Governance Risk and Compliance Risk Register Analyst

Governance Risk and Compliance Risk Register Analyst

Posted Today by Unique System Skills LLC

Negotiable
Undetermined
Remote
Remote

Summary: This role focuses on establishing and operationalizing governance and compliance workflows specifically for cybersecurity and technology risk management. The contractor will be responsible for designing an audit-ready enterprise risk register framework and implementing processes for risk management across various stakeholders. Key deliverables include a risk scoring model, governance workflows, and comprehensive documentation to ensure sustainability beyond the contract term.

Key Responsibilities:

  • Define end-to-end governance workflows for risk identification/intake, review/validation, acceptance/mitigation/transfer, and ongoing monitoring/reassessment.
  • Establish roles and responsibilities for risk owners, reviewers, and governance bodies.
  • Design escalation and reporting processes for high-risk items and accepted risks.
  • Facilitate stakeholder working sessions/workshops across business, technology, security, and governance to validate requirements and socialize processes.
  • Support onboarding and initial population of risks into the enterprise risk register.
  • Produce clear, audit-ready documentation, including risk register structure/data definitions, scoring methodology, and governance workflows/decision authorities.
  • Provide knowledge transfer to designated security staff to support sustainability beyond the contract term.

Key Skills:

  • Experience with Risk Register Design and Framework
  • Experience with Risk Scoring and Prioritization Model
  • Experience with Governance Processes and Workflows
  • Experience with Stakeholder and Enablement
  • Demonstrated skill with documentation and knowledge transfer

Salary (Rate): £56.00 hourly

City: undetermined

Country: undetermined

Working Arrangements: remote

IR35 Status: undetermined

Seniority Level: undetermined

Industry: Other

Detailed Description From Employer:

JOB DESCRIPTION/MINIMUM REQUIREMENTS:
ROLE SUMMARY:
This role will establish and operationalize enterprise governance and compliance workflows for cybersecurity and technology risk management. The contractor will design and document an audit-ready enterprise risk register framework, define risk scoring and prioritization methods, and implement governance processes to intake, validate, accept/mitigate/transfer, and monitor risks across stakeholders.

KEY RESPONSIBILITIES / DELIVERABLES:
Define end-to-end governance workflows for risk identification/intake, review/validation, acceptance/mitigation/transfer, and ongoing monitoring/reassessment.
Establish roles and responsibilities for risk owners, reviewers, and governance bodies.
Design escalation and reporting processes for high-risk items and accepted risks.
Facilitate stakeholder working sessions/workshops across business, technology, security, and governance to validate requirements and socialize processes.
Support onboarding and initial population of risks into the enterprise risk register.
Produce clear, audit-ready documentation, including risk register structure/data definitions, scoring methodology, and governance workflows/decision authorities.
Provide knowledge transfer to designated security staff to support sustainability beyond the contract term.

Planned deliverables include:

  1. Enterprise Risk Register Framework (standardized template and taxonomy)
  2. Risk Scoring and Prioritization Model (likelihood/impact scales; scoring and prioritization logic)
  3. Risk Governance Model (workflows for intake, review, acceptance, monitoring; roles/responsibilities matrix)
  4. Initial Population of Risk Register (documented risks reflecting current cybersecurity and technology risk posture)
  5. Final Documentation Package (consolidated guidance and operating procedures for ongoing risk management)

MINIMUM REQUIREMENTS (Candidates must meet/exceed):

Years

Required/Preferred

Skills/Experience

8

Required

Experience with Risk Register Design and Framework

8

Required

Experience with Risk Scoring and Prioritization Model

8

Required

Experience with Governance Processes and Workflows

8

Required

Experience with Stakeholder and Enablement

8

Required

Demonstrated skill with documentation and knowledge transfer