Security Risk Senior Analyst (Transparency Posting)
Indexed description
Together, we innovate for a stronger Colorado
The work of employees at the Governor's Office of Information Technology (OIT) is challenging and diverse because the needs of agencies, customers and Coloradans constantly evolve. But our focus never changes: improve the lives of all Coloradans through innovation and collaboration. We're building one of the nation's leading government IT organizations by reimagining how we support agencies, building first-of-their-kind applications, and creating an inclusive, collaborative culture, together. Join us in the important work of providing equitable access to services.
Watch this video to learn more about how we're Serving People. Serving Colorado.
Description of Job
IMPORTANT NOTE: Please review your application to ensure completion. For the most equitable applicant experience, OIT’s hiring team considers only the contents of your application to review your qualifications. Please do not include any attachments (such as resume or cover letter) with your application as these items are not used by OIT’s hiring team.
Transparency Posting: This position is intended for and will be filled with an existing resource. This posting is for notification purposes only under the Equal Pay for Equal Work Act.
Senior Risk Analyst is a pivotal role responsible for identifying, assessing, and managing cybersecurity risks across state systems, data assets, and third-party relationships. In this role, you will lead the development and maintenance of our risk management program, ensuring alignment with the NIST Cybersecurity Framework (CSF) and regulatory requirements (e.g., CJIS, HIPAA).
The ideal candidate will conduct risk assessments, evaluate security controls, track remediation efforts, and translate technical findings into actionable guidance for leadership. This position offers a unique opportunity to collaborate across departments, ensuring risk-informed decision-making and protecting critical constituent data and public services.
Essential Functions
- Risk management strategy & governance: Establish and maintain the organization's cybersecurity risk management strategy, risk appetite, and tolerance thresholds in line with NIST CSF Govern (GV) outcomes. Outcome: an approved risk appetite statement that guides prioritization decisions across the security program.
- Roles, policy & oversight: Define risk-related roles, responsibilities, and reporting lines; maintain policies governing risk assessment cadence and escalation. Outcome: documented governance structure that passes audit scrutiny and clarifies accountability.
- Asset & risk assessment: Using current inventory of critical assets, conduct regular risk assessments mapped to CSF Identify (ID) categories (Asset Management, Risk Assessment, Improvement). Outcome: a rationalized and living risk register with likelihood/impact scoring covering all critical assets.
- Third-party & supply chain risk: Maintain a documented program and processes to assess vendor and partner cybersecurity posture as part of ID.SC (Supply Chain Risk Management). Outcome: documented due diligence and reduced third-party exposure, evidenced in vendor risk files.
- Control evaluation & gap analysis: Evaluate existing safeguards against CSF Protect (PR) categories (Identity Management, Data Security, Platform Security) to identify control gaps. Outcome: prioritized remediation roadmap tied to residual risk reduction.
- Threat & risk trend monitoring: Analyze threat intelligence and detection findings (CSF Detect/DE) to refine and recalibrate the risk model. Outcome: a risk register that reflects current threat activity, not static assumptions.
- Incident risk analysis & remediation tracking: Partner with incident response teams to assess risk impact of incidents (CSF Respond/RS) and track remediation of resulting findings to closure. Outcome: closed-loop remediation with measurable mean-time-to-remediate metrics.
- Recovery planning risk input: Contribute risk analysis to recovery planning and business continuity efforts (CSF Recover/RC), ensuring recovery priorities reflect actual risk exposure. Outcome: recovery plans that are risk-informed and tested.
- Executive & stakeholder reporting: Translate risk findings across all six CSF functions into business-relevant reporting for agencies, executives, and stakeholders (legal, compliance). Outcome: informed resourcing decisions and improved organization-wide risk literacy.
- Program maturity metrics: Define and track KPIs/KRIs mapped to CSF function maturity (e.g., % of assets assessed, control coverage, remediation velocity). Outcome: quantifiable, framework-aligned evidence of year-over-year program maturity.
- Additional Functions:
- Self-Direction & Autonomy
- Operates independently with minimal supervision; exercises sound judgment in ambiguous or evolving situations
- Prioritizes and manages a complex workload across competing deadlines without day-to-day direction
- Recognizes when to escalate versus when to resolve independently
- Continuous Improvement Ownership
- Proactively identifies gaps or inefficiencies in the risk program and drives improvements without being asked
- Stays current on evolving threats, regulatory changes, and framework updates (e.g., NIST CSF revisions) and incorporates them into practice
- Seeks feedback on their own work product and iterates on risk methodologies, templates, and reporting over time
- Mentorship & Influence
- Mentors other analysts and stakeholders
- Influences stakeholders and leadership without formal authority — builds credibility through sound analysis rather than positional power
- Acts as a subject-matter resource other teams turn to for risk-related questions
- Accountability & Ownership
- Takes ownership of outcomes, not just tasks — follows through on remediation and reporting until issues are genuinely resolved
- Willing to make and stand behind risk recommendations, including ones that are unpopular or involve trade-offs
- Documents decisions and rationale clearly enough to withstand audit or leadership scrutiny
- Judgment Under Ambiguity
- Comfortable making risk-based recommendations with incomplete information
- Balances competing priorities (security, budget, mission delivery, public accountability) rather than defaulting to a single lens
- Communication & Composure
- Communicates effectively under pressure, including during incidents or audit findings
- Adapts communication style for technical staff, program managers, and non-technical executives or elected oversight bodies
- Professional Development
- Maintains and pursues relevant certifications (CISSP, CRISC, CISM) as a mark of ongoing self-investment
- Participates in professional risk/security communities to bring outside perspective back into the agency
Minimum Qualifications
This is a skills-based job announcement. The required minimum qualifications and/or education (if substituting for the proven experience, knowledge, and skills), are as follows:
- Minimum of five (5) years of experience managing cybersecurity risks across state systems, data assets, and third-party relationships.
- Experience with the NIST Cybersecurity Framework (CSF) and applicable state and federal regulatory requirements (e.g., state IT security policies, CJIS, HIPAA, IRS Publication 1075, as applicable).
- Additional appropriate education will substitute for the required experience on a year-for-year basis, but cannot completely substitute for these qualifications.
- Training or Certification related to the work assigned to the position will be assigned credit towards substitution for experience and/or education, but cannot completely substitute for these qualifications.
- If the minimum qualifications include a degree requirement, additional appropriate paid or unpaid experience will substitute for the required education on a year-for-year basis.
- Professional security certification.
A pre-employment background check will be conducted as part of the selection process. Post-employment background checks will be required for specific agencies as business needs dictate, which may include a polygraph exam, fingerprint-based criminal history search, reference checks, and a drug test.
This position may require travel within the specified geographic area, and to locations across the state as needed.
This position may require on-call duties as needed by the position.
Supplemental Information
If this posting indicates “remote from anywhere in CO” in the title, periodic reporting to the primary state work location designated for the position is required. All remote work must be performed in Colorado.
While candidates from out of state will be considered for this role, the candidate selected for the position must relocate and reside in Colorado on the first day of their new position. A reasonable timeframe for relocation will be established on an individual basis, while considering business needs, and determining a start date.
We know it's important to support each other, and that means having a healthy balance of work and personal time. Visit our benefits to learn more about some of our great offerings that allow us all to have fulfilling lives.
Visit our How to Apply webpage to learn more about our application process and what to expect after you apply.
The State of Colorado strives to create a Colorado for All by building and maintaining workplaces that value and respect all Coloradans through a commitment to equal opportunity and hiring based on merit and fitness. The State is resolute in non-discriminatory practices in everything we do, including hiring, employment, and advancement opportunities.
The Governor's Office of Information Technology is committed to the full inclusion of all qualified individuals. As part of this commitment, our agency will assist individuals who have a disability with any reasonable accommodation requests related to employment, including completing the application process, interviewing, completing any pre-employment testing, participating in the employee selection process, and/or to perform essential job functions where the requested accommodation does not impose an undue hardship. If you have a disability and require reasonable accommodation to ensure you have a positive experience applying or interviewing for this position, please direct your inquiries to our ADA Coordinator at [email protected] or call (303) 764-7900.
This posting may be used to fill multiple vacancies based upon business need.
The Governor's Office of Information Technology does NOT offer sponsored Visas for employment purposes.
Please note that each agency's contact information is different; therefore, we encourage all applicants to view the full, official job announcement which includes contact information and class title. Select the job you wish to view, then click on the "Print" icon.
01
Please detail how your skills and experience align with the requirements of this position.
02
Please describe how you learned of this job opening.
03
The Governor's Office of Information Technology (OIT) complies with Colorado's Equal Pay for Equal Work Act. While a wide salary range is posted, specific criteria (experience, education, state seniority, etc.) will be used to determine any salary offer. While most salary offers are made within the posted range, occasionally an offer is made below or above the posted range based upon this salary analysis. It is this salary analysis, rather than any negotiation process, that determines any salary offer. Please acknowledge your understanding of this process and the posted salary range for this position.
- Yes, I understand the above statement.
All remote work must be performed from within the State of Colorado. If you live out of state and are selected for this position you must relocate to Colorado before commencing employment. There is no form of relocation assistance, financial or otherwise, available for any position. Do you wish to proceed with your submission?
- Yes, I understand the above statement.
Do you currently reside in the state of Colorado?
- Yes
- No
If any of the State of Colorado positions listed in your employment history were performed as a contract employee, you MUST list the position/s, State Agency, and the name of the contracting company by whom you were paid during the contract position. If this does not apply, please type "N/A".
07
Do you currently require employer sponsorship for a Visa, employer-provided documentation to maintain your Visa, or employer participation in a program for the purposes of immigration status?
- Yes
- No
In the future, will you require employer sponsorship for a Visa, employer-provided documentation to maintain your Visa, or employer participation in a program for the purposes of immigration status?
- Yes
- No
- Required Question
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search