst. This role will further implement and enhance our current cybersecurity governance model(s). This role will be instrumental in enhancing the City of Boston risk, compliance, and auditing capabilities. This position plays a central role in actively promoting a culture of exceptional cybersecurity practices throughout the City of Boston. This role will report directly to the Director of Risk, Compliance, & Auditing and work closely with the broader Cybersecurity Team, DoIT, and other departments and technology teams throughout the City.
Responsibilities:
a) Enterprise Risk Management:
- Support the implementation and use of enterprise risk management tools to assist in analyzing, reporting & managing enterprise risks.
- Assist in conducting risk assessments to identify and evaluate potential cybersecurity threats and vulnerabilities.
- Help maintain and update the risk register, providing data and insights for key stakeholders.
- Contribute to the third-party vendor/supplier risk program by gathering data and recommending risk mitigation techniques.
b) Compliance Oversight:
- Assist in ensuring adherence to relevant laws, regulations, and industry cybersecurity standards (e.g., NIST Cybersecurity Framework, PCI-DSS, CJIS, FERPA, HIPAA, etc.).
- Participate in regular compliance assessments to identify gaps and support the implementation of corrective measures.
- Support the City’s vulnerability management program by tracking remediation efforts and following up on outstanding issues.
c) Internal & External Auditing:
- Assist in the execution of the City’s internal technical audit program.
- Provide support during information security external audits and regulatory reviews by gathering and organizing necessary documentation.
- Help audit the effectiveness of IT-related internal processes, controls, risk management, and governance activities.
d) Data Analysis and Reporting:
- Collect and analyze data to support the identification of trends and areas for improvement.
- Prepare basic reports and presentations for senior management under the guidance of the Director.
- Utilize data analytics tools to support risk, compliance, and audit processes.
Performs other related work as required.
Minimum Entrance Qualifications:
- Three (3) years of full-time, or equivalent part-time, experience in Information Security, Risk Management, or business-related fields. A Bachelor's degree in a related field may be substituted for two (2) years of the required experience. A Master's degree can be substituted for three (3) years of the required experience.
- Previous hands-on technical experience is desirable.
- Excellent analytical, problem-solving, and decision-making skills.
- Knowledge of information security & risk management frameworks (e.g., NIST, ISO, etc.).
- Some experience assisting with the management of an enterprise risk management program, compliance, and auditing activities, is desirable.
- Proficiency in data analysis and audit software tools.
- Strong communication and interpersonal skills.
- Ability to manage multiple tasks and meet deadlines.
- Ability to leverage best practices and lessons learned from external organizations and academic institutions dealing with cyber issues.
- Ability to exercise good judgment and focus on detail as required by the job.
BOSTON RESIDENCY REQUIRED
Terms:
Union/Salary Plan/Grade: SENA/ MM1-06
Hours per week: 35
Options:
The City of Boston is proud to be an Equal Opportunity Employer. We are committed to creating a diverse and inclusive environment. Therefore, qualified applicants will be considered regardless of their sex, race, age, religion, color, national origin, ancestry, physical or mental disability, genetic information, marital status, sexual orientation, gender identity, gender expression, military and veteran status, or other protected category.
The City of Boston has played a role in causing and perpetuating the inequities in our society. To break down these barriers, we are embedding equity and inclusion into everything we do.
We define equity as ensuring every community has the resources it needs to thrive in Boston. This requires the active process of meeting individuals where they are. Inclusion is engaging every resident to build a more welcoming and supportive city. We are building a city for everyone, where diversity makes us a more empowered collective.