Governance Risk Compliance (GRC) Analyst - Security Analyst

Job Details

  • ID#49398313
  • Address 33434 , Bocaraton,

    Florida

    Bocaraton USA
  • Job type

    Contract

  • Salary USD USD60 - USD75 60 - 75
  • Hiring Company

    Randstad Technologies

  • Showed04th March 2023
  • Date03rd March 20232023-03-03T00:00:00-0800
  • Deadline02nd May 2023
  • Category

    Et cetera

Governance Risk Compliance (GRC) Analyst - Security Analyst

job summary:

Job Summary: The management, assessment, and mitigation of risks are fundamental components of our information assurance and cyber security program. This position leads the IT security risk and audit program for information systems security using generally accepted standards and frameworks for IT audit and risk management (e.g., NIST, ISO, PCI, and ISACA). The position is responsible for the development and implementation of the IT security risk and audit strategy that perform information systems and business process risk assessments and evaluate the effectiveness of technical, physical, and administrative controls to identify control weakness. This individual will interface with the Security Operations, IT Operations, and various business units to: ? Perform PCI, ISO, COBIT, and applicable State of Florida cybersecurity controls-related reviews to ensure that current, new, and technology infrastructure complies with these standards and Department's security policies. ? Plan and perform IT security controls effectiveness quarterly reviews. Manage remediation efforts for the identified gaps including assessment of new or enhanced implemented controls. ? Maintain IT security risk and compliance matrix and performs management reporting. This will include IT systems controls, and business process risks to meet compliance requirements. Provide risk mitigation strategies. ? Maintain Third Party Risk Management Program (TPRM) and analyze SOC-2 and other reporting including mapping to key IT security and compliance controls such as NIST, PCI, and COBIT. ? Manage IT security vulnerabilities management program aligned with PCI and NIST standards. ? Identifying and ranking the value, sensitivity, and criticality of the operations and assets that could be affected should a threat materialize in order to determine which operations and assets are the most important. ? For the most critical and sensitive assets and operations, estimating the potential losses or damage that could occur if a threat materializes, including recovery costs. ? Identifying cost-effective actions to mitigate and reduce risk. These actions can include implementing new organizational policies and procedures as well as the design of technical or physical controls. ? Coordinating, tracking, and verifying remediation of audit findings. ? Documenting the results and developing a plan of action and milestones for mitigating any identified risk. ? Produce formal audit reports based on ISACA Audit Standards. ? Promotes compliance with regulatory requirements (e.g. PCI DSS) and IT best practices.

GRC Risk Analyst Skills & Requirements: ? 7-10 years of IT Audit experience (CISA certified preferred) ? 3 years of IT Risk Management lifecycle experience ? 3 years of hands-on technical experience (e.g. developer, system administrator) ? Experience working with NIST 800-30 Risk Assessment Standard ? Extensive experience with IT General Controls evaluation and design ? Advanced skill level in business process mapping and documentation as well as policy and procedure development ? Recent experience in Information Security with up-to-date knowledge of the current threat landscape. ? Solid understanding of PCI DSS standards

Education and Certifications: ? Bachelor's Degree in Computer Science, Information Systems, Business Administration, or other related field and/or equivalent work experience. ? CISA and CISSP certifications (preferred). location: Boca Raton, Floridajob type: Contractsalary: $60 - 75 per hourwork hours: 8am to 5pmeducation: No Degree Required responsibilities:

Job Summary: The management, assessment, and mitigation of risks are fundamental components of our information assurance and cyber security program. This position leads the IT security risk and audit program for information systems security using generally accepted standards and frameworks for IT audit and risk management (e.g., NIST, ISO, PCI, and ISACA). The position is responsible for the development and implementation of the IT security risk and audit strategy that perform information systems and business process risk assessments and evaluate the effectiveness of technical, physical, and administrative controls to identify control weakness. This individual will interface with the Security Operations, IT Operations, and various business units to: ? Perform PCI, ISO, COBIT, and applicable State of Florida cybersecurity controls-related reviews to ensure that current, new, and technology infrastructure complies with these standards and Department's security policies. ? Plan and perform IT security controls effectiveness quarterly reviews. Manage remediation efforts for the identified gaps including assessment of new or enhanced implemented controls. ? Maintain IT security risk and compliance matrix and performs management reporting. This will include IT systems controls, and business process risks to meet compliance requirements. Provide risk mitigation strategies. ? Maintain Third Party Risk Management Program (TPRM) and analyze SOC-2 and other reporting including mapping to key IT security and compliance controls such as NIST, PCI, and COBIT. ? Manage IT security vulnerabilities management program aligned with PCI and NIST standards. ? Identifying and ranking the value, sensitivity, and criticality of the operations and assets that could be affected should a threat materialize in order to determine which operations and assets are the most important. ? For the most critical and sensitive assets and operations, estimating the potential losses or damage that could occur if a threat materializes, including recovery costs. ? Identifying cost-effective actions to mitigate and reduce risk. These actions can include implementing new organizational policies and procedures as well as the design of technical or physical controls. ? Coordinating, tracking, and verifying remediation of audit findings. ? Documenting the results and developing a plan of action and milestones for mitigating any identified risk. ? Produce formal audit reports based on ISACA Audit Standards. ? Promotes compliance with regulatory requirements (e.g. PCI DSS) and IT best practices.

GRC Risk Analyst Skills & Requirements: ? 7-10 years of IT Audit experience (CISA certified preferred) ? 3 years of IT Risk Management lifecycle experience ? 3 years of hands-on technical experience (e.g. developer, system administrator) ? Experience working with NIST 800-30 Risk Assessment Standard ? Extensive experience with IT General Controls evaluation and design ? Advanced skill level in business process mapping and documentation as well as policy and procedure development ? Recent experience in Information Security with up-to-date knowledge of the current threat landscape. ? Solid understanding of PCI DSS standards

Education and Certifications: ? Bachelor's Degree in Computer Science, Information Systems, Business Administration, or other related field and/or equivalent work experience. ? CISA and CISSP certifications (preferred). qualifications:
  • Experience level: Experienced
  • Minimum 7 years of experience
  • Education: No Degree Required (required)
skills:
  • SECURITY ANALYST
  • SECURITY
  • SECURITY ENGINEER
  • Network Security
  • Equal Opportunity Employer: Race, Color, Religion, Sex, Sexual Orientation, Gender Identity, National Origin, Age, Genetic Information, Disability, Protected Veteran Status, or any other legally protected group status.At Randstad, we welcome people of all abilities and want to ensure that our hiring and interview process meets the needs of all applicants. If you require a reasonable accommodation to make your application or interview experience a great one, please contact HRsupport@randstadusa.com. Pay offered to a successful candidate will be based on several factors including the candidate's education, work experience, work location, specific job duties, certifications, etc. In addition, Randstad offers a comprehensive benefits package, including health, an incentive and recognition program, and 401K contribution (all benefits are based on eligibility). For certain assignments, Covid-19 vaccination and/or testing may be required by Randstad's client or applicable federal mandate, subject to approved medical or religious accommodations. Carefully review the job posting for details on vaccine/testing requirements or ask your Randstad representative for more information.

    Apply This Job

    Similar jobs

    Governance Risk Compliance (GRC) Analyst - Security Analyst

    Randstad Technologies - Governance Risk Compliance (GRC) Analyst - Security Analyst

    Governance Risk Compliance (GRC) Analyst - Security Analyst

    Randstad Technologies - Governance Risk Compliance (GRC) Analyst - Security Analyst

    Data Analyst- Risk and Analytics

    FlexShopper, LLC - Data Analyst- Risk and Analytics