Holland Knight

Holland Knight

IT Enterprise Risk Analyst

Operations Center - Tampa

Sponsorship not specified$53k-$800kDetected 31 days ago
AzureCybersecurityIncident ResponseComplianceAuditingProcurementHIPAALeadershipCommunicationOrganizational SkillsMicrosoft OfficeInternal AuditUnderwriting

About the role

  • This position is based in the Firm's global operations center in Tampa, FL.
  • align with ISO/IEC 27001/27002, NIST CSF, CIS Controls, SOC 2, HIPAA, GLBA, GDPR, and state privacy laws (e.g., CCPA/CPRA).
  • Applicants who are interested in applying for a position and require an accommodation during the process should contact ApplicantAccommodations@hklaw.com.

Responsibilities

  • The IT Risk Analyst helps manage the Firm's GRC and IT risk programs, focusing on information security for client data, attorney work, and privileged communications.
  • Reporting to the IT Enterprise Risk Management Manager, the role maintains policies, assesses risks and controls, coordinates third-party reviews, drafts responses for client guidelines, prepares evidence for cyber insurance, and supports audits.
  • Support the development, review, and maintenance of information security and technology risk policies, standards, procedures, and guidance documents.
  • Maintain the policy lifecycle process, including stakeholder reviews, approvals, publication, periodic review schedules, and version control.
  • Map policies/standards to ISO, NIST, CIS Controls, SOC 2, HIPAA, GLBA, U.S. state privacy laws, and EU requirements, and to applicable client Outside Counsel Guidelines and contractual security addenda; maintain crosswalks and control documentation to support audit readiness.
  • Help maintain controls supporting ethical walls / information barriers, matter-level access restrictions, and legal hold obligations, under the direction of the Senior Analyst and in partnership with the Office of the General Counsel, Conflicts, and Records & Information Governance.
  • Maintain awareness of the Firm's professional responsibility obligations, including ABA Model Rules 1.1 (technology competence) and 1.6 (confidentiality of information), and apply that awareness to policy implementation and control activities.
  • Conduct or facilitate risk assessments for applications, infrastructure, cloud services, Firm-critical legal-industry platforms (document management, time and billing, conflicts and new business intake, eDiscovery, and matter management), and key business processes; document risk statements, likelihood/impact, and control effectiveness.
  • Maintain and update the risk register, including inherent and residual ratings, treatment plans, owners, milestones, and status updates.
  • Partner with control owners to identify remediation actions, track progress, and validate closure with appropriate evidence.

Requirements

  • Ability to sit or stand for extended periods of time.
  • ability to translate control requirements into clear documentation and actionable guidance.

Nice to have

  • Prior exposure to GRC, IT risk, or information security work in a law firm, professional services firm, or other client-confidential environment is preferred.
  • time and billing such as 3E or Aderant
  • conflicts and new business intake such as Intapp
  • eDiscovery platforms such as Relativity) and with the data-sensitivity considerations they raise is a plus.
  • Familiarity with Controlled Unclassified Information (CUI) handling, NIST SP 800-171, CMMC, and ITAR/EAR data-handling concepts
  • prior exposure to federal, defense, or government-contracts client matters is a plus.
  • Awareness of the ABA Model Rules of Professional Conduct (in particular Rules 1.1 and 1.6) and applicable state bar requirements relating to technology competence and client confidentiality is preferred.
  • Familiarity with EU information security and privacy requirements (e.g., GDPR security principles)

Skills

  • Strong written and verbal communication skills; ability to translate control requirements into clear documentation and actionable guidance.
  • Strong organizational skills and attention to detail.
  • Ability to manage multiple priorities and deadlines.
  • Knowledge or ability to learn Microsoft Office Suite, or Microsoft 365.
  • Required Qualifications & Education:
  • Bachelor's degree in information security, Information Technology, Risk Management, Business, or equivalent practical experience.
  • 3+ years of experience in GRC, information security, technology risk management, compliance, internal audit, or third-party risk management.
  • Working knowledge of ISO/IEC 27000 Family concepts, NIST CSF/SP 800-53/800-171, and HIPAA.
  • Experience collecting, organizing, and validating control evidence and supporting audits/assessments.
  • Certifications - ISACA: CRISC (Certified in Risk and Information Systems Control) and/or CISA (Certified Information Systems Auditor).
  • Preferred Qualifications & Education:
  • Certifications -

Compensation

  • Help compile control attestations and evidence packages for the Firm's annual cyber insurance application and renewal cycle, supporting responses to underwriter and broker inquiries under senior oversight.

Benefits

  • Below are the benefits we offer: comprehensive medical (PPO and HDHPs), dental and vision plans including coverage for domestic partners
  • short and long term disability insurance
  • tax-advantaged accounts for health care expenses, including FSAs and HSAs
  • health advocacy services
  • behavioral health and counseling resources for all family members
  • profit sharing
  • and paid holidays and other paid time off, including paid leave for new parents.

Company info

  • We are a Firm where people truly believe in what they do and strive to achieve the highest standards of performance and success.
  • We are seeking an IT Enterprise Risk Analyst to join our team.

This listing is sourced directly from Holland Knight's careers page and normalized into a canonical job model.