Please scroll down, To apply

Governance Risk and Compliance Analyst

hiring now
New job

Rose International

2024-10-02 09:40:06

Job location Memphis, Tennessee, United States

Job type: fulltime

Job industry: I.T. & Communications

Job description

Schedule: M-F, 8:00AM-5:00PM

3 day minimum in WFO (remote candidates will NOT be considered)

Screening Questions (Please add to the top of the resume)

Please describe your experience with third-party risk assessments and the methodologies used.

Please describe your experience reviewing and evaluating security attestations documents such as PCI DSS, SOC 2 Type II, ISO 27001, etc.

Description:

  • Governance Risk and Compliance (GRC) Analyst will support key functions in the development, implementation, and maintenance of the organization's GRC program, including planning and implementing policies, procedures, standards, and controls to govern the protection and privacy of corporate information systems, networks, data and third-party risk reviews. In this role, you will have the opportunity to support strategic and innovative company initiatives through technological solutions.

  • Requires thorough knowledge of information security practices and technologies; ability to speak and write in a clear and understandable manner for internal and external relations; understand extremely complex verbal or written instructions; understand information security issues dealing with computer hardware, software, and infrastructure.

    Essential Job Functions

  • Work in the Information Security lab and work with a close team of analysts, engineers, and architects to mature the Information Security department and protect the organization and its donors.

  • Analyzes and monitor enterprise information security systems and reports all suspicious activity. Requires use of a personal computer.

  • Operates in an unbiased manner, maintaining confidentiality and integrity with all information security events.

  • Manage third-party vendor risk assessments while collaborating with internal and external teams.

  • Have a strong risk and audit mindset with experience in interpreting and assessing controls using compliance frameworks such as ISO 27001, SOC 2, PCI DSS, and others.

  • Collaborate on building out an improved third-party risk management program.

  • Provides analysis of information security processes and tools recommending innovative solutions for enhancing processes, toolsets, and policies.

  • Stay up to date on industry trends and best practices by continuously learning and adapting the security program to address evolving threats.

  • Measure and report on performance by tracking key metrics (KPIs/KRIs), identifying areas for improvement, and reporting to the GRC leader and other stakeholders.

  • Assist with training personnel on information security issues. Knowledge ordinarily acquired through attainment of a bachelor's degree in business or information systems plus 3 years of progressive information security experience. Information security certification preferred. If no degree, must show extensive years of experience.

    Additional Recruitment Details & Screening Questions

  • Top Skills Preferred in order of preference

  • Have a strong risk and audit mindset with experience in third-party risk assessments interpreting and assessing controls using compliance frameworks such as ISO 27001, SOC 2, PCI DSS, and others.

  • Collaborate on building out an improved third-party risk management program by owning & reporting on performance by tracking key metrics (KPIs/KRIs).

  • GRC/Vendor Management tool experience like OneTrust, Tugboat, Archer, BitSight, Security Scorecard, etc.

  • Examples of daily assignments or duties this contractor would be responsible for supporting

  • Manage and execute on vendor third party risk assessments & reporting. Collaborating with internal teams and external vendors driving success for GRC program.

  • Effectively managing a dynamic schedule of vendor engagements and assessments while analyzing for any security concerns that may impact CLIENT.

  • Operate in CLIENT's GRC toolset providing daily updates for the downstream use for the entire team.

  • Measure and report on performance by tracking key metrics, identifying areas for improvement, and reporting to the GRC leader and other stakeholders.

    • Only those lawfully authorized to work in the designated country associated with the position will be considered.

    • Please note that all Position start dates and duration are estimates and may be reduced or lengthened based upon a client's business needs and requirements.

  • Benefits:

    For information and details on employment benefits offered with this position, please visit here . Should you have any questions/concerns, please contact our HR Department via our secure website .

    California Pay Equity:

    For information and details on pay equity laws in California, please visit the State of California Department of Industrial Relations' website here .

    Rose International is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, age, sex, sexual orientation, gender (expression or identity), national origin, arrest and conviction records, disability, veteran status or any other characteristic protected by law. Positions located in San Francisco and Los Angeles, California will be administered in accordance with their respective Fair Chance Ordinances.

    If you need assistance in completing this application, or during any phase of the application, interview, hiring, or employment process, whether due to a disability or otherwise, please contact our HR Department .

    Rose International has an official agreement (ID ), effective June 30, 2008, with the U.S. Department of Homeland Security, U.S. Citizenship and Immigration Services, Employment Verification Program (E-Verify). (Posting required by OCGA 13/10-91.).

    Inform a friend!

    <!– job description page –>
    Top