Enter a job title or keyword

Information Security Risk Analyst


Job Location:

Chicago, IL - USA

Yearly Salary: $ 105000 - 110000
Posted: 22 September 2026 (3 hours ago)
Application Deadline: 20 December 2026
Vacancies: 1 Vacancy

Job Summary

Job Title: Information Security Risk Analyst
Primary Location: Remote
Position Type: Direct Hire

Overview
TalentFish is casting a line for an Information Security Risk Analyst. This is a Direct Hire role that can sit remotely. This position exists to play a critical role within the Governance Risk and Compliance (GRC) team executing and enhancing the organizations information security risk management program. The analyst will independently conduct risk analysis on information systems platforms and processes in accordance with established regulatory requirements organizational policies and industry standards leading and contributing to the identification assessment documentation mitigation and communication of information security risks across the organization.

What You Bring to the Role. (Ideal Experience)

  • Bachelors degree required in Information Security Computer Science Engineering Information Technology or a related field; masters degree preferred.

  • 3 years of experience in cybersecurity information security risk management or audit; healthcare industry experience strongly preferred.

  • Demonstrated experience with risk assessment methodologies auditing information security practices and familiarity with risk management platforms and risk registers.

  • Strong understanding of regulatory compliance and industry best practices for maintaining compliance with HIPAA NIST and other relevant healthcare regulations and standards.

  • One or more of the following certifications required or must be obtained within 12 months of hire: CRISC CISM CISA or any other applicable certification.

  • Ability to lead and structure risk assessments with limited supervision and manage multiple concurrent assessments and projects in a fast-paced healthcare setting.

  • Experience preparing both detailed technical risk reports and executive-level summaries tailored to varied audiences.

  • Strong written verbal and interpersonal communication skills with the ability to translate technical findings into business-relevant language for leadership audiences.

  • Experience tracking audit findings third-party vendor risks and remediation efforts and analyzing contractual security language to identify risk exposure.

What Youll Do. (Skills Used in this Position)

  • Lead and conduct comprehensive information security risk analysis for IT assets applications processes medical devices and third-party vendors.

  • Evaluate threats and vulnerabilities affecting the confidentiality integrity and availability of ePHI and other confidential or sensitive information ensuring alignment with HIPAA Security Rule requirements and other applicable regulatory frameworks (e.g. NIST).

  • Lead and manage risk management initiatives based on analysis of outcomes including maintaining the organizations risk register and scoring methodology.

  • Oversee corrective action plans (CAPs) penetration testing results audit findings and risk treatment outcomes.

  • Collaborate with IT partners and key stakeholders to prioritize implement and track remediation efforts.

  • Monitor regulatory changes and industry threats to proactively identify emerging risks recommend mitigation strategies and document findings.

  • Contribute to risk reporting including executive dashboards and participate in risk acceptance processes and governance reviews.

  • Contribute to the development review and improvement of cybersecurity policies standards and procedures and evaluate policy exceptions for governance committees.

  • Enhance the organizations cybersecurity awareness and training efforts by communicating risk insights to technical and non-technical audiences.

Compensation Information
The expected salary range for this position is $105000-$110000 per year depending on experience and qualifications. This role also qualifies for comprehensive benefits such as health insurance 401(k) and paid time off. TalentFish is committed to pay transparency and equal opportunity. The salary range provided is in compliance with applicable state and federal regulations.
This role requires authorization to work in the U.S. without current or future visa sponsorship.
All offers are contingent upon the completion of a background check which may include but is not limited to reference checks education verification employment verification drug testing criminal records checks and any required certifications or compliance requirements based on the end clients background check policies and applicable laws.
TalentFish is an employee-owned company pioneering a new realm in talent acquisition. We are redefining IT staffing by evolving AI video screening and our unique platform. TalentFish focuses on providing the best employee consultant and client experience possible.
At TalentFish we are an Equal Opportunity Employer; we embrace and encourage diversity!