Trust Analyst II
New
A
Abnormal AICybersecurity SaaS
Remote - USAFull-TimeMiddle
SalaryBase salary range: $114,800 — $165,000 USD
Apply NowOpens the employer's application page
Job Details
- Experience
- 4-7 years of experience in cyber security, technology risk, GRC, and/or technical compliance roles, with at least 2 years focused on ISO 27001 implementation and maintenance
- Required Skills
- Project ManagementServiceNow
Requirements
- Have 4-7 years of experience in cybersecurity, technology risk, GRC, and/or technical compliance roles.
- Have at least 2 years focused on ISO 27001 implementation and maintenance.
- Have led at least one full ISO 27001 certification cycle, including the 2022 revision, from start to finish.
- Have project management experience across concurrent compliance projects, cross-functional teams, and competing deadlines.
- Have experience with Agile or Waterfall project management methodologies and tools such as ServiceNow.
- Have experience owning or facilitating cross-functional governance programs or committees.
- Understand ISMS implementation and maintenance, control mapping across frameworks, and continuous control monitoring and automation.
- Have experience implementing and managing ISO 27001 and ISO 27701 compliance programs, including Statements of Applicability, risk treatment plans, risk acceptance criteria, internal audits, and management reviews.
- Have a proven track record working with external auditors and managing internal stakeholders.
- Have experience with audit automation and continuous control monitoring tools.
- Be able to manage multiple stakeholders and vendors while maintaining project momentum.
- Preferred: bachelor's degree or equivalent military experience, relevant auditor or professional certifications, and familiarity with NIST or AI governance frameworks.
Responsibilities
- Own and run governance committees, including AI Governance, Data Governance, and Security Governance, setting agendas, facilitating stakeholders, and driving decisions to closure.
- Draft, revise, and maintain policies, drive stakeholder review and acknowledgment, and manage the company’s Policy Center.
- Manage risk operations, including the risk register, risk assessments, and risk exceptions.
- Monitor internal control effectiveness, implement control enhancements, and advise on control design and operations.
- Perform compliance readiness assessments and provide recommendations and roadmaps to senior management and business partners.
- Advise, educate, and train process, control, and risk owners on their responsibilities and related processes.
- Identify policy and process gaps, and drive remediation and risk mitigation plans with internal business partners.
- Keep current with regulatory and industry developments and advise leadership on potential program impacts.
- Communicate control testing, audit, risk assessment, issue management, and program status to partners and senior management.
View Full Description & ApplyYou'll be redirected to the employer's site