Senior Risk Analyst

XeroxPublished 20 hours agoFirst seen 3 hours ago

The salary range above represents the low and high end in the local currency of Xerox’s salary range for this position and is reflected in an annualized amount. Actual salaries will vary based on factors including, but not limited to, geographic location, market competition, and/or the successful applicant’s education, experience, knowledge, skills, and abilities. The range listed is just one component of Xerox’s total compensation package for employees. Employees are also afforded a comprehensive suite of benefits, to view those details please visit Xerox Careers for your applicable country. If you are not reviewing this job posting on Xerox Careers, we cannot guarantee the validity of this posting. For a list of our current internal postings, please visit Xerox Careers.

About Xerox Holdings Corporation
For more than 100 years, Xerox has continually redefined the workplace experience. Harnessing our leadership position in office and production print technology, we’ve expanded into software and services to sustainably power the hybrid workplace of today and tomorrow. Today, Xerox is continuing its legacy of innovation to deliver client-centric and digitally-driven technology solutions and meet the needs of today’s global, distributed workforce. From the office to industrial environments, our differentiated business and technology offerings and financial services are essential workplace technology solutions that drive success for our clients. At Xerox, we make work, work. Learn more about us at www.xerox.com.

Location: Remote - United States, Eastern or Central Time Zone
Schedule: Full-Time, Days
Compensation: $146,000-$195,000 based on experience

Overview

Xerox is seeking a Sr. Risk Analyst to support and lead key cybersecurity risk initiatives within our Governance, Risk, and Compliance organization. This role will help assess, monitor, and report on cybersecurity and third-party risk using industry-standard frameworks, including the CIS Critical Security Controls and the NIST Cybersecurity Framework.

The Sr. Risk Analyst will play a key role in Xerox’s Third-Party Risk Management program, CMMC and FedRAMP compliance initiatives, security policy exception process, risk register management, and executive-level risk reporting. This position is ideal for an experienced risk, audit, or compliance professional who is ready to take ownership of complex programs, mentor others, and help mature enterprise cybersecurity risk practices.

What You’ll Do

  • Lead and support cybersecurity risk assessments using frameworks such as CIS Critical Security Controls and the NIST Cybersecurity Framework.
  • Support and mature Xerox’s Third-Party Risk Management program, including vendor security questionnaires, third-party risk assessments, ongoing monitoring, and escalation of high-risk findings.
  • Review vendor-submitted evidence, including SOC 2 reports, security questionnaires, certifications, and due diligence materials.
  • Support CMMC compliance efforts, including control documentation, System Security Plan development, readiness assessments, and leadership reporting.
  • Advise on FedRAMP authorization and continuous monitoring activities for applicable cloud services.
  • Manage the security policy exception process, including intake, risk scoring, compensating control review, and leadership approval preparation.
  • Provide direction, guidance, and quality review for risk analysts and related GRC workstreams.
  • Partner with Security Governance, Security Architecture, Global Sourcing, Internal Audit, and business leaders on risk-related matters.
  • Maintain the security risk register, ensuring risks are documented, prioritized, tracked, and driven toward closure.
  • Develop dashboards, metrics, and reports that translate technical risk findings into clear business risk narratives.
  • Support internal and external audits, including ISO 27001, SOC 2, and customer security assessments.
  • Track changes in cybersecurity regulations, frameworks, and compliance requirements, including NIST, CMMC, and FedRAMP updates.
  • Help establish and maintain risk assessment methodologies, templates, standards, and scalable processes.
  • Support GRC tooling and identify opportunities to improve efficiency, consistency, and program coverage.

Who You Are

  • Bachelor’s degree in Cybersecurity, Information Systems, Computer Science, or a related field; equivalent practical experience will also be considered.
  • 5+ years of experience in information security, IT risk management, audit, compliance, or a related field.
  • Experience leading, mentoring, or providing guidance to analysts or project teams.
  • Strong working knowledge of CIS Critical Security Controls and the NIST Cybersecurity Framework.
  • Experience with third-party/vendor risk management programs, including questionnaires, due diligence, and ongoing monitoring.
  • Working knowledge of CMMC requirements and NIST SP 800-171.
  • Working knowledge of FedRAMP requirements and authorization processes, including SSPs, SARs, and POA&Ms.
  • Experience with security policy exception processes, risk-based decision-making, and compensating controls.
  • Strong communication and presentation skills, with the ability to explain technical risk findings to senior leadership and business stakeholders.

Preferred Qualifications

  • Relevant certification such as CISSP, CRISC, CRMA, CISA, CCSK, or a CMMC-related credential.
  • Direct experience supporting or leading a CMMC or FedRAMP assessment or authorization effort.
  • Experience with SOC 2, ISO 27001, or similar audit frameworks.
  • Experience with GRC or risk management tools such as ServiceNow GRC, OneTrust, or similar platforms.

#LI-AW1

#LI-REMOTE