College Board logo

College Board

Security Risk Analyst

🇺🇸 Remote - US 🕑 Full-Time 💰 $72K - $120K 💻 Information Technology 🗓️ July 28th, 2026
CISM CISSP COBIT

Edtech.com's Summary

College Board is hiring a Security Risk Analyst. The role involves managing the organization's Risk and Control Issues Register and evaluating exceptions to IT security policies. The analyst will communicate risks, collaborate with stakeholders to mitigate them, support vendor risk management, and develop risk and policy exception reports.

Highlights
  • Manage the Risk Register, including oversight of issues, escalation of audit actions, and data quality maintenance.
  • Analyze and manage exceptions to IT security policies, prepare risk assessment reports, and present findings to leadership.
  • Support Vendor Risk Management by performing risk assessments and serving as backup to the Senior Risk Analyst.
  • Provide weekly and monthly reporting, produce trending metrics, and escalate policy exceptions as needed.
  • Requires 5-7 years of experience in IT security risk management, including managing risk registers and policy exceptions.
  • Strong understanding of risk management techniques and ability to independently assess risk and recommend actions.
  • Proficient communication and negotiation skills to engage with multiple stakeholders effectively.
  • Experience with governance, risk, and compliance tools (e.g., OneTrust) and familiarity with security frameworks like ISO 27001, NIST, GDPR preferred.
  • Bachelor’s degree in computer science, cybersecurity, engineering, IT management, or equivalent experience; information security certification preferred or to be obtained within 6 months of hire.
  • Salary range $72,000–$120,000, with adjustments based on location, experience, and market data.

Security Risk Analyst Full Description

Job Description 
External Posting Role Title - Security Risk Analyst 
College Board - Risk Management 
Location:  
This is a remote role. Candidates who live near CB offices have the option of being fully remote or hybrid (Tuesday and Wednesday in office). All CB employees are required to occasionally travel to meet in person for business purposes. 
Role Type:  
This is a full-time position 
 
About the Team  
The Information Security Governance Risk and Compliance (ISGRC) team at the College Board works closely with other teams across the organization to assess and certify the security of College Board's information systems and processes. This dedicated team facilitates information security governance and compliance by assessing College Board's vendors, reviewing and negotiating contractual commitments to information security, planning for disaster response and recovery, testing system strength using industry-recognized frameworks (ISO 27001, PCI-DSS and SOC2) and obtaining related compliance certifications, implementing information security policies, promoting security awareness and training, and testing the acumen of College Board employees through robust and innovative training and phishing campaigns.  
  
About the Opportunity   
As a Security Risk Analyst, you will have the critical role of being responsible for evaluating and managing exceptions to IT security policies, for managing the Organization's Risk and Control Issues Register (Risk Register), and for developing reports and metrics.  
Your strong technical communication and negotiation skills will help you build relationships and collaborate with diverse stakeholders and reduce risk to the organization and ensure compliance.  

Under the direction of management, you will manage the Risk Register and perform security policy exceptions to help the College Board understand its critical risks.  

In this role you will:  
Manage the Risk Register (20%)  
  • Leads the management of the issues and risks and quickly escalates any untimely completion of audit actions.  
  • Works independently to communicate risks and works with others to problem-solve risks to tolerance levels based on data and evidence.  
  • Maintains data quality of Risk Register and executes any required data clean-up exercises.  
  • Understands College Board work to be able to drive Risk or Control Owners to ensure consistent application of policies and standards. 
  • Raises awareness about Risk & Control Issues, Policy exceptions, and available risk reduction options.  
  • Fosters a culture of risk awareness and compliance within the technology department and across the organization.  
 
Manage Policy Exceptions (65%)  
  • Independently analyzes policy exception submissions and provides risk assessment reports for critical service lines, applications, and infrastructure hosted on-prem and in the cloud.  
  • Evaluates and manage exceptions to IT security policies.  
  • Manages materials for the Exception Review Board and presents exception information to executive leadership and senior team members.  
  • Maintains an up-to-date knowledge and understanding of IT security policies and principles.  
  • Maintains a customer-focused attitude in all interactions with customers and colleagues.  
 
Support Vendor Risk Management (10%) 
  • Support the Vendor Risk Management program by understanding policies and procedures. 
  • Perform New Vendor Risk Assessments and Reassessments. 
  • Serve as backup to the Sr. Risk Analyst.  
 
Manage Metrics and Reporting (5%)  
  • Provides weekly and monthly reporting for the Risk Register and policy exceptions.  
  • Produces trending metrics and escalate exceptions.  
  • Performs other duties as assigned.  
 
About You  
To qualify for this role you must have 
  • 5-7 years of experience managing or supporting IT Security Risk and Control Risk Register and processing policy exceptions.  
  • Strong understanding of risk management techniques such as risk identification, risk scoring, risk mitigation, and risk tracking.  
  • Proven ability to lead conversations balancing risk and multiple business needs that result in positive outcomes with multiple stakeholders.  
  • The capacity to assess risk information and make risk recommendations independently.  
  • Strong organization and prioritization skills and the proven ability to manage multiple tasks simultaneously, both independently and as a member of the team.  
  • Excellent verbal and written communication skills.  
  • Experience with governance, risk, and compliance tools (e.g., OneTrust) preferred.  
  • Experience with information security and privacy frameworks such as ISO 27001, COBIT, NIST-CSF, NIST 800-53, GDPR etc.  
  • Current Information Security Certification (e.g., CISSP, CRISC, CISM, CISA, or related security certification) preferred or the ability to attain one within 6 months of hire.  
  • Bachelor's degree in computer science, cybersecurity, engineering, IT management or four years equivalent IT and security industry experience.  
  • Vendor Risk Management policies and procedures. 
  • Bachelor's degree required.  
  • The ability to travel 2-4 times a year to College Board offices or on behalf of College Board business. 
 
All roles at College Board require: 
  • A passion for expanding educational and career opportunities and mission-driven work 
  • Curiosity and enthusiasm for emerging technologies, with a willingness to experiment with and adopt new AI-driven solutions and comfort with learning and applying new digital tools independently and proactively.  
  • Clear and concise communication skills, written and verbal 
  • A learner's mindset and a commitment to growth: welcoming diverse perspectives, giving and receiving timely, respectful feedback, and continuously improving through iterative learning and user input. 
  • A drive for impact and excellence: solving complex problems, making data-informed decisions, prioritizing what matters most, and continuously improving through learning, user input, and external benchmarking. 
  • A collaborative and empathetic approach: working across differences, fostering trust, and contributing to a culture of shared success 
  • Authorization to work in the United States 
 
About Our Process   
  • Application review will begin immediately and will continue until the position is filled. This role is expected to accept applications for a minimum of 5 business days. 
  • While the hiring process may vary, it generally includes: resume and application submission, recruiter phone/video screen, hiring manager interview, performance exercise such as live coding, a panel interview, a conversation with leadership and reference checks.    
 
What We Offer 
At College Board, we offer more than a paycheck- we provide a meaningful career, a supportive team, and a comprehensive package designed to help you thrive. We're a self-sustaining nonprofit that believes in fair and competitive compensation grounded in your qualifications, experience, impact, and the market. 
 
A Thoughtful Approach to Compensation 
  • The hiring range for this role is $72,000-$120,000. 
  • Your exact salary will depend on your location, experience, and how your background compares to others in similar roles at the College Board. 
  • We aim to make our best offer upfront, rooted in fairness, transparency, and market data. 
  • We adjust salaries by location to ensure fairness, no matter where you live. 
You'll have open, transparent conversations about compensation, benefits, and what it's like to work at College Board throughout your hiring process. Check out our careers page for more. 
#LI- MD1 
#LI- remote