
AlphaSense is maturing its security risk management program and needs a Senior Risk Analyst to be a core builder and operator of that function. You will design, implement, and mature a risk framework that spans information security, AI, and operational risk—building toward a program that is quantitative-leaning, connected to live data sources, and actionable at every altitude from service owner to executive leadership. You will establish risk identification and scoring methodologies, own the enterprise risk register, and produce risk intelligence that drives real decisions. You will also support the TPRM function led by a dedicated TPRM lead, contributing to assessments and risk tracking as needed. You approach this with an AI-native mindset: using AI to monitor threat landscapes, analyze risk data, draft risk narratives, and surface emerging risks faster than a traditional manual program could. Key Responsibilities Risk Program Design & Maturation: Design and implement a structured risk management program, including risk taxonomy, scoring methodology, risk appetite statements, and escalation thresholds. Align the program with ISO 27005, NIST RMF, or ISO 31000 as appropriate. Risk Register Ownership: Build and maintain the enterprise risk register as a living operational tool. Lead periodic risk identification workshops with business, engineering, and legal stakeholders. AI-Augmented Risk Analysis: Leverage AI tools to monitor threat intelligence, identify patterns across risk data, accelerate risk narrative drafting, and keep the risk register current. Third-Party & Vendor Risk Support: Support the TPRM function in partnership with the dedicated TPRM lead. Contribute to vendor risk assessments and risk scoring. AI & Emerging Technology Risk: Identify and assess AI-related risks including data privacy, model bias, explainability, security misuse, agentic system behavior, and third-party AI dependencies. Support compliance with AI governance frameworks (ISO 42001, NIST AI RMF, EU AI Act). Risk Reporting & Executive Communication: Produce clear, executive-ready risk reports, dashboards, and periodic risk summaries. Cross-Functional Risk Advisory: Provide cross-functional risk and control guidance on process improvements, new technology adoption, and remediation activities. Who You Are Basic Requirements - 6+ years of experience in GRC, information security, risk management, or IT audit, preferably in a SaaS or cloud-native environment - Strong understanding of security and compliance frameworks including SOC 2, ISO 27001, NIST CSF 2.0, and CIS Controls; working knowledge of ISO 42001 and NIST AI RMF - AI-native mindset: you use AI tools—LLMs, agents, automation—for real, substantive work - Proficiency with GRC platforms (Drata, Vanta, AuditBoard, ServiceNow GRC, or equivalent) - Familiarity with cloud environments (AWS, Azure, or GCP) - Experience supporting external audits across security or privacy domains - Working knowledge of privacy and data protection requirements (GDPR, CCPA/CPRA) - 4+ years of hands-on experience in information security risk management or a combined GRC/risk role with responsibility for building or significantly maturing a risk register and scoring methodology - Proven experience maturing an organization's risk program from qualitative to quantitative risk measurement - Experience with data warehousing concepts, KRI development and tracking Nice to Have - Relevant certifications: CISA, CRISC, CISM, CISSP, CCSK, or ISO 27001 Lead Auditor/Implementer - Experience with AI governance frameworks including ISO 42001, NIST AI RMF, EU AI Act, or OECD AI Principles - Exposure to SOX ITGC cycles - Privacy program crossover: data mapping, DPIAs, GDPR/CCPA operational compliance - Scripting or automation experience (Python, JavaScript, or low-code tools) - Quantitative risk experience: FAIR-style decomposition, Monte Carlo simulation, or loss exceedance analysis - Familiarity with risk aggregation and BI tooling (Tableau, Looker, Power BI) - Background in financial services regulatory risk environments (SOX, FFIEC, or equivalent).
Job Details
Responsibilities
- Design and implement a structured risk management program including taxonomy and scoring
- Align program with ISO 27005, NIST RMF, or ISO 31000
- Build and maintain the enterprise risk register as a living operational tool
- Lead risk identification workshops with business, engineering, and legal stakeholders
- Use AI tools to monitor threat intelligence and automate risk narratives
- Support the TPRM function with vendor risk assessments and scoring
- Identify and assess AI-related risks (privacy, bias, agentic behavior)
- Ensure compliance with AI governance frameworks like ISO 42001 and EU AI Act
- Produce executive-ready risk reports and dashboards
- Provide cross-functional risk and control guidance for new technology adoption
Requirements
- 6+ years of experience in GRC, information security, risk management, or IT audit
- Experience in SaaS or cloud-native environment
- Strong understanding of SOC 2, ISO 27001, NIST CSF 2.0, and CIS Controls
- Working knowledge of ISO 42001 and NIST AI RMF
- AI-native mindset using LLMs and automation for substantive work
- Proficiency with GRC platforms like Drata, Vanta, AuditBoard, or ServiceNow GRC
- Familiarity with AWS, Azure, or GCP
- Experience supporting external audits in security or privacy domains
- Working knowledge of GDPR and CCPA/CPRA
- 4+ years of hands-on experience building or maturing a risk register and scoring methodology
- Experience moving risk programs from qualitative to quantitative measurement
- Experience with data warehousing concepts and KRI development
Skills & Technologies

Related Opportunities
Discover more opportunities that match your interests and skills