The Security Governance, Risk & Compliance Analyst conducts comprehensive activities supporting information security governance, risk, and compliance, including but not limited to drafting and updating security policies, standards, and procedures; performing security risk assessment and remediation activities; supporting the internal controls testing program; facilitating audits and assessments; information security issues oversight; supporting security training and awareness activities. Plan and support the Security Governance, Risk and Compliance programs and department initiatives. Further develop Security Governance, Risk and Compliance skills and support at least two of the functional areas within Security Governance, Risk and Compliance: Risk management, PCI assessments, Internal Audits, Security policy management, GRC tool management, remediation plans for security-related findings (IA, OCC, SOC-2, etc.), participation and facilitation of external audits: (GLBA, SOC-2, customer audits, consolidated customer audits), Security trainings and user responsibility agreements, ensure adherence to policies and deadlines, and provide assistance to remediation owners for interpretation of policies and processes in line with the objectives of the organization and regulators. Provide consultation to management on regulatory, legal, and contractual requirements. Perform GRC activities using the GRC platform; support the Security Department with GRC platform usage and best-practices. Engage business owners throughout the organization in the development and enforcement of security policies, standards, procedures, and guidelines at the direction of Security Management. Oversee the completion of internal control testing; advise management on control design and implementation; perform testing where needed. Identify control gaps and weaknesses, and track and report remediation progress. Assess information security risk and recommend mitigation activities in alignment with Enterprise and Operational Risk Management requirements. Facilitate the collection and review of documentation required for internal and external audits and assessments (SOC-2, GLBA, FISMA, PCI-DSS, others). Facilitate the execution of internal and external audits and assessments. Conduct security GRC reporting (risk, controls, issues, or otherwise) for management and stakeholders. Create monthly security-focused metrics reporting for management and senior leadership. Maintain compliance programs (security awareness and training activities, phishing and password, etc.) according to their set schedules. Support the company’s commitment to protect the integrity and confidentiality of systems and data.
Stand Out From the Crowd
Upload your resume and get instant feedback on how well it matches this job.
Job Type
Full-time
Career Level
Mid Level