Security Compliance Analyst

TEKsystemsRocklin, CA
1d$75 - $80Hybrid

About The Position

The Information Security Compliance Analyst supports the sustained compliance of the company with requirements for the protection of its systems and information assets. The scope of work extends across the corporate environment and its consumer delivery channels and it addresses legal requirements and industry standards such as PCIDSS, COBIT, ISO, HIPAA, CA1386 and GDPR. The Information Security Compliance Specialist plays a lead role in this activity. The Specialist will be responsible for providing execution support to business units in performing third party risk assessments, due diligence activities, data management, ongoing oversight, and reporting related to the engagement and management of third parties handling sensitive business information. The Specialist supports periodic updates to policies, standards and awareness materials, and is responsible for ongoing validation that key controls are implemented in a sound and sustained manner. The Specialist may also identify potential security exceptions, help to resolve business requirements, escalate matters requiring management attention, and oversee timely and effective remediation of vulnerabilities in the security of company information.

Requirements

  • BA/BS or equivalent experience
  • 3+ years of experience gained in the information security field
  • Experience reviewing, editing and negotiating contracts, specifically to ensure adequate safeguards are defined to protect sensitive business information
  • Experience working with, and ideally writing, information security policies and standards
  • Understand information security holistically and how it relates to business goals
  • Excellent written, oral, and interpersonal communications skills
  • Ability to design, implement, reengineer and manage complex processes.
  • Proven people management skills.
  • Strong analytical skills
  • General knowledge and experience with information security standards and methodologies, including the PCIDSS, ISO 9000 series, COBIT, Sarbanes Oxley, HIPAA, and other relevant industry security standards, and knowledge of risk assessment and risk analysis
  • Experience with PCI DSS Assessments.
  • Experience working with, and ideally writing, information security policies and standards and/or developing or implementing security-related tools
  • Experience within GRC, specifically reviewing contracts and agreements between various parties to determine risks

Nice To Haves

  • CISSP, CISM, CISA or similar certification [e.g., GIAC Certified ISO-17799 Specialist (G7799)]
  • Privacy Certification (e.g., Certified Information Privacy Professional)
  • Experience communicating privacy and security compliance issues to upper management
  • Experience presenting information security issues to large audiences, forums, or communities
  • Experience working within the retail sector

Responsibilities

  • Respond to requests from the business to perform security reviews of third party engagement to ensure regulatory requirements and internal compliance obligations are met
  • Partner with business owners to maintain an inventory of third parties sharing or accessing WSI’s sensitive business data
  • Assign and monitor compliance tasks using GRC tools
  • Work with business partners to ensure that policies and standards align with their commercial priorities and applicable laws, regulations, and related industry directives
  • Develop and document standard operating procedures and process maps for the performance of third party risk management activities, based on higher level policy and procedures documentation
  • Maintain effective relationships with business unit third party coordinators and other stakeholders, to ensure that business needs are satisfied in an efficient and effective manner
  • Build and maintain strong professional relationships and partnerships with key business partners
  • Communicate and promote the sound implementation of policies, standards, and procedures throughout the organization.
  • Monitor and evaluate external security trends and best practices for policy adoption within WSI

Benefits

  • Medical, dental & vision
  • Critical Illness, Accident, and Hospital
  • 401(k) Retirement Plan – Pre-tax and Roth post-tax contributions available
  • Life Insurance (Voluntary Life & AD&D for the employee and dependents)
  • Short and long-term disability
  • Health Spending Account (HSA)
  • Transportation benefits
  • Employee Assistance Program
  • Time Off/Leave (PTO, Vacation or Sick Leave)
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service