Digital Risk & Controls Specialist
Description

The Digital Risk & Controls Specialist coordinates day-to-day activities that support the Community Foundation's governance and risk management program. This role focuses on digital controls, third-party risk management, and the systems and processes used to help identify, track, and manage risk.

This role helps ensure the organization meets its cybersecurity, data protection, and compliance obligations by coordinating the collection, organization, reporting, and retention of required documentation and evidence. The position is a key partner to the cybersecurity team and supports the Community Foundation's broader digital risk management and information security programs.

This salaried, exempt position reports to the Director, Information Security. This role is based in our downtown Kansas City, MO office, with the opportunity for a hybrid schedule following a successful training period.

Requirements
  • GRC Platform Administration: Serves as the primary administrator and user for the GRC management platform and maintains all related GRC monitoring tools and workflows.
  • Digital Controls Management: Maintains centralized security, privacy, and AI risk management controls database to continue the digital governance controls framework the Community Foundation has adopted. Tracks remediation of control gaps as identified in risk assessments and resolution of findings from external audits.
  • Digital Risk Assessments & Reporting: Performs regular risk assessments across IT and data-handling processes, including vendors and other third parties. Maintains the Community Foundation’s digital governance risk register. Documents risk profiles for vendors, systems, and processes; oversees data related to risk management decisions and mitigations; delivers periodic risk reports and metrics to leadership, translating technical security risks into realistic business impact potential indicators.
  • Vendor Reviews: Coordinates reviews of vendors, applications, data-sharing arrangements, and AI tools to assess security, privacy, and technology risks. Analyze vendor documentation, identify control gaps and potential risks, and document findings and recommendations within the Community Foundation's risk management platform.

Experience

  • Education & Experience: Bachelor's degree in information security, information technology, business administration, accounting or related discipline, or equivalent practical experience. 2 years of experience in GRC, IT risk, security controls, audit readiness, control testing, compliance, security assurance, or related field. Preference towards beginning progress toward a professional designation such as CISA, CISM, CRISC, CIPP, AIGP, or equivalent.
  • Artificial Intelligence Literacy: Experience with and knowledge of the principles and concepts around artificial intelligence and the use of general-purpose and specialized large language models as applied to overall business operations, including a basic understanding of AI and LLM risks. Hands-on experience with a variety of general-purpose AI tools.
  • Communication: Possess written and verbal communication skills to facilitate being able to read, analyze, and interpret a variety of instructions and procedures, interpret and operate within current technical development and security best practices. 
  • Technical Aptitude: Strong foundational knowledge of current cybersecurity and data protection best practices, with a basic understanding of contemporary governance standards, frameworks, and information technology risk management approaches. High general technical aptitude and ability to learn new software quickly and thoroughly.
  • Collaborative Environment: Ability to operate in a highly collaborative environment, while able to work independently and be self-motivated.
  • Responsiveness: Respond effectively to the most sensitive inquiries or complaints; work well under pressure, including identifying and quickly resolving problems.

Physical Requirements

  • Office & Computer Work: Ability to work regularly at a computer workstation in a fast-paced environment with frequent interruptions.
  • Noise & Communication: Able to work in an office with moderate noise levels. Ability to communicate and interpret detailed information effectively.

This job description is a summary of the employment-at-will relationship and not a contract. Not every responsibility is outlined; changes should be anticipated, and other duties will be assigned as necessary.


Please submit a cover letter with your resume.