Skip to main content
AlphaSense

Senior Risk Analyst

RemoteIndia only
Published
Role
Security
Experience
Senior
Company size
Enterprise
Salary not disclosed
Check eligibility

Open to IN only. Set where you work from to check your eligibility.

No BS summary

Senior GRC/risk analyst with 6+ years in information security, risk management, GRC, or IT audit, including 4+ years building or maturing risk registers and scoring. Must be India-remote and strong with security/compliance frameworks, GRC platforms, cloud security tooling, AI-assisted risk workflows, audits, and executive risk reporting.

Core skills

GRCRisk managementAI risk

Required skills

SOC 2ISO 27001NIST CSF 2.0CIS ControlsISO 42001NIST AI RMFLLMsDrata/Vanta/AuditBoard/ServiceNow GRCAWS/Azure/GCPCSPMSIEMGDPRCCPACPRAAI agentsAutomationRisk registersAI-assisted risk analysis

Optional skills

CISACRISCCISMCISSPCCSKISO 27001 Lead AuditorISO 27001 Lead ImplementerEU AI Act

What you'll do

  • Design and implement a structured risk management program, including risk taxonomy, scoring methodology, risk appetite statements, and escalation thresholds.
  • Align the risk program with ISO 27005, NIST RMF, or ISO 31000 as appropriate.
  • Help define the architecture of the risk management program and continuously mature the discipline as the company scales.
  • Build and maintain the enterprise risk register as a living operational tool, not a compliance artifact.
  • Lead periodic risk identification workshops with business, engineering, and legal stakeholders to surface new and evolving risks.
  • Ensure every risk has a documented owner, risk rating, treatment decision, and remediation timeline.
  • Ensure the risk register reflects current reality rather than outdated snapshots.
  • Leverage AI tools to monitor threat intelligence, identify patterns across risk data, accelerate risk narrative drafting, and keep the risk register current between formal review cycles.
  • Build AI-assisted workflows that reduce manual risk review burden and surface emerging risks earlier.
  • Apply judgment to validate AI output before it informs a risk decision.
  • Support the TPRM function in partnership with the dedicated TPRM lead.
  • Contribute to vendor risk assessments, risk scoring, and finding documentation as needed.
  • Provide risk framework input to ensure third-party risks are consistently rated and tracked in alignment with the broader risk register.
  • Identify and assess AI-related risks including data privacy, model bias, explainability, security misuse, agentic system behavior, and third-party AI dependencies.
  • Support compliance with AI governance frameworks including ISO 42001, NIST AI RMF, and EU AI Act.
  • Maintain current knowledge of the evolving AI risk landscape.
  • Help AlphaSense stay ahead of regulatory and operational risks from AI deployment.
  • Produce clear, executive-ready risk reports, dashboards, and periodic risk summaries.
  • Translate technical risk findings into business impact language that drives informed decisions at the service owner, leadership, and board levels.
  • Make risk actionable for engineers and executives.
  • Provide cross-functional risk and control guidance on process improvements, new technology adoption, post-implementation reviews, and remediation activities.
  • Support stakeholders in interpreting risk requirements and embedding risk management practices into how they build and operate.
  • Align the program with ISO 27005, NIST RMF, or ISO 31000 as appropriate.
  • Help define the architecture and continuously mature the discipline as the company scales.
  • Ensure every risk has a documented owner, risk rating, treatment decision, and remediation timeline—and that the register reflects current reality, not last quarter's snapshot.
  • Support compliance with AI governance frameworks (ISO 42001, NIST AI RMF, EU AI Act).
  • Maintain current knowledge of the evolving AI risk landscape and help AlphaSense stay ahead of regulatory and operational risks from AI deployment.
  • Make risk actionable at every altitude—engineers understand their exposure, executives understand portfolio risk.
  • Support stakeholders in interpreting risk requirements and embedding risk management practices into how they build and operate—not as a checkpoint, but as an enabling partner.

What they require

  • 6+ years of experience in GRC, information security, risk management, or IT audit, preferably in a SaaS or cloud-native environment.
  • Strong understanding of security and compliance frameworks including SOC 2, ISO 27001, NIST CSF 2.0, and CIS Controls; working knowledge of ISO 42001 and NIST AI RMF.
  • AI-native mindset using AI tools such as LLMs, agents, and automation for substantive work including analysis, drafting, evidence gathering, and workflow automation.
  • Ability to judge where AI creates leverage and where a human must stay in the loop.
  • Proficiency with GRC platforms for evidence management and control testing such as Drata, Vanta, AuditBoard, ServiceNow GRC, or equivalent.
  • Familiarity with cloud environments such as AWS, Azure, or GCP and security and compliance posture tooling that runs on them, including CSPM, SIEM, and identity platforms.
  • Experience supporting external audits across security or privacy domains, including evidence collection, control walkthroughs, and auditor interaction.
  • Ability to interpret technical controls and translate findings into compliance, risk, and policy documentation that engineers and non-technical stakeholders both understand.
  • Working knowledge of risk registers, control libraries, and policy governance lifecycles.
  • Working knowledge of privacy and data protection requirements such as GDPR and CCPA/CPRA and how they intersect with security controls, in partnership with Legal and Product teams.
  • Strong written communication, analytical thinking, and attention to detail.
  • Able to produce clear audit responses, risk narratives, and control documentation under deadline.
  • 4+ years of hands-on experience in information security risk management or a combined GRC/risk role with responsibility for building or significantly maturing a risk register and scoring methodology.
  • Demonstrated use of AI or data tools to surface risk insights, analyze trends, draft risk narratives, or automate risk register workflows, with clear judgment about validating AI output before it informs a decision.
  • Proven experience maturing an organization's risk program from qualitative to quantitative risk measurement, including introducing scoring models, KRI frameworks, and data-driven risk reporting that changed how leadership makes risk decisions.
  • Experience with data warehousing concepts, KRI development and tracking, and risk reporting pipelines that connect live data sources to dashboards and executive reporting.
  • Proficiency with GRC platforms for risk tracking, control testing, and evidence management such as Drata, Vanta, AuditBoard, ServiceNow GRC, or equivalent.
  • Strong analytical skills including comfort with qualitative and quantitative risk scoring, heat maps, likelihood/impact matrices, and risk appetite articulation.
  • Experience producing executive-ready risk reports and translating technical findings into business impact language for non-technical audiences.
  • Experience supporting TPRM assessments and contributing to vendor risk documentation in partnership with a dedicated TPRM function.
  • Preferred: Relevant certifications such as CISA, CRISC, CISM, CISSP, CCSK, or ISO 27001 Lead Auditor/Implementer.
  • Preferred: Experience with AI governance frameworks including ISO 42001, NIST AI RMF, EU AI Act, or OECD AI Principles.
  • Preferred: Exposure to SOX ITGC cycles, including managing evidence, walkthroughs, and findings with external auditors.
  • Preferred: Privacy program crossover including data mapping, DPIAs, and GDPR/CCPA operational compliance.
  • Preferred: Quantitative risk experience including FAIR-style decomposition, Monte Carlo simulation, or loss exceedance analysis applied to real risk decisions, not just theoretical familiarity.
  • Preferred: Experience with AI risk domains including model risk, algorithmic bias, AI system failure modes, agentic system risks, and governance frameworks including NIST AI RMF or ISO 42001.
  • Preferred: Background in financial services regulatory risk environments such as SOX, FFIEC, or equivalent.
  • AI-native mindset: you use AI tools—LLMs, agents, automation—for real, substantive work including analysis, drafting, evidence gathering, and workflow automation.
  • You apply judgment about where AI creates leverage and where a human must stay in the loop.
  • Proficiency with GRC platforms for evidence management and control testing (Drata, Vanta, AuditBoard, ServiceNow GRC, or equivalent).
  • Familiarity with cloud environments (AWS, Azure, or GCP) and the security and compliance posture tooling that runs on them (CSPM, SIEM, identity platforms).
  • Working knowledge of privacy and data protection requirements (GDPR, CCPA/CPRA) and how they intersect with security controls, in partnership with Legal and Product teams.
  • Strong written communication, analytical thinking, and attention to detail; able to produce clear audit responses, risk narratives, and control documentation under deadline.
  • Demonstrated use of AI or data tools to surface risk insights, analyze trends, draft risk narratives, or automate risk register workflows—with clear judgment about validating AI output before it informs a decision.
  • Proven experience maturing an organization's risk program from qualitative to quantitative risk measurement—including introducing scoring models, KRI frameworks, and data-driven risk reporting that changed how leadership makes risk decisions.
  • Proficiency with GRC platforms for risk tracking, control testing, and evidence management (Drata, Vanta, AuditBoard, ServiceNow GRC, or equivalent).
  • Strong analytical skills: comfort with qualitative and quantitative risk scoring, heat maps, likelihood/impact matrices, and risk appetite articulation.
  • Preferred: Relevant certifications: CISA, CRISC, CISM, CISSP, CCSK, or ISO 27001 Lead Auditor/Implementer.
  • Preferred: Exposure to SOX ITGC cycles—managing evidence, walkthroughs, and findings with external auditors.
  • Preferred: Privacy program crossover: data mapping, DPIAs, GDPR/CCPA operational compliance.
  • Preferred: Scripting or automation experience applied to GRC or compliance workflows.
  • Preferred: Quantitative risk experience: FAIR-style decomposition, Monte Carlo simulation, or loss exceedance analysis applied to real risk decisions—not just theoretical familiarity.
  • Preferred: Experience with AI risk domains: model risk, algorithmic bias, AI system failure modes, agentic system risks, and governance frameworks including NIST AI RMF or ISO 42001.
  • Preferred: Familiarity with risk aggregation and BI tooling for risk dashboarding and executive reporting.
  • Preferred: Background in financial services regulatory risk environments (SOX, FFIEC, or equivalent).

AlphaSense delivers AI-driven market intelligence and search built on public and private content including equity research, company filings, event transcripts, expert calls, news, trade journals, and clients’ own research content.

🇺🇸 United StatesTechnologyEnterprisealphasense.net/
Salary not disclosed