Info Sec Governance Risk and Compliance Analyst Sr

Location US-CA-Valencia (HQ)
ID 2024-1133
Category
Technology
Position Type
Full-Time
Remote
No

Overview

The Info Sec Governance Risk and Compliance Analyst Sr will lead the development and implementation of the InfoSec Governance, Risk & Compliance (GRC) programs. Lead the coordination of security compliance efforts, risk assessment and mitigation, third party risk management, and overall security policy governance. 

Responsibilities

Lead the strategic design and execution of a comprehensive security risk and compliance program for the organization.
 
Develop, review, communicate and maintain Information Security policies, standards and procedures that support security best practices. Serves as a subject matter expert for information security and compliance policies and procedures.
 
Provide leadership and direction for the ongoing monitoring of the organization's security posture and identify potential risks, threats and vulnerabilities.
 
Lead ongoing third-party due diligence, risk tracking and monitoring, and coordinate efforts to address security concerns or requirements.
 
Lead interactions with external auditors to ensure compliance with industry regulatory requirements and standard.
 
Perform regular risk assessments to address security threats, changes to systems and/or applications, process improvement initiatives, third-party provider assessments and other related business needs.
 
Coordinate remediation efforts to mitigate internal/external information technology and security related audit findings.
 
Maintain accurate reporting of mitigation and remediation activities to bring appropriate visibility to stakeholders and leadership.
 
Prepare and present executive-level reports regarding the organization's security and compliance status.
 
Lead and facilitate the enterprise security awareness program, including development of custom materials when needed.
 
Develop reporting metrics, dashboards and evidence of risk management and compliance activities.
 
Stay updated on the latest security trends, emerging threats and best practices to continuously improve the overall security posture.
 
Provide leadership and mentoring for a team of GRC analysts.
 
Carries out other responsibilities as assigned by their manager

Qualifications

Education

 

Education Level:  

Minimum: 4 Year / Bachelors Degree 

Preferred: Graduate Degree      

       

Description:

 

Minimum: Bachelor’s degree in computer science, Information Systems, Information Security/Assurance, or related field.

Preferred: Master's degree in computer science, Information Systems, Information Security/Assurance, or related field.

Preferred: Professional certifications in Information Security, Risk Management and/or Compliance (such as CISA, CGEIT, CISM, CRISC, CISSP, CRISC etc.) preferred.

 

Experience

 

Minimum Years of Experience: 8

Preferred Years of Experience: 10

Comments: Minimum of 8 years of relevant experience in Information Security Compliance, Technology Risk Management and/or Auditing 

 

 

Knowledge, Skills & Ability
 
Excellent knowledge of regulatory rules, standards and best practices that govern information security in the financial services industry, such as FFIEC/NCUA.
 
Excellent knowledge and extensive experience with facilitating information security and risk management standards, practices, methods, frameworks including NIST, PCI, ISO 27001, FAIR, OCTAVE etc.
 
Prior experience with developing security policies, standards, and controls definition across multiple security compliance frameworks
 
Previous management consulting experience, preferred.
 
Strong interpersonal skills and ability to effectively communicate, both written and verbally, with a broad range of stakeholders
 
Excellent presentation, facilitation, executive reporting, and communication skills

Corporate Values

• Practice open Communication with all levels;

• Be Accountable by taking ownership of customer issues and responsibility for one’s actions;

• Foster Teamwork by cooperating and collaborating with other employees;

• Seek ways to make the workplace Fun for oneself & others;

• Conduct oneself with Integrity by being honest, trustworthy and ethical in all work activities and interactions;

• Work with a Service Orientation by having a genuine concern for the needs of one’s customers and by being friendly, professional and following through on commitments; and

• Demonstrate Humility in all interactions and remember to leave one’s ego at the door when one arrives to work.

Disclaimer

Logix Federal Credit Union is an equal opportunity employer that does not discriminate in employment opportunities or practices on the basis of race, religion, color, sex, sexual orientation, gender identity, national origin, protected veteran or disability status, or any other status protected by law.

Pay Range

USD $107,712.94 - USD $166,955.06 /Yr.

Options

Sorry the Share function is not working properly at this moment. Please refresh the page and try again later.