Security Risk & Compliance Analyst
Insight Global
Job Description
To exceed the expectations of our talented, creative partners, we need highly motivated, customer focused professionals who are inspired by finding new ways to deliver world class cybersecurity capabilities. This role is part a Cybersecurity team that is responsible for validating our content creation and delivery platforms, services, applications, workflows, and websites are designed and implemented to the highest security standards. You will be responsible for assisting in remediation planning and execution support, Third Party risk assessment, controls exception and risk acceptance reporting.
Your role:
- Coordinate with the client's applications, database, and infrastructure teams to develop
appropriate remediation activities and associated timelines for resolution of compliance
including Management Audit related gaps by:
- Developing appropriate remediation plans and related timelines for the client's review and
approval.
- Driving the relevant remediation plans to completion.
- Monitoring and adjusting remediation plans throughout the remediation cycle so that
established milestones are more likely to be met.
- Working with application, database, and infrastructure teams to gather evidence
reasonably required for the completion of remediation plans.
- Tracking and communicating to management known open compliance and management
audit gaps and action plans.
- Identifying issues warranting escalation to management and providing services to assist Cybersecurity and Risk team to resolve such issues.
- Support Third Party risk assessment processes by:
* Review intake requests to understand business use case and initial vendor impact
* Schedule kick-off meeting with business owner / requestor and vendor contact
* Send and review questionnaire responses and artifacts
* Analyze and identify any potential impact or deficiencies
* Communicate gaps and findings with stakeholders to identify any mitigating controls or
remediation plans.
* Monitor for any necessary vendor reassessments
- Collaborate with the Application Security team for any testing and review applicable to
vendor application / service.
- Provide support in documenting control exceptions;
* Review and analyze the exception request and validate that it is in security scope
* Work with application owner(s) to understand context and mitigating controls
* Document and capture review and conclusions
* Share with the security management for peer review and communication
* Inform the Security Risk team
We are a company committed to creating diverse and inclusive environments where people can bring their full, authentic selves to work every day. We are an equal opportunity/affirmative action employer that believes everyone matters. Qualified candidates will receive consideration for employment regardless of their race, color, ethnicity, religion, sex (including pregnancy), sexual orientation, gender identity and expression, marital status, national origin, ancestry, genetic factors, age, disability, protected veteran status, military or uniformed service member status, or any other status or characteristic protected by applicable laws, regulations, and ordinances. If you need assistance and/or a reasonable accommodation due to a disability during the application or recruiting process, please send a request to HR@insightglobal.com .
To learn more about how we collect, keep, and process your private information, please review Insight Global's Workforce Privacy Policy: https://insightglobal.com/workforce-privacy-policy/ .
Skills and Requirements
- Bachelors degree in Computer Information Systems, computer science or an equivalent
combination of education, training, and years of experience
- 3 to 5 years of cybersecurity and risk management experience and proven experience in
supporting IT audit/compliance functions
- Thorough understanding of ITGC, NIST, CIS standards
- Highly organized and efficient.
- Interpersonal skills with the ability to work with teams cross-functionally
- Must be a strong communicator to technical and non-technical audiences including developers
and tech operators
- Detail-oriented but able to understand the big picture
- Ability to navigate through ambiguity, manage and coordinate multiple project assignments
simultaneously in a fast-paced, deadline-driven environment, accepting ownership and
accountability of the process and deliver on commitments
- Experience and knowledge of GRC tools and systems
- Project Tracking/Reporting Tools: JIRA & SmartSheet null
We are a company committed to creating diverse and inclusive environments where people can bring their full, authentic selves to work every day. We are an equal employment opportunity/affirmative action employer that believes everyone matters. Qualified candidates will receive consideration for employment without regard to race, color, ethnicity, religion,sex (including pregnancy), sexual orientation, gender identity and expression, marital status, national origin, ancestry, genetic factors, age, disability, protected veteran status, military oruniformed service member status, or any other status or characteristic protected by applicable laws, regulations, andordinances. If you need assistance and/or a reasonable accommodation due to a disability during the application or the recruiting process, please send a request to HR@insightglobal.com.
Confirm your E-mail: Send Email
All Jobs from Insight Global