Governance, Risk & Compliance, Analyst (Seasonal)

MLB (Job Board Only)New York, NY
10h$23 - $30

About The Position

The MLB Information Security team is looking for a GRC analyst to focus on governance, risk management, and compliance activities. The Analyst will assist with routine GRC activities, such as supporting audit preparation, conducting risk assessments and monitoring risk registers, and updating internal policies and procedures.

Requirements

  • Completed a Master’s or Bachelor’s degree in Information Technology, Information Security, Cybersecurity, Computer Science, or a related field (i.e., Information Security, Risk Management, Compliance).
  • Strong understanding of PCI v4.0.1 standards, global data privacy laws and regulations (e.g., GDPR, CCPA), IT control frameworks (e.g., NIST CSF, ISO 27001), and risk assessment methodologies
  • Ability to gather and analyze considerable volumes of data from multiple sources and effectively summarize information into concise, well-written, objective reports and dashboards.
  • Strong knowledge of risk management processes (e.g., methods for assessing and mitigating risk).

Responsibilities

  • Help implement MLB’s data privacy, governance, and risk management programs.
  • Support the successful execution of PCI-DSS and SOC 1 Type II audits by reviewing evidence, coordinating with internal stakeholders, and maintaining audit readiness dashboards.
  • Conduct comprehensive vendor security and compliance risk assessments, and support the team in providing recommendations for contractual security provisions
  • Implement and refine vendor risk review workflows, maintain vendor repository, and apply risk tiering based on data access and criticality within MLB’s TPRM tool.
  • Track and manage risk acceptances and policy exceptions, ensuring proper documentation and regular review.
  • Assist in responding to and fulfilling Data Subject Access Requests (DSAR), ensuring all requests are completed within the statutory timelines required by applicable privacy law.
  • Assist in drafting compliance policies, procedures, and playbooks on cybersecurity, privacy, confidentiality, and data protection topics.
  • Develop and maintain KPIs and dashboards to measure the success of GRC programs and initiatives.
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service