Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Information Security Risk & Compliance Analyst

$80k

Ryder Truck Rental

Job Description Summary The Information Security Risk & Compliance Analyst will be responsible for assuring information security and managing risks related to the use, processing, transmission and storage of information and the systems and processes used for those purposes. The Analyst's role lies within the Chief Information Security Officer's organizational structure, reporting to the Manager of Information Security Governance, Risk and Compliance. The Analyst will be a key member contributing to the development and maintenance of information security policies, standards, and controls, assessing and prioritizing risk across the organization, compliance with existing and future frameworks, legal and regulatory standards and the development and reporting of information security metrics. The Analyst's role will help prepare for and facilitate assessments and examinations by independent information security assessors. The Analyst will perform third party supplier security assessments, as well as facilitate and coordinate responses for customer due diligence questionnaires. Essential Functions Perform information security risk assessments and risk management activities across new and existing information technology solutions. Establish and maintain risk criteria, identify, analyze, and evaluate information security risks. Ensure that repeated information security risk assessments produce consistent valid and comparable results. Maintain repository of documented information about the information security risk assessment process. Conduct risk and vulnerability assessments of planned and installed information systems. The Information Risk and Compliance Analyst will create, organize and articulate summarized risk findings that are clear and actionable by business stakeholders, reduce risk by helping to prioritize and drive remediation efforts throughout the organization, and contribute to risk management, treatment, and reporting process efforts to protect data assets. Perform all ongoing compliance activities related to the implementation, maintenance, monitoring and continuous improvement of Ryder’s existing Information Security Management System (ISMS) based on the requirements of ISO/IEC 27001 International Standard as well as future compliance requirements. The analyst will work with various levels and departments across the organization to ensure appropriate documentation is maintained as evidence of competence and compliance and help to facilitate internal and external independent examinations. The analyst will also help to develop and implement an effective and unified global information technology/security compliance program with applicable data protection standards, legislation, as well as customer information security requirements. Perform information security, governance, risk and compliance assessment reports on third party suppliers to ensure supply chain risk is managed throughout the supplier's lifecycle. Produce final reports of pros and cons, observations of anomalies, and deliverables for the business as well as mandates for supplier compliance. Articulate results of the final assessments to business stakeholders, project sponsors, program managers, and other internal parties. Assist with review of information security sections within supplier contracts to ensure security and data privacy requirements are in place. Assist with the evaluation of the effectiveness of information security management and performance by developing, monitoring, gathering and analyzing information security and compliance metrics for management. Develop and implement a risk reporting framework for management teams and governance committees. Design and document IT general controls to ensure the business demonstrates compliance with its regulatory or compliance obligations. Facilitate and coordinate activities and responses related to internal and external controls testing including entitlement reviews. Facilitate the remediation of control gaps and elevate critical issues to management. Work closely with control owners, internal and external auditors to ensure requests are completed for timely delivery to audit. Assist with third party audits and certifications for the organization (i.e. SOC, ISO, PCI, etc.) Assist with responding to customer information security requirements and due diligence questionnaires. Coordinate and facilitate response gathering in conjunction with other organizational application, support, infrastructure, legal, HR, and physical security teams as necessary. Ensure responses are accurate, valid, consistent and reported within expected deadlines. Maintain repository of customer information security requirements, track and report on compliance. Analyze and evaluate information security incidents in order to reduce the likelihood or impact of future incidents. Facilitate reports of security violations by documenting and coordinating remediation and awareness of violations to respective managers. Maintain repository of information security incidents and develop metrics for reporting to management. Research, recommend, and contribute to information security polices, standards, and procedures and work with other organizational participants from legal, human resources, information technology, compliance, physical security, the business units and others that have to implement the policies. Assist the lifecycle management of information security's policy and supporting documents. Additional Responsibilities Performs other duties as assigned. Provide assistance with other information security, risk and compliance projects and initiatives as assigned. Stay current with industry trends relevant to cyber security, privacy, and risk. Skills and Abilities Strong verbal and written communication skills Strong verbal communication and listening skills Ability to work in a regulated environmentAn understanding of organizational mission, values, and goals and consistent application of this knowledge Ability to present information and ideas clearly and understandably to othersAn ability to identify and assesses the severity and potential impact of risks and communicate risk assessment findings to risk owners outside Information Security in a way that consistently drives objective, fact-based decisions about risk that optimize the trade-off between risk mitigation and business performance Ability to create and maintain professional relationships within all levels of the organization (peers, work groups, customers, supervisors) Ability to maintain confidential information Ability to simultaneously handle multiple priorities Ability to work independently and as a member of a team Demonstrates a high level of accuracy, even under pressure Possesses a high degree of initiativeAn understanding of business needs and commitment to delivering high-quality, prompt, and efficient service to the business Seeks to acquire knowledge in area of specialty Excellent organizational skills Maintains a high degree of professionalism Proactively approaches responsibilitiesAn understanding of organizational mission, values, and goals and consistent application of this knowledge Ability to drive multiple projects to successful completionExcellent prioritization capabilities, with an aptitude for breaking down work into manageable parts, effectively assessing the priority and time required to complete each part Maintains composure under pressure Ability to analyze and solve problems Ability to effectively facilitate meetings, work sessions, and training Ability to group, categorize, and systematize data, people, or thingsAbility to collect, compile, gather reports with associated email thread responses ensuring respective reports and responses are maintained separate for each entitlement report reviewer Ability to work within tight timeframes and meet strict deadlines Flexibility to operate and self-driven to excel in a fast-paced environment Ability to work with others in a professional manner while achieving a common goal Capable of multi-tasking, highly organized, with excellent time management skills Ability to effectively manage a variety of tasks and projects simultaneouslyAn ability to work on several tasks simultaneously and pay attention to sources of information from inside and outside one’s network within an organization Ability to influence internal and/or external constituentsAn ability to effectively influence others to modify their opinions, plans, or behaviors, with an emphasis on collaborating across multiple teams and ensuring program needs are satisfied through interpersonal and trusted communication Demonstrates excellent judgment and decision making skillsStrong decision-making capabilities, with a proven ability to weigh the relative costs and benefits of potential actions and identify the most appropriate one Ability to listen, write, and speak effectively Inform, explain, and give instructionsAn ability to communicate complex and technical issues to diverse audiences, orally and in writing, in an easily-understood, authoritative, and actionable manner Exposure to and familiarity with relevant standards such as ISO/IEC 27000 family - Information Security Management Systems, NIST Cybersecurity Framework, NIST 800, and applicable laws related to regulatory compliance, information security and privacy (e.gSOX, HIPAA, GDPR, PCI-DSS) intermediate required Knowledge of information security risk management and IT controls frameworks and methodologies (e.gISO/IEC 27005, COBIT, OCTAVE) intermediate required Knowledge of Risk Management Principles (risk avoidance, transfer, mitigation, acceptance), Risk Assessment process intermediate required Knowledge of Cloud Security - Cloud Control Matrix (CCM), Consensus Assessment Questionnaire (CAIQ) intermediate required Knowledge of Common Controls Hub - Unified Compliance Framework (UCF) intermediate preferred Knowledge of Standardized Information Gathering (SIG) Questionnaire intermediate preferred Knowledge of AICPA SOC for Service Organizations intermediate preferred Qualifications Bachelor's degree required Information Security, Information Technology, Management Information Systems Master's degree preferred Information Security, Information Technology, Management Information Systems Three (3) years or more Experience with risk assessments and compliance of major regulatory, standards and privacy initiatives (e.g. SOX, PCI-DSS, HIPAA, GDPR, CCPA, FedRAMP) required Three (3) years or more Experience with cyber security and information security program management and frameworks (e.g. NIST CSF, ISO/IEC 27000, etc.) required Exposure to and familiarity with relevant standards such as ISO/IEC 27000 family - Information Security Management Systems, NIST Cybersecurity Framework, NIST 800, and applicable laws related to regulatory compliance, information security and privacy (e.g. SOX, HIPAA, GDPR, PCI-DSS) intermediate required Knowledge of information security risk management and IT controls frameworks and methodologies (e.g. ISO/IEC 27005, COBIT, OCTAVE) intermediate required Knowledge of Risk Management Principles (risk avoidance, transfer, mitigation, acceptance), Risk Assessment process intermediate required Knowledge of Cloud Security - Cloud Control Matrix (CCM), Consensus Assessment Questionnaire (CAIQ) intermediate required Knowledge of Common Controls Hub - Unified Compliance Framework (UCF) intermediate preferred Knowledge of Standardized Information Gathering (SIG) Questionnaire intermediate preferred Knowledge of AICPA SOC for Service Organizations intermediate preferred Other Certified Information Systems Security Professional (CISSP), Certified Information Systems Auditor (CISA), or Certified in Risk and Information Systems Control (CRISC) or Certified Cloud Security Professional (CCSP) credentials or International Association of Privacy Professionals (IAPP) Travel None DOT Regulated None Job Category: Information Security Our Culture & Commitment At Ryder, you’re trusted to make an impact—while enjoying room to grow and having a voice that’s heard. Our culture is built on respect, collaboration, and shared pride in doing great work rooted in innovation and safety. Your Voice. Your Success. The Future We Build Together. Compensation Information The compensation offered to a candidate may be influenced by a variety of factors, including the candidate’s relevant experience; education, including relevant degrees or certifications; work location; market data/ranges; internal equity; internal salary ranges; etc. The position may also be eligible to receive an annual bonus, commission, and/or long-term incentive plan based on the level and/or type. Compensation ranges for the position are below: Pay Type Salaried Minimum Pay Range: $80,000.00 Maximum Pay Range: $110,000.00 Benefits Information: For all Full-time positions only: Ryder offers comprehensive health and welfare benefits, to include medical, prescription, dental, vision, life insurance and disability insurance options, as well as paid time off for vacation, illness, bereavement, family and parental leave, and a tax-advantaged 401(k) retirement savings plan. Ryder is proud to be an Equal Opportunity Employer and Drug Free workplace. All qualified applicants will receive consideration for employment without regard to race, religion, color, national origin, sex, sexual orientation, gender identity, age, status as a protected veteran, among other things, or status as a qualified individual with disability. Important Note Some positions require additional screening that may include employment and education verification; motor vehicle records check and a road test; and/or badging or background requirements of the customer to which you are assigned. Security Notice for Applicants Ryder will only communicate with an applicant directly from a [@ryder.com] email address and will never conduct an interview online through a chat type forum, messaging app (such as WhatsApp or Telegram), or via an online questionnaire. During an interview, Ryder will never ask for any form of payment or banking details and will never solicit personal information outside of the formal submitted application through . #J-18808-Ljbffr Ryder System, Inc.

Vacancy posted 2 days ago
Similar jobs that could be interesting for youBased on the Information Security Risk & Compliance Analyst in Coral Gables, FL vacancy
  •  ...Cybersecurity Risk And Compliance Analyst The Cybersecurity Risk and Compliance Analyst ensures...  ...and facilitate response generation, information gathering, testing evidence, and escalation...  ...team members, drive the adoption of security best practices, assist with creating... 
    Suggested

    Goodwill Industries of South Florida

    Miami, FL
    3 days ago
  • $80k

     ...Job Description Summary The Information Security Risk & Compliance Analyst will be responsible for assuring information security and managing risks related to the use, processing, transmission and storage of information and the systems and processes used for those purposes... 
    Suggested
    Full time

    Ryder

    Coral Gables, FL
    1 day ago
  •  ...Governance, Risk & Compliance (GRC) Analyst (AI Training) About the Role We're partnering with...  ...compliance programs, risk frameworks, or security audits, your expertise is exactly...  ...workflows Background in information security, internal audit, or third-party... 
    Suggested
    Hourly pay
    Ongoing contract
    Contract work
    Freelance
    Remote work
    Flexible hours

    Alignerr

    Miami, FL
    4 days ago
  •  ...Job Title Risk and Compliance Analyst Location Doral, FL 33122 US (Primary) Category...  ...Education Bachelor's Degree Travel Security Clearance Required None Job...  ...A Bachelor's degree in Engineering, Information Systems, or a related field, or five... 
    Suggested
    Full time

    Prescient Edge

    Miami, FL
    1 day ago
  • The Risk & Compliance Analyst is responsible for ensuring Educational Federal Credit Union’s adherence to operational, regulatory, and compliance requirements through coordinated risk assessments, compliance monitoring, and support of enterprise-wide risk and compliance... 
    Suggested
    Work at office

    Educational Federal Credit Union

    Miami, FL
    3 days ago
  •  ...Consulting team at Southcom HQ. Position: Risk and Compliance Analyst LCAT:  Mid Location: SOUTHCOM...  ...Bachelor's degree in Engineering, Information Systems, or a related field, or five...  ...the program adheres to relevant security, operational, and financial... 
    Temporary work
    Work at office
    Flexible hours

    Nalley Consulting

    Miami, FL
    6 days ago
  • Millennium is seeking a Compliance Analyst to support their global compliance program. This role involves high-level analysis, project management, and effective communication with various internal groups. Ideal candidates will have 2+ years in financial services compliance... 

    Millennium

    Miami, FL
    4 days ago
  •  ...Security, Risk and Compliance Consultant Miami, Florida, United States An SEI-er is a master communicator and active listener who understands...  ...in the following areas: Compliance Information Security Risk Management Data Privacy The ideal... 
    Permanent employment

    SEI

    Miami, FL
    3 days ago
  •  ...our unique company culture rewards self-starters and those who are committed to doing what is best for our customers.Brown & Brown's Risk Solutions team, formerly Beecher Carlson, is looking for an Account Manager to join the National Healthcare Practice.As an Account... 
    Work at office
    Remote work

    Brown & Brown

    Coral Gables, FL
    1 day ago
  •  ...best for our customers. Brown & Brown's Risk Solutions team, formerly known as Beecher Carlson, is looking for a Risk Analyst to join the National Healthcare Practice....  ...not limited to compilations of underwriting information and coverage placement, loss forecasting and... 
    Work at office

    Brown & Brown

    Coral Gables, FL
    12 days ago
  • $109.04k - $163.56k

     ...Sr Risk Analyst - KR07DE We’re determined to make a difference and are proud to be an insurance company that goes well beyond coverages and policies. Working here means having every opportunity to achieve your goals – and to help others accomplish theirs, too. Join our... 
    Temporary work
    Work at office
    3 days per week

    The Hartford

    Coral Gables, FL
    3 days ago
  •  ...Risk Management Analyst Lennar is one of the nation's leading homebuilders, dedicated to making...  ...audits of claim files and provide any information requested from within Lennar or...  ...for $1 Company Match up to 5%, helps secure their financial future, while Paid Parental... 
    Live in
    Work at office
    Local area

    Lennar

    Miami, FL
    2 days ago
  •  ...Security & Compliance Analyst Join the Nalley Consulting team at Southcom HQ. Position: Security & Compliance...  ...DoD IL-4/IL-5 security mandates, and Risk Management Framework (RMF) guidelines...  ...Security is required. Certified Information Systems Auditor (CISA), Certified... 
    Temporary work
    Work at office
    Flexible hours

    NALLEY CONSULTING, LLC

    Miami, FL
    4 days ago
  • $34 per hour

     ...benefits and a collaborative workplace where you can thrive. We are currently seeking a Business Risk Product Specialist to support our critical function focused on ensuring compliance with international cross-border and jurisdictional rules. Benefits Comprehensive... 
    Permanent employment
    Temporary work

    Russell Tobin

    Miami, FL
    1 day ago
  •  ...AR, Asheboro, NC, Johnson City, TN SUMMARY The Senior Risk Compliance Officer - BSA Systems develops, administers, and monitors anti...  .... The incumbent provides quality, accurate and timely information to internal BSA/AML management to ensure compliance risks are... 
    Work at office

    First Horizon Bank

    Hialeah Gardens, FL
    2 days ago
  • $95.4k - $119.2k

     ...Bachelor’s degree in Computer Science, Information Technology, Business Administration, or...  ...office position which requires the Data Analyst II to have the ability to operate computer...  ...$1 for $1 Company Match up to 5%, helps secure their financial future, while Paid Parental... 
    Work at office
    Local area

    Brown & Brown

    Doral, FL
    1 day ago
  •  ...Days On-Site) Type: Full-Time FLSA: Exempt Job Summary The Sr. Risk Analyst - Billing & Payments manages and optimizes an automated...  ...automate allotment re-onboarding and schedule adjustments in compliance with internal and 3rd-party guidelines. Billing Control Reporting... 
    Full time
    Work at office

    BMG Money

    Doral, FL
    1 day ago
  • $43k - $44.63k

     ...Field Risk Specialist DataScan's Risk Management Operations team is seeking Field Risk Specialists to support our growing North...  ...reconcile findings, document results, and ensure the accuracy of information captured in DataScan's mobile audit application. This position... 
    Temporary work
    Flexible hours
    Night shift

    DataScan

    Miami, FL
    1 day ago
  • $61.6k - $73.5k

     ...that’s why there’s nowhere like RSM. As a Risk Consulting Associate at RSM, you will...  ...of projects include internal audits, SOX/compliance work and financial reporting control...  ...intended to provide our clients with timely information on business operations and methods to... 
    Full time
    Work experience placement
    Summer work
    Local area

    RSM

    Coral Gables, FL
    13 hours ago
  •  ...About The Role As Félix expands nationwide, we are scaling our Credit Risk function from the ground up to support our new Consumer Lending division. We are looking for a Senior Credit Risk Analyst who lives and breathes data, portfolio mathematics, and lending dynamics... 
    Work at office
    Remote work

    Félix

    Miami, FL
    4 days ago
  • $84.74k - $138.67k

     ...Actuarial Analyst II Location: This role requires associates...  ...analyzes and models data including risk reporting and forecasting....  ...Plan Pricing Factors & Compliance Testing: Contribute to the development...  ..., ethnicity, genetic information, gender (including gender identity... 
    Temporary work
    Work experience placement
    Work at office
    Local area
    2 days per week
    1 day per week

    Elevance Health

    Miami, FL
    2 days ago
  • $89.83k - $170.21k

     ...Actuarial Analyst III Location: This role requires associates to be in-office 1-2 days...  ...an impact: Analyzes and implements risk contracts including conducting experience...  ..., creed, disability, ethnicity, genetic information, gender (including gender identity and... 
    Temporary work
    Traineeship
    Work experience placement
    Work at office
    Local area
    2 days per week
    1 day per week

    Elevance Health

    Miami, FL
    2 days ago
  •  ...industry-leading ability to understand risk, source efficient capital and rapidly pay...  ...a collaborative global team of pricing analysts and actuaries tasked with building a complete...  ...with the ability to explain technical information to different audiences ~ Strong... 
    Local area

    RenaissanceRe

    Miami, FL
    1 day ago
  • $91k - $321.5k

     ...At PwC, our people in risk and compliance focus on maintaining regulatory compliance and managing...  ...problems, and applying sound judgment to make informed decisions. Your role will involve...  ...these factors thoughtfully to establish a secure and trusted workplace for all.... 
    Contract work
    H1b

    PwC

    Miami, FL
    2 days ago
  •  ...and complex matters related to issues and requests for rulings pertaining to the requirements under the Employee Retirement Income Security Act of 1974 (ERISA), such as minimum funding standards, plan mergers and changes of actuarial funding methods. Prepare... 

    Treasury Department

    Miami, FL
    1 day ago
  •  ...- Employee Plans, Rulings & Agreement, Groups 7571 and 7572 Consider each location carefully when applying. If you are selected for a location, that location will become your official post of duty. REVIEW THE ADDITIONAL INFORMATION BELOW FOR FURTHER DETAILS... 

    US Government Jobs

    Miami, FL
    2 days ago
  •  ...leadership role responsible for building and leading GVW's enterprise risk capability across the group and its portfolio companies....  ...insurance strategy, and technology risk. It is not a traditional compliance or audit role. The focus is on enabling the business to grow... 
    Work at office

    GVW Group

    Miami, FL
    4 days ago
  • Arbol is a global climate risk coverage platform and FinTech company offering full-service solutions for any business looking to analyze...  ...are ultimately made by humans. If you would like more information about how your data is processed, please contact us. #J-18808-... 
    Full time
    Work at office
    Flexible hours

    Arbol

    Miami, FL
    13 hours ago
  • JOB TITLE: Senior Actuarial Analyst EMPLOYER: A-CAP Services LLC DEPARTMENT: Finance - Actuarial REPORTS TO: Chief Actuary LOCATION:...  ...partners. This commitment is demonstrated through the industry-leading risk-adjusted returns we achieve, and the innovative capital... 
    Full time
    Temporary work
    Work experience placement
    Immediate start
    Monday to Friday

    Acap

    Miami, FL
    4 days ago
  •  ...Lead Pricing Actuary - Cyber & Executive Risks Key Relationships Underwriters and...  ...People & Sustainability or assurance teams (compliance, risk, internal audit) either directly,...  ...Achievement and solution focused Analytical Information seeking Stakeholder focus Using... 
    Work at office
    Home office
    Flexible hours

    Beazley Management Limited

    Miami, FL
    2 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Information Security Risk & Compliance Analyst. Be the first to apply!