IG Compliance & Security Analyst
$88k - $124kCooley
IG Compliance & Security Analyst
Cooley is seeking an IG Compliance & Security Analyst to join the Information Governance & Data Privacy team.
Position summary: The Information Governance (IG) Compliance & Security Analyst executes day-to-day compliance and security activities, including performing vendor and internal security assessments, supporting audits, and responding to client security requests. This role tracks risks, monitors adherence to policies and frameworks (e.g., ISO 27001, NIST), and works to document evidence, manage findings, and support remediation efforts. The analyst partners with business teams to address compliance requirements, maintain audit readiness, and apply best practices to reduce risk.
Cooley (IG) embraces a culture of customer service excellence and all members of the department are expected to move this agenda forward. To that end, the IG Compliance & Security Analyst is expected to recognize that the Cooley IG Department is a service organization first and foremost and will be evaluated on this requirement equal in importance to the technical or operational responsibilities outlined later in this document. Specific duties and responsibilities include, but are not limited to, the following:
Position responsibilities:
- Perform vendor security assessments and audits to prove up vendor's compliance with firm security policies and procedures in connection with vendor contracts, or internal inquiries
- Respond to clients' security assessment requests and audits to demonstrate firm's security compliance
- Participate in the management of the firm's ISO 27001 certification by engaging with auditors, collecting and presenting evidence, understanding the relevant firm policies, and working in the GRC platform
- Conduct both internal and external audits to ensure compliance with all industry-mandated regulations
- Work on compliance initiatives to ensure operational effectiveness with applicable laws and regulations, as well as internal policies and procedures
- Monitor activities of assigned IS areas to ensure compliance with internal policies and standards
- Participate in the development and implementation of new business initiatives to ensure functionality required to support compliance
- Provide guidance to business functions on compliance/security-related matters
- Coordinate audit-related tasks to ensure the readiness of managers and their teams for audit testing and facilitate the timely resolution of any audit findings
- Conduct/support periodic risk assessments and develop appropriate mitigation plans in support of deliverables
- Conduct formal risk assessment reviews to determine the critical points of business exposure
- Evaluate and recommend commercial governance, risk and compliance vendors and tools
- Participate in the maintenance of the firm's governance, risk and compliance platforms..
- Develop and maintain metrics that assess the firm's governance, risk and compliance initiatives
- Assess and track the firm's compliance to existing and future global regulations in privacy and security
- Assess and track the firm's compliance with standard security frameworks such as ISO and NIST
- Assist in the identification of risks, threats and vulnerabilities to firm
- Track risks and mitigation efforts
- Continued education in governance, risk and compliance forums and organizations to learn new ideas to solve problems
- Collaborate with team in evaluating effectiveness of the internal security control framework and recommend adjustments as business needs change
- Perform periodic security risk assessments and advise business stakeholders on best practices to reduce risk and overall breach profile
- Adhere to department's internal workflow processes
- All other duties as assigned or required
Skills and experience:
Required:
- After orientation at Cooley LLP, exhibit proficiency in the Microsoft Office suite, iManage and other firm applications
- Ability to work extended and/or weekend hours, as required
- Ability to travel, as required
- 3+ years' experience in governance, risk and compliance (GRC) processes, solutions, information security and auditing; Eligible for consideration of Senior designation with 5+ years' directly applicable work experience, along with the proven ability to operate at an elevated level
- CISSP or equivalent certifications and/or experience
- Demonstrated ability to apply technology-related knowledge and experience in solving compliance issues
- Background in security controls, auditing, network and system security
- Proven practical experience in information security and well-rounded knowledge of technology
- Experience with managing and implementing ISO 27001 or NIST compliance practices
- Demonstrated experience evaluating the security posture of vendors and system architecture
- Prior experience implementing and running incident management programs and systems
- Prior experience in reviewing vendor agreements for security issues and providing recommendations
- Project management experience
Preferred:
- Bachelor's degree in Information Technology or Computer Information Systems
- Prior law firm experience
- Desired certifications: PCIP, ISA/QSA, CISSP, CISA, CISM, and related GIAC
- Experience acting in an independent audit function
- Experience implementing GDPR, HIPAA, SOC 2 audits
- Experience with Smarsh, Logicgate, Bitsight, Ironclad
- Proven experience in vendor contract administration.
- Additional security certifications
Competencies:
- Exceptional customer service skills
- Ability to express technical concepts in business terms
- Able to work well under deadlines in a changing environment and complete multiple projects effectively and concurrently
- Motivated team player with a commitment to contribute meaningfully to the team's objectives, and ambition to improve skillset
- Excellent analytical, problem-solving and project management skills
- Excellent oral and written communication skills, including technical and user documentation
- Excellent active listening skills
- Ability to balance security best practices with business objectives
- Proven track record of excellent decision-making, integrity and working with members of technology management, business users and employees
- Detail orientated and strong organizational skills
- Ability to work independently and under high pressure with tight schedules and deadlines
- Ability to interact well with all levels of business professionals
- Capable of grasping new concepts quickly and without prior experience
- Ability to interact and coordinate with several teams to achieve objectives
- Ability to solve problems independently and simultaneously, effectively managing multiple tasks
- Professional demeanor at all times
Cooley offers a competitive compensation and excellent benefits package and is committed to fair and equitable employment practices.
EOE.
The expected annual pay range for this position with a full-time schedule is $88,000 - $124,000. Please note that final offer amount will be dependent on geographic location, applicable experience and skillset of the candidate. Senior level candidates may be considered for this position and would be eligible for a higher salary range based on experience.
We offer a full range of elective benefits including medical, health savings account (with applicable medical plan), dental, vision, health and/or dependent care flexible spending accounts, pre-tax commuter benefits, life insurance, AD&D, long-term care coverage, backup care for children and/or adults and other parental support benefits. In addition to elective benefit options, benefited employees receive firm-paid life insurance, AD&D, LTD, short term medical benefits as well as 21 days of Paid Time Off ("PTO") and 10 paid holidays each year. We provide generous parental leave and fertility benefits. New employees will attend a detailed benefit orientation to learn more about our many benefits and resources.
$88k - $124k
IG Compliance & Security Analyst Cooley is seeking an IG Compliance & Security Analyst to join the Information Governance & Data Privacy team. Position summary Cooley Information Services (IS) embraces a culture of customer service excellence and all members of the department...SuggestedFull timeTemporary workWork experience placementFlexible hoursWeekend work- Lead Infrastructure Security Analyst (Games) Santa Monica, Los Angeles Skydance Games Skydance is looking for a lead information security analyst skilled in working within the games industry to work with the infrastructure team to implement and configure security best...SuggestedRemote work
- A leading game development company in Santa Monica seeks a Lead Infrastructure Security Analyst. This role focuses on implementing security best practices and coordinating with the infrastructure team. Candidates should have over 5 years of experience in the games industry...Suggested
$140k - $160k
...Skydance is looking for a Lead Information Security Analyst skilled in working within the games industry to work with the infrastructure team to implement and configure security best practices and provide guidance on tool usage. Requirements Develop a security plan...SuggestedRemote work- Skydance is seeking a Lead Information Security Analyst based in Santa Monica, California, to enhance the security posture within the games industry. The ideal candidate will have over 5 years of experience in the sector, strong knowledge of IT security best practices,...SuggestedRemote job
$85k - $115k
...ultimate goal of enabling human life on Mars. INDUSTRIAL SECURITY ANALYST (CSSO/CPSO) SpaceX is looking for a multidisciplinary Industrial... ...requirements and protections needed Assist with compliance related activities to include self-inspections, audits, and...Permanent employmentTemporary workWork at officeRemote workWeekend work$95k - $115k
...SpaceX is actively developing the technologies to make this possible, with the ultimate goal of enabling human life on Mars. SECURITY ANALYST (DETECTION AND INCIDENT RESPONSE) As a Security Analyst at SpaceX, you are on the frontline of our information security...Permanent employmentTemporary workRemote workWeekend work- ...Industrial Security Analyst / Csso - Level 3 Or 4 At Northrop Grumman, our employees have incredible opportunities to work on revolutionary... ...rulings, interpretations, and acceptable deviations for compliance with regulations from government agencies. Prepares manuals...
$63k - $94.6k
...only part of history, they're making history. Northrop Grumman Aeronautics Sector (NGAS) is seeking an Associate Industrial Security Analyst (Level 1) or Industrial Security Analyst (Level 2) to join our team of qualified, diverse individuals in El Segundo, CA ....For contractorsWork at officeRelocationShift work$94.2k - $141.2k
...Northrop Grumman Aeronautics Systems is seeking a Industrial Security Analyst / CSSO - Level 3 or 4 to support the restricted programs... ...Obtains rulings, interpretations, and acceptable deviations for compliance with regulations from government agencies. Prepares manuals...For contractorsRelocationShift work- ...Exciting Security Analyst / Engineer - Threat & Cortex XSIAM (Hybrid) Requirements ~3 plus years of experience in cyber security or related discipline. ~ SIEM, Cortex XSIAM, correlation, and threat monitoring ~ Understands the following concepts: confidence intervals...Remote work
$108.1k - $145.2k
...Acquisition Security Analyst (ASA) II K2 Group is seeking an Acquisition Security Analyst (ASA) II to support a USAF customer located in El Segundo, CA at the Los Angeles Air Force Base. The Acquisition Security Analyst II will assist the Government Program Manager...Contract workTemporary workFor contractorsWork experience placementWork at office$94.2k - $141.2k
Northrop Grumman is hiring an Industrial Security Analyst/CSSO - Level 3 or 4 for its El Segundo and Redondo Beach locations. This role involves supporting a high-profile program and managing security initiatives related to classified materials. Candidates must have a...- ...4 trips to Germany per year About the Role We're seeking a Security Analyst to partner closely with development and product teams to ensure... ...and implementation of additional security measures Support compliance with security policies, controls, and procedures (PCI‑DSS,...Work at officeLocal areaRemote work
- Stability Technology is looking for a Cyber Security Analyst in Los Angeles, CA, to enhance security across cloud and network environments. This hands-on role requires 3-6 years of experience and strong knowledge of Azure security tools, Microsoft Defender, and incident...Contract work
$63k - $94.6k
Northrop Grumman is seeking an Associate Industrial Security Analyst or Industrial Security Analyst in El Segundo, CA. The role involves developing and administering security programs for classified materials. Candidates must possess a Bachelor's degree or equivalent security...Work at office- A leading aerospace company in Hawthorne, California, is looking for an Information Security Analyst to manage its security operations and support security services. This role includes maintaining security tools, automating tasks, and documenting processes. The ideal candidate...
$75.8k - $113.8k
Northrop Grumman is seeking a Financial Analyst in El Segundo, CA. This role involves monthly financial reporting, planning processes, and supporting financial performance improvements. The ideal candidate should have at least a Bachelor's degree and two years of relevant...- IT Security Analyst - EAD or GC or USC ONLY Full-time, Los Angeles, CA, 1-2 year contract. USM Business Systems Inc. is a quickly developing... ...or USC ONLY The main skills: 3rd Party Risk Assessment Compliance/SOX/Audit Experience CISA or CISSP Certification For more...Full timeContract workWorldwide
- ...aerospace company based in Hawthorne, CA is seeking an Industrial Security Analyst to join their team. This role requires a self-starter with... ...encompass partnership with engineering teams to ensure compliance with security protocols, assisting in personnel clearance management...
$95k - $115k
...actively developing the technologies to make this possible, with the ultimate goal of enabling human life on Mars. INFORMATION SECURITY ANALYST We are looking for an Information Security Analyst to join our Information Security team. This role is the operational...Permanent employmentTemporary workRemote workWeekend work$90k - $120k
...Information Security Analyst II The Marvin Group is a Strategic Partner for Global Alternate Mission Equipment and Sustainment. The Marvin... ...assessments and risk analysis Cybersecurity Compliance Frameworks SIEM Tools Cloud Security System administration...Permanent employmentContract workFor contractorsWork experience placementWork at officeFlexible hours- About the Role We are seeking an Information Security Analyst to help protect the organization's systems, networks, and data from security... ..., and procedures Collaborate with IT, engineering, and compliance teams to integrate security into systems and processes...Work at officeLocal area
- A county government is seeking an IT Security Analyst in Los Angeles. This role requires a Bachelor's degree in Computer Science or a related field and at least two years of full-time experience in IT security solutions and industrial control systems. The analyst will...Full time
- Exciting Threat Intelligence Analyst / Security Analyst Tier II, 6 months, contract opportunity in Los Angeles, CA. 2 plus years of experience in tactical intelligence or intelligence analysis, or a related area. 3 plus years of experience in cyber security or related...Contract work
- Title: Information Security Analyst Role Overview: The Information Security Analyst is a hands‑on role within the Information Security function, partnering closely with IT and business stakeholders to ensure consistent, measurable delivery of security services. This position...Work at office
$80k - $120k
This full-time Senior Information Security Analyst role is based on-site in Los Angeles, CA. The role involves overseeing and enhancing the... ...teams to implement security measures and maintain compliance with relevant regulations. Responsibilities Monitor and analyze...Full time- A specialized recruitment firm is looking for an Information Security Analyst in Los Angeles. This role involves overseeing vendor management and conducting security assessments. Ideal candidates will have 2-3 years in IT and cybersecurity, including vendor security assessments...
- A growing IT service provider in Los Angeles is looking for a full-time IT Security Analyst for a contract role. Candidates should have experience with 3rd Party Risk Assessment and Compliance/SOX/Audit, along with CISA or CISSP certifications. This position offers an opportunity...Full timeContract work
- A dynamic tech consulting firm in Los Angeles seeks an experienced Information Security Analyst to enhance their security practices. The role demands proactive involvement in vendor management, third-party assessments, and security integrations across both enterprise and...
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to IG Compliance & Security Analyst. Be the first to apply!
- regulatory compliance remote Santa Monica, CA
- vp compliance Santa Monica, CA
- customs compliance Santa Monica, CA
- compliance paralegal Santa Monica, CA
- regulatory affairs Santa Monica, CA
- vendor compliance Santa Monica, CA
- compliance lead Santa Monica, CA
- regulatory compliance Santa Monica, CA
- ethics compliance Santa Monica, CA
- compliance technician Santa Monica, CA

