GRC Analyst
Software Technology Inc
GRC Analyst
We are looking for an individual who is personable, comfortable working within a growing & supportive environment and capable of building processes within new and existing technologies to showcase cybersecurity to IT and business leadership. This position will play a crucial role in maturing cybersecurity function toward proactive risk management capabilities.
Key Responsibilities
- Provide analytic expertise, operational skill and input for development of ASMG’s IT & Cybersecurity functions
- Develop IT policies, procedures, operational techniques & improvements for IT internal controls
- Evaluate and assist with developing security monitoring and operating procedures at the application, system and tenant level
- Analyze vendor services and information security requirements, maintaining relationships with key 3rd party providers
- Assist in the development of relevant, useful cybersecurity KPIs to track and communicate performance, coverage and risk
- Work with Internal Audit and outside teams to effectively manage IT security framework and regulatory requirements
- Support incident response and trouble resolution on complex issues
- Maintain awareness of trends and development opportunities within security regulatory, technology, and operational requirements
Education and Experience Profile
- B.S. in Technology- or Business-related discipline, or equivalent experience
- Strong background and orientation with IT & cybersecurity requirements and internal controls
- 1-3+ years of experience within IT operations, cybersecurity, audit or consulting functions, including familiarity with internal and cloud-based IT environments
- Familiarity with Microsoft or similar environments including M365, D365, Azure, Defender, Darktrace, Workday & others
- Preference given to CISA/CRISC/CGEIT/CISSP/CISM & related/industry certifications, or willingness to pursue
Desired Skills and Abilities
- Experience with managing cybersecurity requirements within IT GRC and Data Privacy frameworks, such as NIST 800-53/171/CSF, SOC(x), PCI-DSS or GDPR
- Demonstrated capability with developing IT communications to internal/external constituents and executive management teams
- Effective communicator with an ability to translate security analyses into understandable, actionable elements
- Willingness to work constructively with Infrastructure and Operations personnel to provide input on improvements to cybersecurity toolsets and techniques
- Solid organization and prioritization skills
- Personable approach and ability to work with remote IT venue personnel, contributing to a team environment with professionalism
- Strong communication skills, both verbal and written
Vacancy posted more than 2 months ago
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to GRC Analyst. Be the first to apply!
Related searches
