702,534open jobs
41,709companies
98,601added this week
Browse all
Salary
$146k – $195k per year
Location
Remote/Hybrid (United States)
Seniority
Senior · 5+ years exp
Overview
Company
Impact
Profile match
Headquartered in Norwalk, Connecticut, Xerox is a global workplace technology company that pioneered modern office printing and digital document systems. The company offers a comprehensive portfolio of hardware, software, and services, ranging from advanced multifunction printers to automated workflow management solutions. By integrating innovative document management and digital transformation tools, it helps businesses worldwide streamline operations and enhance productivity.

About Xerox Holdings Corporation

For more than 100 years, Xerox has continually redefined the workplace experience. Harnessing our leadership position in office and production print technology, we’ve expanded into software and services to sustainably power the hybrid workplace of today and tomorrow. Today, Xerox is continuing its legacy of innovation to deliver client-centric and digitally-driven technology solutions and meet the needs of today’s global, distributed workforce. From the office to industrial environments, our differentiated business and technology offerings and financial services are essential workplace technology solutions that drive success for our clients. At Xerox, we make work, work. Learn more about us at www.xerox.com.

Location: Remote - United States, Eastern or Central Time Zone

Schedule: Full-Time, Days

Compensation: $146,000-$195,000 based on experience

Overview

Xerox is seeking a Sr. Risk Analyst to support and lead key cybersecurity risk initiatives within our Governance, Risk, and Compliance organization. This role will help assess, monitor, and report on cybersecurity and third-party risk using industry-standard frameworks, including the CIS Critical Security Controls and the NIST Cybersecurity Framework.

The Sr. Risk Analyst will play a key role in Xerox’s Third-Party Risk Management program, CMMC and FedRAMP compliance initiatives, security policy exception process, risk register management, and executive-level risk reporting. This position is ideal for an experienced risk, audit, or compliance professional who is ready to take ownership of complex programs, mentor others, and help mature enterprise cybersecurity risk practices.

What You’ll Do

  • Lead and support cybersecurity risk assessments using frameworks such as CIS Critical Security Controls and the NIST Cybersecurity Framework.
  • Support and mature Xerox’s Third-Party Risk Management program, including vendor security questionnaires, third-party risk assessments, ongoing monitoring, and escalation of high-risk findings.
  • Review vendor-submitted evidence, including SOC 2 reports, security questionnaires, certifications, and due diligence materials.
  • Support CMMC compliance efforts, including control documentation, System Security Plan development, readiness assessments, and leadership reporting.
  • Advise on FedRAMP authorization and continuous monitoring activities for applicable cloud services.
  • Manage the security policy exception process, including intake, risk scoring, compensating control review, and leadership approval preparation.
  • Provide direction, guidance, and quality review for risk analysts and related GRC workstreams.
  • Partner with Security Governance, Security Architecture, Global Sourcing, Internal Audit, and business leaders on risk-related matters.
  • Maintain the security risk register, ensuring risks are documented, prioritized, tracked, and driven toward closure.
  • Develop dashboards, metrics, and reports that translate technical risk findings into clear business risk narratives.
  • Support internal and external audits, including ISO 27001, SOC 2, and customer security assessments.
  • Track changes in cybersecurity regulations, frameworks, and compliance requirements, including NIST, CMMC, and FedRAMP updates.
  • Help establish and maintain risk assessment methodologies, templates, standards, and scalable processes.
  • Support GRC tooling and identify opportunities to improve efficiency, consistency, and program coverage.

Who You Are

  • Bachelor’s degree in Cybersecurity, Information Systems, Computer Science, or a related field; equivalent practical experience will also be considered.
  • 5+ years of experience in information security, IT risk management, audit, compliance, or a related field.
  • Experience leading, mentoring, or providing guidance to analysts or project teams.
  • Strong working knowledge of CIS Critical Security Controls and the NIST Cybersecurity Framework.
  • Experience with third-party/vendor risk management programs, including questionnaires, due diligence, and ongoing monitoring.
  • Working knowledge of CMMC requirements and NIST SP 800-171.
  • Working knowledge of FedRAMP requirements and authorization processes, including SSPs, SARs, and POA&Ms.
  • Experience with security policy exception processes, risk-based decision-making, and compensating controls.
  • Strong communication and presentation skills, with the ability to explain technical risk findings to senior leadership and business stakeholders.

Preferred Qualifications

  • Relevant certification such as CISSP, CRISC, CRMA, CISA, CCSK, or a CMMC-related credential.
  • Direct experience supporting or leading a CMMC or FedRAMP assessment or authorization effort.
  • Experience with SOC 2, ISO 27001, or similar audit frameworks.
  • Experience with GRC or risk management tools such as ServiceNow GRC, OneTrust, or similar platforms.
Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
702,534 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account Continue with Google
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
In your city
$37k – $89k per year (Estimated) • In office • Full-Time • Bengaluru
Python
PowerShell
Bash
DevOps
GCP
Azure
AWS
IAM
Linux
Windows
TCP/IP
DNS
DHCP
VPN
Wi-Fi
Cybersecurity
Okta
ISO 27001
SOC 2
Microsoft Entra ID
Active Directory
Management
Google Workspace
Apply
$33k – $86k per year (Estimated) • In office • 8+ years exp • Bengaluru
DevOps
Incident Management
VPN
Cybersecurity
ISO 27001
SOC 2
Zero Trust
Least Privilege
Active Directory
SIEM
DLP
Apply
$100k – $113k per year • Remote • 7+ years exp • Bachelor's Degree
Python
DevOps
Terraform
IAM
Cybersecurity
ISO 27001
CIS Benchmarks
PCI DSS
SOC 2
HIPAA
Zero Trust
SIEM
Apply
$100k – $170k per year • Remote • 12+ years exp • Bachelor's Degree
Python
DevOps
Terraform
IAM
Cybersecurity
ISO 27001
CIS Benchmarks
PCI DSS
SOC 2
HIPAA
Zero Trust
SIEM
Apply
$95k – $125k per year • Remote • 6+ years exp • Bachelor's Degree
Python
PowerShell
DevOps
Terraform
Azure DevOps
GitHub Actions
Istio
Linkerd
Azure
CI/CD
Kubernetes
Service Mesh
Bicep
Azure AKS
FinOps
Cybersecurity
PCI DSS
SOC 2
HIPAA
FedRAMP
Apply
Specialist Bid Writer 2 hours ago
Remote/Hybrid • 5+ years exp • Bachelor's Degree
Apply
Remote/Hybrid
Management
Outlook
Microsoft Office
Apply
Remote/Hybrid
Management
Outlook
Microsoft Office
Apply
Payroll Analyst 2 hours ago
Remote/Hybrid • 2+ years exp • Bachelor's Degree
Analytics
Microsoft Excel
Management
Microsoft Office
Apply
Remote/Hybrid • 2+ years exp • Bachelor's Degree
Python
JavaScript
SQL
Databases
Databricks
Oracle
Microsoft Fabric
Analytics
Power BI
ETL/ELT
SAP BusinessObjects
Microsoft Excel
Management
Power Automate
ITIL
Apply
See all jobs
This is one of many
702,534 more open roles from verified company boards, updated every day.