Apply

GRC Analyst

Posted 3 months agoViewed

View full description

💎 Seniority level: Middle, 3+ years

📍 Location: United States

💸 Salary: 70000.0 - 90000.0 USD per year

🔍 Industry: Media and Entertainment

🗣️ Languages: English

⏳ Experience: 3+ years

🪄 Skills: CybersecurityRisk Management

Requirements:
  • 3+ years experience in Information Security
  • Bachelor's degree in Computer Science or related field
  • Technical Cyber Security Certification
  • Understanding of security, risk and privacy regulatory frameworks
Responsibilities:
  • Manage supplier security risk assessments from initiation to completion
  • Generate risk assessment reports
  • Communicate remediation importance
  • Support monitoring of remediation efforts
Apply

Related Jobs

Apply
🔥 GRC Analyst II
Posted 8 days ago

📍 United States

💸 110000.0 - 130000.0 USD per year

🔍 Insurance

🏢 Company: joinroot

  • 3+ years of experience in executing information security risk management activities, including risk assessment, response, and monitoring processes
  • Proficient in information security control frameworks, standards, and regulations (such as NIST CSF, PCI DSS, and insurance data security laws or similar)
  • In-depth experience designing and evaluating controls to reduce information security risk
  • Excellent problem solving skills and attention to detail
  • Experience developing reports and metrics including data analysis and data visualization
  • Self-motivated; naturally collaborative, ability to influence without direct authority
  • Proven ability to balance security with the ongoing needs of the business while maintaining compliance and meeting risk management requirements
  • Active security certification (CISM, CISSP, CIA, CISA, etc.) preferred
  • Familiarity with applying security controls in public cloud environments (e.g. AWS)
  • Contribute to the ongoing development and maturation of Root’s information security risk management processes to appropriately manage risk in alignment with the organization's risk appetite and continuously monitor the risk landscape/control environment
  • Aid in conducting risk assessments across the organization, working with a variety of teams/functions to identify, evaluate, and mitigate risks
  • Support compliance with Root’s information security regulatory requirements, performing readiness assessments, ensuring policies and controls adequately address relevant requirements, reporting on Root’s compliance status, and tracking remediation efforts as necessary
  • Assist in the ongoing development and management of Root’s information security control framework
  • Perform analysis of the information security control environment to monitor effectiveness, identify gaps, and inform compliance reporting
  • Coordinate issue management/risk mitigation activities, collaborating with teams across the organization to manage and track remediation efforts to completion
  • Maintain information security policies and standards
  • Support control design and effectiveness testing of information security controls
  • Coordinate the reporting of key metrics related to the control environment
  • Aid in responding to regulatory exams and other third-party audits
  • Contribute to the creation of a risk-aware culture and advocate for applying risk management practices and a risk-based approach to security

AWSSQLCloud ComputingCybersecurityData AnalysisREST APIComplianceJSONRisk ManagementData visualization

Posted 8 days ago
Apply
Apply
🔥 Cybersecurity GRC Analyst
Posted about 1 month ago

📍 US, UK, Ireland, Poland, Germany

🧭 Full-Time

💸 180000.0 - 230000.0 USD per year

🔍 Ecommerce, livestream shopping

🏢 Company: Whatnot👥 251-500💰 $260,000,000 Series D over 2 years agoInternetMarketplaceE-CommerceInformation TechnologyTrading PlatformCollectibles

  • A minimum of 8+ years of relevant experience in security governance, risk, and compliance, preferably in a tech startup environment.
  • A Bachelor’s degree in Computer Science, Information Security, or a related field.
  • Deep knowledge of security best practices and industry standards, such as ISO 27001, SOC2, PCI, and GDPR/CCPA.
  • Experience at a Big 4 firm or similar reputable audit firm.
  • Experience in supporting complex third party audit projects in a cloud centric environment.
  • Excellent written communication skills with the ability to document, communicate, and report security assessments and the effectiveness of cybersecurity controls.
  • Reviewing and implementing secure configurations across various tools like Okta, Terraform, AWS, Lumos, Cloudflare, and Github.
  • Developing security requirements for partner teams and driving progress towards the execution of those requirements.
  • Preparing for and running external security audits.
  • Shaping the strategic direction of the Security GRC team.

AWSCybersecurityTerraformDocumentationComplianceRisk Management

Posted about 1 month ago
Apply