PitchMeAI
Strategic Education, Inc

Principal IT Risk Management Analyst

Strategic Education, Inc · United States

  • Hybrid
  • Full-time
  • $178,900 / year
  • United States
Tailored resumekeyword-matched to this role.
Hiring managerwe find who's hiring.
Intro emaildrafted to reach them directly.

Job highlights

  • Lead IT risk management strategy and execution.
  • Assess technology risks and compliance gaps.
  • Develop and implement risk mitigation plans.
  • Collaborate across departments for unified risk approach.
  • Mentor junior risk management team members.

About the role

Principal IT Risk Management Analyst

At Strategic Education Inc., our mission is to enable economic mobility through education. Through a portfolio of institutions and learning solutions, we focus on serving working adult learners by improving college affordability, enhancing student engagement, and strengthening workforce readiness so our graduates are equipped with the skills needed to succeed in today’s jobs. This mission guides how we operate as an organization, including our approach to enterprise technology and risk management.

The Principal IT Risk Management Analyst is a senior-level role responsible for leading and overseeing comprehensive IT risk management efforts across the organization. This position provides strategic guidance on identifying and assessing complex technology risks and on the development and implementation of effective risk management strategies. The Principal IT Risk Management Analyst partners closely with cross‑functional stakeholders to promote the security, compliance, and resilience of the organization’s IT systems, infrastructure, and processes.

Strategic Leadership

  • Provide thought leadership and strategic direction in IT risk management, aligning efforts with the organization's goals and risk tolerance.
  • Collaborate with executive leadership to define risk management strategies and objectives.

Risk Assessment And Analysis

  • Identify and assess high-impact IT risks, including emerging cybersecurity threats, regulatory compliance gaps, and operational vulnerabilities.
  • Analyze complex risk scenarios, evaluating potential business impacts and likelihoods.

Risk Mitigation Strategy

  • Develop and execute comprehensive risk mitigation strategies, ensuring the effective implementation of controls, processes, and frameworks.
  • Lead the design of risk management initiatives that align with industry best practices and standards.

Cross-Functional Collaboration

  • Work closely with IT, cybersecurity, legal, compliance, and business units to integrate risk management principles into day-to-day operations.
  • Facilitate communication and collaboration among teams to ensure a unified approach to risk management.

Regulatory Compliance

  • Monitor and interpret relevant IT regulations, standards, and frameworks (e.g., GDPR, FERPA, NIST, ISO 27001, CIS 8) to ensure compliance.
  • Advise on risk management strategies that address compliance requirements.

Risk Reporting And Communication

  • Prepare and deliver clear and concise risk reports for executive management and relevant stakeholders.
  • Communicate complex technical concepts and risk scenarios in a manner understandable by non-technical audiences.

Incident Response And Recovery

  • Provide leadership during IT security incidents, guiding incident response teams to minimize impact and ensure effective recovery.
  • Review and enhance incident response plans to reflect lessons learned and emerging threats.

Continuous Improvement

  • Identify opportunities to enhance risk assessment methodologies, tools, and processes based on evolving threats and industry trends.
  • Drive continuous improvement initiatives across the risk management function.

Mentorship And Development

  • Provide mentorship and guidance to junior members of the risk management team, fostering professional growth and skill development.

Job Skills

  • Proven leadership skills with the ability to guide cross-functional teams and provide strategic direction.
  • Strong analytical and problem-solving capabilities to assess complex risk scenarios and recommend effective mitigation strategies.
  • Ability to write and manage policies.
  • Excellent communication and presentation skills to convey technical information to various stakeholders.
  • Familiarity with security technologies, security frameworks, tools, and industry best practices.
  • Project management skills to drive risk management initiatives and improvements.
  • Ability to adapt to evolving technologies and risks in the IT landscape.

Work Experience

  • 5+ years of experience in a Senior Analyst role or Similar
  • 5+ yrs of experience in IT risk management, with a strong understanding of risk assessment methodologies, frameworks, and regulatory requirements.
  • 5+ yrs experience with Third Party Risk Management.
  • 3+ yrs experience with Artificial Intelligence, Cloud Platforms, and DevSecOps.
  • 3+ with incident response, crisis management, and business continuity planning.

Education

Bachelor's degree in Information Technology, Cybersecurity, IT Risk Management, Business, or a related field (Master's preferred).

Certificates, Licenses And Registrations

Professional certifications such as Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), or Certified Information Systems Auditor (CISA) or Project Management Professional are required.

Key skills/competency

  • IT Risk Management
  • Cybersecurity
  • Regulatory Compliance
  • Risk Assessment
  • Incident Response
  • Third Party Risk Management
  • Information Security
  • NIST
  • ISO 27001
  • CISSP

Skills & topics

  • IT Risk Management
  • Cybersecurity
  • Risk Assessment
  • Compliance
  • Information Security
  • NIST
  • ISO 27001
  • CISSP
  • CISM
  • CISA
  • PMP
  • Third Party Risk Management
  • Incident Response
  • Business Continuity
  • Cloud Security
  • DevSecOps
  • AI Risk
  • Strategic Leadership
  • Policy Management

How to get hired

  • Tailor your resume: Highlight 5+ years in IT risk management, policy writing, and familiarity with NIST, ISO 27001, and CIS 8.
  • Showcase expertise: Emphasize experience with AI, Cloud, DevSecOps, and incident response in your application.
  • Certifications are key: Ensure your resume lists CISSP, CISM, CISA, or PMP for strong consideration.
  • Prepare for interviews: Be ready to discuss strategic leadership, complex risk scenarios, and cross-functional collaboration.
  • Align with mission: Understand and articulate how your risk management approach supports SEI's mission.

Technical preparation

Master NIST, ISO 27001, CIS 8 frameworks.,Gain experience with AI, Cloud, DevSecOps.,Develop incident response and BCP skills.,Practice risk assessment methodologies.

Behavioral questions

Describe a complex risk scenario you managed.,How do you ensure cross-functional collaboration?,How do you provide strategic risk leadership?,How do you communicate technical risks to non-technical audiences?

Frequently asked questions

What are the key certifications required for the Principal IT Risk Management Analyst role at Strategic Education, Inc.?
For the Principal IT Risk Management Analyst position at Strategic Education, Inc., professional certifications such as Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), Certified Information Systems Auditor (CISA), or Project Management Professional (PMP) are required. These demonstrate a strong foundation in information security and risk management.
What specific IT regulations and frameworks are important for this role at Strategic Education, Inc.?
The Principal IT Risk Management Analyst role at Strategic Education, Inc. requires familiarity with various IT regulations, standards, and frameworks. These include, but are not limited to, GDPR, FERPA, NIST, ISO 27001, and CIS 8, to ensure comprehensive compliance.
How does Strategic Education, Inc. approach risk management in its IT operations?
Strategic Education, Inc. integrates comprehensive IT risk management into its operations to ensure the security, compliance, and resilience of its IT systems. The Principal IT Risk Management Analyst plays a key role in providing strategic guidance, identifying risks, and developing mitigation strategies aligned with organizational goals and risk tolerance.
What is the expected salary range for a Principal IT Risk Management Analyst at Strategic Education, Inc.?
The expected salary range for this position at Strategic Education, Inc. is $119,300.00 to $178,900.00 annually. The actual base pay will depend on factors like job-related knowledge, skills, experience, business needs, and geographical location.
Does Strategic Education, Inc. offer remote work for the Principal IT Risk Management Analyst position?
The job description mentions that work onsite in a Corporate or Campus location may be required, but also states that if offsite or hybrid, candidates must have a suitable remote work setting. It's best to clarify the specific work arrangement for this Principal IT Risk Management Analyst role during the application process.
What kind of experience is required for the Principal IT Risk Management Analyst role?
The Principal IT Risk Management Analyst role requires at least 5 years of experience in IT risk management, including a strong understanding of risk assessment methodologies and frameworks. Additionally, experience with Third Party Risk Management, Artificial Intelligence, Cloud Platforms, DevSecOps, incident response, crisis management, and business continuity planning is highly valued.