Information Security Associate
COMPANY OVERVIEW
KKR is a leading global investment firm that offers alternative asset management as well as capital markets and insurance solutions. KKR aims to generate attractive investment returns by following a patient and disciplined investment approach, employing world-class people, and supporting growth in its portfolio companies and communities. KKR sponsors investment funds that invest in private equity, credit and real assets and has strategic partners that manage hedge funds. KKR’s insurance subsidiaries offer retirement, life and reinsurance products under the management of Global Atlantic Financial Group. References to KKR’s investments may include the activities of its sponsored funds and insurance subsidiaries.
POSITION SUMMARY
KKR is seeking an Information Security Risk Analyst to join the Information Security Governance, Risk, and Compliance (GRC) team. The role will help build and operate cyber and technology governance processes, identify and document risk issues, support remediation strategies, and manage cyber regulatory initiatives. The successful candidate will work across Information Security, Technology, and control functions to strengthen governance, improve risk visibility, support security assessments, and enhance cyber risk reporting.
RESPONSIBILITIES
Cyber Risk & Issue Management
- Support the identification, assessment, documentation, and management of cyber and technology risk issues and develop appropriate remediation, mitigation, and risk management strategies..
- Monitor risk issues and remediation activities, helping ensure risks are appropriately governed through their lifecycle.
- Maintain and support workflows to help ensure cyber risk and exception processes operate consistently and effectively.
Cyber Governance & Control Frameworks
- Help develop and enhance cyber and technology governance frameworks, standards, procedures, and supporting documentation.
- Support the development and maintenance of a cyber control catalog and associated control documentation.
- Support improvements to governance tooling, workflow design, and documentation.
Security & Technology Risk Assessments
- Support security risk assessments of applications, systems, technologies, and technology changes.
- Participate in application security and system design assessments to identify security risks and control requirements.
- Collaborate with technical and business stakeholders to understand system designs, identify risks, and recommend proportionate security controls.
Cyber Regulatory & Compliance Initiatives
- Support the delivery and coordination of cyber regulatory initiatives in response to new and changing regulatory requirements.
- Help assess regulatory requirements and translate them into practical governance, risk, and control activities.
- Help ensure cyber governance processes remain aligned with applicable regulatory obligations and industry frameworks.
Cyber Metrics & Reporting
- Support the development and enhancement of cyber risk metrics, management information, dashboards, and reporting.
- Analyze risk and governance data to identify trends, themes, and areas requiring management attention.
- Help communicate cyber risk information clearly to technical, business, management, and control stakeholders.
QUALIFICATIONS
- Bachelor's degree in Information Security, Information Systems, Computer Science, Risk Management, or a related field—or equivalent work experience.
- Cybersecurity certification would be advantageous, such as CISSP, CompTIA Security+, or an equivalent industry-recognized certification(s).
PREFERRED EXPERIENCE
- Experience working within Information Security, Technology Risk, GRC, Internal Controls, or a related technology governance function.
- Experience identifying, documenting, assessing, and tracking cyber or technology risk issues through remediation or formal risk acceptance.
- Exposure to cyber governance frameworks, standards, and control models such as NIST or CIS as well as regulatory frameworks like SOX or NIS 2.
- Experience supporting the development or maintenance of cyber policies, standards, procedures, control catalogs, or governance documentation.
- Exposure to application security assessments, system design reviews, product security reviews, or broader technology risk assessments.
- Experience developing or contributing to cyber risk metrics, dashboards, management reporting, or other risk-based management information.
- Familiarity with GRC platforms, workflow or ticketing tools, risk registers, reporting tools, or data analysis platforms used to support governance and risk processes.
SOFT SKILL REQUIREMENTS
- Ability to translate complex security, risk, and regulatory topics into clear, practical, and business-friendly guidance/actions.
- Strong stakeholder management skills with the ability to build effective relationships across Information Security, Technology, business, risk, compliance, and other control functions.
- Collaborative and team-oriented, with a willingness to contribute across a global team and work effectively with colleagues from different disciplines and backgrounds.
- Self-motivated with a strong sense of ownership, initiative, and accountability for the quality of work delivered.
- Comfortable operating in areas of ambiguity and adapting to changing priorities, technologies, regulatory expectations, and business needs.
#LI-ONSITE
KKR is an equal opportunity employer. Individuals seeking employment are considered without regard to race, color, religion, national origin, age, sex, marital status, ancestry, physical or mental disability, veteran status, sexual orientation, or any other category protected by applicable law.
KKR will provide reasonable accommodations as required by applicable federal, state, and/or local laws. Individuals seeking an accommodation for the application or interview process should email [email protected]. Emails sent for unrelated issues, such as following up on an application, will not receive a response.
If you are a qualified individual with a disability or a disabled veteran, you may request a reasonable accommodation if you are unable or limited in your ability to use or access https://www.kkr.com/careers because of your disability. You can request reasonable accommodations by sending an email to [email protected]. Only emails left for this purpose will be returned.
Massachusetts Applicants: It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this law shall be subject to criminal penalties and civil liability. This notice applies only to applicants and employees who work or will work in Massachusetts, in accordance with applicable state law.