How Remoteville checks and expires listings

Sr. Analyst Governance Risk and Compliance

Skills
Business ContinuityCritical ThinkingData PrivacyInformation Security GovernanceNIST 800-53Payment Card Industry Data Security StandardPresentations
Role

What the job involves

The main requirements, responsibilities and hiring steps.

Requirements

  • Expertise in Information Security Governance Risk and Compliance
  • Expertise in IT SOX ITGC Technology Risk Internal Controls
  • Expertise in Payment Card Industry Data Security Standard (PCI-DSS)
  • Experience with information security controls frameworks NIST 800-53 ISO27001 PCI-DSS
  • Highly preferred experience in Data privacy and protection (GDPR CCPA/CPRA)
  • Familiarization with information security risk assessment methodologies
  • Experience in assessing security risks in cloud services (SaaS PaaS IaaS) technologies and validating controls around full technology stack
  • Expertise in technical business environment familiarity with security standards and experience with business continuity disaster recovery risk management vulnerability assessments and cyber-security
  • Ability to facilitate corrective action at all levels of the organization
  • Strong communication critical thinking interpersonal and formal presentation skills
  • Minimum of 4 years in Information Security Governance Risk and Compliance role
  • Legal right to work in the United States

Nice to have

  • GDPR
  • Security Standards
  • CCPA

Day to day

  • Creating and rolling out Information Security policies and standards
  • Aligning security requirements with business objectives and security compliance frameworks
  • Managing the enterprise information security controls framework and working with global stakeholders on policies and standards
  • Leading the IT SOX and technology internal controls program
  • Assisting in the Payment Card Industry (PCI-DSS) compliance program including technical controls implementation and liaising with PCI QSA auditors
  • Leading PCI compliance objectives and ensuring teams are prepared for assessments
  • Implementing solutions for data privacy regulations to protect sensitive information
  • Identifying risks with business units and tracking risk mitigation plans
  • Supporting development of metrics for Information Security risk management reporting
  • Assisting in the implementation of governance and risk management solutions
  • Participating in Third-Party Risk Assessment of vendors
  • Contributing to the development and maintenance of Disaster Recovery and Business Continuity Plans

Hiring process

  • Assessment or selection process
  • Accommodations upon request