IT Data Privacy, Risk, and Compliance Analyst
Vacancy expired!
LaSalle Network is currently partnering with a client that is seeking an
IT Data privacy, Risk and Compliance Analyst. This is a hands-on position that involves working directly with IT and Business users. The individual in this position will take on a wide range of responsibilities in data privacy, vendor due diligence, security educational awareness, business continuity and IT risk management. This is a 6-month contract (possibilities for extension). IT Data privacy, Risk and Compliance Analyst Responsibilities:Data Privacy:- Responsible for designing, implementing, and maintaining IT privacy policies and procedures
- Monitor and identify for gaps with existing Company procedures and privacy-based requirements
- Monitor for the continuous adherence to the Company's Privacy Program's requirements
- Maintain the Company's personal data inventory
- Analyze and assess privacy considerations and risks for new and existing technology.
- Monitor and coordinate rights requests
- Ensure all externally facing web sites meet Compliance requirements as it relates to tracking personal data
- Coordinate third-party assessments of the Company's Privacy program
- Work with vendors to implement, validate and comply with privacy provisions as required by data protection laws and the Company's applicable policies and procedures, including those described in the Code of Ethics and Regulatory Compliance Manual, any privacy notices and/or any other IT-related policies and procedures
- Maintain the Company's Vendor Due Diligence policy
- Lead the Company's efforts with initial and ongoing vendor due diligence
- Coordinate the classification and tiering of vendors
- Coordinate updates associated with the Company's vendor management list tracking system
- Work with the CTO and Compliance to identify and select vendors for annual due diligence reviews
- Maintain the Company's Vendor Management system
- Evaluate and select questions appropriate for vendor due diligence reviews
- Review due diligence related questionnaires and perform vendor assessments\
- Document and review all vendor security breaches and report findings and analysis
- Responsible for making sure the Company complies with the Privacy Checklist for third-party agreements
- Ensure vendor incident response plans address contractual breach notification requirements
- Manages and leads cybersecurity awareness training
- Design, plan and execute ongoing phishing simulations
- Coordinate information security simulations of the Company's security incident response plan within IT
- Business Continuity and Disaster Recovery (BC/DR)
- Coordinate with Compliance and IT to ensure BC/DR requirements are met
- Coordinate updates to business-based BC/DR plans. (small piece of the role; 1-2 times per year)
- Assist with the planning and coordination of tabletop exercises
- Partner with the business to define and update internal recovery point and recovery time objectives
- Partner with third party technology providers to ensure recovery points and objectives are met
- Facilitate quarterly access reviews for applications with sensitive data
- Ensure completion of periodic IT operational responsibilities
- Perform ongoing internal IT testing of technology controls
- Ensure IT complies with various requirements defined in the Company's Information Security Policy
- Partner with IT team members to capture and document cybersecurity related risks
- Perform gap assessments between existing capabilities and desired capabilities based on Compliance or other required standards
- Coordinate reporting on security incidents related to users, computers, servers, and vendors
- At least 3 to 5 years' experience in IT risk and IT compliance related roles
- Effective at managing multiple projects and shifting priorities to meet business needs
- Experience gathering and interpreting risks and associated impacts
- Understanding of various risk and security certifications and attestations
- Familiarity with vendor management and governance concepts
- Experience with compliance and security auditing
- An appreciation and dedication to details
- Self-driven and able to thrive in a fast-paced environment
- Excellent verbal and written communication skills
- Financial services, or other regulated industry experience helpful
Vacancy expired!
Similar jobs
Psychosis Risk Outcomes Network Study