×
Register Here to Apply for Jobs or Post Jobs. X

Senior Governance & Risk Analyst

Job in Chicago, Cook County, Illinois, 60290, USA
Listing for: Zs Associates
Full Time position
Listed on 2026-01-23
Job specializations:
  • IT/Tech
    Cybersecurity, IT Business Analyst, Information Security, Data Security
Salary/Wage Range or Industry Benchmark: 150000 - 200000 USD Yearly USD 150000.00 200000.00 YEAR
Job Description & How to Apply Below

ZS is a place where passion changes lives. As a management consulting and technology firm focused on improving life and how we live it, we transform ideas into impact by bringing together data, science, technology and human ingenuity to deliver better outcomes for all. Here you’ll work side‑by‑side with a powerful collective of thinkers and experts shaping life‑changing solutions for patients, caregivers and consumers worldwide.

ZSers drive impact by bringing a client‑first mentality to each and every engagement. We partner collaboratively with our clients to develop custom solutions and technology products that create value and deliver company results across critical areas of their business. Bring your curiosity for learning, bold ideas, courage and passion to drive life‑changing impact to ZS.

Senior Governance & Risk Analyst

ZS IT Support teams are aligned with the company’s business strategy and operating model and aim to provide its 4,000+ employees and their clients the right tools and information for high performance. The IT organization focuses on providing products and services to ZS to ensure successful business outcomes. This involves providing a scalable, sustainable and reliable IT infrastructure, customized applications, messaging and collaboration products, Business Intelligence and Database administration support along with reliable 24
* 7 uninterrupted high‑quality technology support services.

What You’ll Do

We are seeking applicants for the position of Senior Analyst – Governance and Risk team to join our US IT Governance, Risk and Compliance team. The position will support various management‑directed, IT risk governance initiatives which include the following job requirements.

The primary responsibility of this role is to perform comprehensive risk assessments, including vendor due diligence, process/project security risk assessments, and maintaining the risk register. The successful candidate will possess a strong understanding of IT risk management principles and will play a crucial role in identifying, assessing, and mitigating risks to ensure the security and stability of our organizational infrastructure. It requires strong analytical skills, familiarity with security domains, and the ability to communicate risk insights clearly and effectively.

Risk

Assessments
  • Perform assessments for vendors, processes, and projects to identify security gaps and recommend controls.
  • Evaluate risks across IT systems, applications, infrastructure, and third‑party engagements.
  • Document assessment findings with clear rationale and actionable recommendations.
VRA Execution & Risk Register Management
  • Perform vendor risk assessments to evaluate third‑party security posture, document findings, and recommend mitigation strategies aligned with organizational standards.
  • Maintain and update the risk register, ensuring accurate classification, ownership mapping, and closure tracking across all active and draft risks.
  • Collaborate with internal teams (e.g., security, legal, procurement) and external stakeholders to ensure risk documentation is complete, validated, and aligned with business priorities.
  • Conduct periodic risk hygiene activities, including archival of outdated risks, evidence collection, and exception tracking.
  • Ensure all risk‑related documentation is clear, complete, and accessible for stakeholders, supporting decision‑making and compliance readiness.
Compliance & Controls
  • Apply knowledge of regulatory standards (e.g., ISO, NIST, GDPR) to assess and document compliance.
  • Support the implementation of security policies and control frameworks across business functions.
  • Monitor control effectiveness and suggest improvements where needed.
Reporting & Communication
  • Prepare risk reports with summaries of findings, impact analysis, and mitigation plans.
  • Share updates on risk trends, exceptions, and closure progress on a regular cadence.
  • Communicate technical risk concepts in a clear, accessible format for non‑technical audiences.
What You’ll Bring
  • Bachelor’s degree in Computer Science, Information Systems, or a related field (master’s degree is a plus).
  • Minimum of 4‑6 years’ experience in IT risk management, IT…
Position Requirements
10+ Years work experience
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)

Job Posting Language
Employment Category
Education (minimum level)
Filters
Education Level
Experience Level (years)
Posted in last:
Salary