How Remoteville checks and expires listings
Sr. Analyst Governance Risk and Compliance
Skills
Business ContinuityCritical ThinkingData PrivacyInformation Security GovernanceNIST 800-53Payment Card Industry Data Security StandardPresentations
What the job involves
The main requirements, responsibilities and hiring steps.
Requirements
- Expertise in Information Security Governance Risk and Compliance
- Expertise in IT SOX ITGC Technology Risk Internal Controls
- Expertise in Payment Card Industry Data Security Standard (PCI-DSS)
- Experience with information security controls frameworks NIST 800-53 ISO27001 PCI-DSS
- Highly preferred experience in Data privacy and protection (GDPR CCPA/CPRA)
- Familiarization with information security risk assessment methodologies
- Experience in assessing security risks in cloud services (SaaS PaaS IaaS) technologies and validating controls around full technology stack
- Expertise in technical business environment familiarity with security standards and experience with business continuity disaster recovery risk management vulnerability assessments and cyber-security
- Ability to facilitate corrective action at all levels of the organization
- Strong communication critical thinking interpersonal and formal presentation skills
- Minimum of 4 years in Information Security Governance Risk and Compliance role
- Legal right to work in the United States
Nice to have
- GDPR
- Security Standards
- CCPA
Day to day
- Creating and rolling out Information Security policies and standards
- Aligning security requirements with business objectives and security compliance frameworks
- Managing the enterprise information security controls framework and working with global stakeholders on policies and standards
- Leading the IT SOX and technology internal controls program
- Assisting in the Payment Card Industry (PCI-DSS) compliance program including technical controls implementation and liaising with PCI QSA auditors
- Leading PCI compliance objectives and ensuring teams are prepared for assessments
- Implementing solutions for data privacy regulations to protect sensitive information
- Identifying risks with business units and tracking risk mitigation plans
- Supporting development of metrics for Information Security risk management reporting
- Assisting in the implementation of governance and risk management solutions
- Participating in Third-Party Risk Assessment of vendors
- Contributing to the development and maintenance of Disaster Recovery and Business Continuity Plans
Hiring process
- Assessment or selection process
- Accommodations upon request
