Information Security Analyst, GR&C

CrashPlanMinneapolis, MN
5d$105,000 - $125,000Remote

About The Position

We are recruiting for an Information Security Analyst, Governance, Risk Management and Compliance to join our team. As a key member of the CrashPlan Information Security Team, you will be supporting the risk management and compliance functions. We believe in smart security and in your role you will look for meaningful ways to manage risk, ensure compliance, and work with teams to implement better security practices.

Requirements

  • Bachelor’s Degree in Computer Science, Information Systems, Cybersecurity, or related discipline and/or equivalent experience
  • 3+ years professional experience in a similar role
  • Knowledge of/experience working with NIST 800-53, ISO 27001, SOC2, GDPR, DPF and other relevant security and privacy frameworks
  • Knowledge of/experience with third Party Security, Policy management, Customer Security Assurance, and/or Security Awareness
  • Experience conducting data privacy and security risk assessments and impact analysis

Nice To Haves

  • One or more information security or privacy certifications (e.g. CISSP, CISM, CIPP)
  • Experience using vulnerability scan tools and threat and vulnerability management
  • Experience with Azure and AWS environments

Responsibilities

  • Conducting security and privacy risk assessments and security consulting engagements
  • Conducting information security assessments of third-party vendors
  • Maintaining reporting and tracking for information security and privacy risks and working closely with risk owners to remediate
  • Conducting periodic business continuity and disaster recovery testing
  • Responding to customer and prospect security questions related to CrashPlan’s products and security posture
  • Supporting information security and privacy compliance audits and initiatives (e.g. SOC2, ISO 27001, PCI-DSS, GDPR) including day to day management of the GRC platform and continuous monitoring activities
  • Conducting internal audits
  • Managing the security training and awareness program and phishing simulations
  • Facilitating change management
  • Prioritizing risks efficiently and appropriately; challenging assumptions and methodologies
  • Triaging and prioritizing vulnerabilities for remediation
  • Developing and maintaining cross-functional partnerships, and partnering with SMEs to determine appropriate risk-based remediation strategies

Benefits

  • medical
  • dental
  • vision
  • 401k match
  • annual bonus
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service