Information Security Associate
KKR
- Location
- Dublin
- Work model
- On-Site
- Level
- Entry
- Posted
- 1h ago
Skills
About this role
COMPANY OVERVIEW
KKR is a leading global investment firm that offers alternative asset management as well as capital markets and insurance solutions. KKR aims to generate attractive investment returns by following a patient and disciplined investment approach, employing world-class people, and supporting growth in its portfolio companies and communities. KKR sponsors investment funds that invest in private equity, credit and real assets and has strategic partners that manage hedge funds. KKR’s insurance subsidiaries offer retirement, life and reinsurance products under the management of Global Atlantic Financial Group. References to KKR’s investments may include the activities of its sponsored funds and insurance subsidiaries.
POSITION SUMMARY
KKR is seeking an Information Security Risk Analyst to join the Information Security Governance, Risk, and Compliance (GRC) team. The role will help build and operate cyber and technology governance processes, identify and document risk issues, support remediation strategies, and manage cyber regulatory initiatives. The successful candidate will work across Information Security, Technology, and control functions to strengthen governance, improve risk visibility, support security assessments, and enhance cyber risk reporting.
RESPONSIBILITIES
Cyber Risk & Issue Management
• Support the identification, assessment, documentation, and management of cyber and technology risk issues and develop appropriate remediation, mitigation, and risk management strategies..
• Monitor risk issues and remediation activities, helping ensure risks are appropriately governed through their lifecycle.
• Maintain and support workflows to help ensure cyber risk and exception processes operate consistently and effectively.
Cyber Governance & Control Frameworks
• Help develop and enhance cyber and technology governance frameworks, standards, procedures, and supporting documentation.
• Support the development and maintenance of a cyber control catalog and associated control documentation.
• Support improvements to governance tooling, workflow design, and documentation.
Security & Technology Risk Assessments
• Support security risk assessments of applications, systems, technologies, and technology changes.
• Participate in application security and system design assessments to identify security risks and control requirements.
• Collaborate with technical and business stakeholders to understand system designs, identify risks, and recommend proportionate security controls.
Cyber Regulatory & Compliance Initiatives
• Support the delivery and coordination of cyber regulatory initiatives in response to new and changing regulatory requirements.
• Help assess regulatory requirements and translate them into practical governance, risk, and control activities.
• Help ensure cyber governance processes remain aligned with applicable regulatory obligations and industry frameworks.
Cyber Metrics & Reporting
• Support the development and enhancement of cyber risk metrics, management information, dashboards, and reporting.
• Analyze risk and governance data to identify trends, themes, and areas requiring management attention.
• Help communicate cyber risk information clearly to technical, business, management, and control stakeholders.
QUALIFICATIONS
• Bachelor's degree in Information Security, Information Systems, Computer Science, Risk Management, or a related field—or equivalent work experience.
• Cybersecurity certification would be advantageous, such as