Davis Polk & Wardwell LLP Logo

Davis Polk & Wardwell LLP

Risk & Compliance Analyst

Posted 11 Days Ago
In-Office
New York, NY, USA
100K-125K Annually
Mid level
In-Office
New York, NY, USA
100K-125K Annually
Mid level
Support and execute the firm's GRC program including ISO 27001 ISMS support, client security assessments, vendor risk reviews, internal IT risk assessments, DR testing, access recertification, and remediation tracking across audits and security reviews.
The summary above was generated by AI

Davis Polk & Wardwell LLP (including its associated entities) is an elite global law firm with world-class practices across the board. Clients know they can rely on Davis Polk for their most challenging legal and business matters. From offices in the world's key financial centers and political capitals, our more than 1,000 lawyers collaborate seamlessly to deliver exceptional service, sophisticated advice and creative, practical solutions. Visit davispolk.com.

Position Summary

The Risk & Compliance Analyst will play a key role in supporting and executing the Firm’s governance, risk and compliance (GRC) program. Reporting to the Compliance Manager, this role will independently manage components of the Firm’s risk and compliance processes, including vendor risk management, client assessments, audit support, and policy governance. This position offers strong exposure to ISO 27001, client-facing security assessments, and enterprise risk management within a professional services environment.

Essential Duties and Responsibilities

Typical responsibilities include, but are not limited to, the following:

  • Support and help maintain the Firm’s Information Security Management System (ISMS), including contributing to ISO 27001 compliance and annual recertification efforts.

  • Manage day-to-day execution of the Firm’s client security assessment process, including gathering documentation, tracking questionnaires, and coordinating responses with internal teams.

  • Support third-party vendor risk assessments, including reviewing questionnaires, SOC reports, and supporting security documentation.

  • Assist in conducting internal IT risk assessments by gathering information from business and IT stakeholders to identify risks, document findings, and support development of risk treatment plans.

  • Support disaster recovery (DR) testing activities, including coordination, documentation, and tracking of results and action items.

  • Execute user access recertification processes for standard and privileged accounts, including tracking completion and escalating issues as needed.

  • Track and follow up on remediation efforts related to findings from client assessments, internal audits, penetration tests, and other security reviews.

  • Support the ongoing use of tools supporting vendor risk management and compliance processes.

  • Perform other duties as assigned.

Qualifications/Position Requirements

  • Familiarity with ISO 27001 framework, as well as NIST, SOC 2, or similar.

  • Experience responding to client security questionnaires and conducting vendor risk assessments.

  • Strong analytical, organizational, and time management skills with attention to detail.

  • Proven ability to manage multiple priorities and projects simultaneously in a fast-paced environment while consistently meeting deadlines.

  • Excellent verbal, written, and presentation skills, with the ability to communicate effectively with clients, leadership, and cross-functional teams.

  • Strong interpersonal skills with ability to build relationships and interact with individuals at all organizational levels.

  • Ability to work independently, exercise sound judgement, and take initiative while collaborating effectively across teams.

Education and/or Experience

  • Bachelor’s degree required, preferably Business Systems, Information Systems.

  • 3-5 years of experience in IT risk, compliance, audit, or information security.

  • Previous experience in legal services preferred.

Compensation

The expected base salary for this position ranges from $100,000 - $125,000. Salary offers are based on a wide range of factors including relevant skills, training, experience, education, anticipated assignment, and, where applicable, licensure or certifications obtained. Market and organizational factors are also considered. Davis Polk offers a competitive salary and comprehensive benefits package.

HQ

Davis Polk & Wardwell LLP New York, New York, USA Office

450 Lexington Ave, New York, NY, United States, 10163

Similar Jobs

20 Days Ago
Hybrid
New York, NY, USA
162K-202K Annually
Senior level
162K-202K Annually
Senior level
Consumer Web • Healthtech • Professional Services • Social Impact • Software
Lead and mature Headway's GRC program across certifications (HITRUST, SOC 2, PCI-DSS, HIPAA), third-party risk, security awareness training, and technical risk management. Manage audit readiness, vendor assessments, risk register, and cross-functional embedding of compliance. Build repeatable, AI-enabled processes and coordinate remediation and assessor activities.
Top Skills: AIDrataGrc PlatformsHipaaHitrustOnetrustPci-DssSoc 2Vanta
23 Days Ago
In-Office or Remote
United States
Senior level
Senior level
Healthtech • Information Technology
The Senior IT Risk and Compliance Analyst manages vendor risk, ensures compliance with regulations, documents controls, and supports risk mitigation efforts across IT teams.
Top Skills: Audit MethodologiesCobitIso27001Iso27002NistServicenow Irm
3 Minutes Ago
Remote or Hybrid
USA
37K-75K Annually
Mid level
37K-75K Annually
Mid level
Machine Learning • Payments • Security • Software • Financial Services
Provide phone-based first-line technical support to internal employees/contractors: troubleshoot hardware, software, network, and access issues; document incidents in ServiceNow or similar ITSM tools; escalate complex problems; and maintain data privacy and strong customer service in a remote workspace.
Top Skills: Call Center TechnologiesHelp DeskItsmServicenow

What you need to know about the NYC Tech Scene

As the undisputed financial capital of the world, New York City is an epicenter of startup funding activity. The city has a thriving fintech scene and is a major player in verticals ranging from AI to biotech, cybersecurity and digital media. It also has universities like NYU, Columbia and Cornell Tech attracting students and researchers from across the globe, providing the ecosystem with a constant influx of world-class talent. And its East Coast location and three international airports make it a perfect spot for European companies establishing a foothold in the United States.

Key Facts About NYC Tech

  • Number of Tech Workers: 549,200; 6% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Capgemini, Bloomberg, IBM, Spotify
  • Key Industries: Artificial intelligence, Fintech
  • Funding Landscape: $25.5 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Greycroft, Thrive Capital, Union Square Ventures, FirstMark Capital, Tiger Global Management, Tribeca Venture Partners, Insight Partners, Two Sigma Ventures
  • Research Centers and Universities: Columbia University, New York University, Fordham University, CUNY, AI Now Institute, Flatiron Institute, C.N. Yang Institute for Theoretical Physics, NASA Space Radiation Laboratory

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account