Remote Jobs
Governance, Risk and Compliance Analyst Senior
What's your preference?
Job Description
- Req#: JR153225
- Lead the execution and reporting of outcomes derived from Third Party Risk Assessments.
- Manage the completion of risk and vulnerability assessments, validation testing, compliance reviews, and audits in accordance with NIST and HITRUST standards.
- Manage and monitor a central repository for all security risks and audit evidence.
- Maintain security standards, policies, and practices on an annual basis to make sure they meet organizational and regulatory requirements.
- Manage a security awareness training program in order to educate associates about security compliance standards, risk management practices, and ethical behavior.
- Collaborate with legal and compliance teams to ensure policies and security controls align with regulatory requirements.
- Conduct internal audits to assess the effectiveness of security controls and identify areas for improvement.
- Performs other duties as assigned.
- Required: Bachelor's Degree and/or equivalent experience.
- Required: 7 years
- Required: Certified Information Security Manager (CISM) certification.
Information Systems
Excited to grow your career?
We value our talented employees, and whenever possible strive to help one of our associates grow professionally before recruiting new talent to our open positions. If you think the open position you see is right for you, we encourage you to apply!
Our people make all the difference in our success.
The Governance, Risk & Compliance (GRC) Analyst - Senior will collaborate with process owners, internal auditors, external auditors, and other stakeholders in order to assist in reviewing, monitoring, and resolving cybersecurity risk. This includes helping the organization manage HITRUST, HIPAA and NIST Common Security Framework (CSF) audits and attestations. By supporting the implementation of internal and external assessments, responding to and managing the full lifecycle of compliance audits, and ensuring compliance with existing and emerging regulations and standards including SOC2, ISO 27001, PCI-DSS, SOX, and other GRC activities, the Principal GRC Analyst will also contribute to managing the organization's IT compliance program.
Essential Job Function:
Education:
Experience:
Licensure/Certification/Listing:
Work Shift :
Days/No Weekends (United States of America)
On Call Required
No
FTE:
1
Job Type:
Full Time (40 Hours/Week)About the company
The best remote jobs for you
Notice
Talentify is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or protected veteran status.
Talentify provides reasonable accommodations to qualified applicants with disabilities, including disabled veterans. Request assistance at accessibility@talentify.io or 407-000-0000.
Federal law requires every new hire to complete Form I-9 and present proof of identity and U.S. work eligibility.
An Automated Employment Decision Tool (AEDT) will score your job-related skills and responses. Bias-audit & data-use details: www.talentify.io/bias-audit-report. NYC applicants may request an alternative process or accommodation at aedt@talentify.io or 407-000-0000.