Position Name: Cyber security analyst GRC
Location: Walnut Creek , CA
Duration: long Term
JD:-
Summary
Leads and executes the IT CyberSecurity governance program. Performs Enterprise CyberSecurity risk assessments, including third party assessments for business initiatives. Coordinate and Manage 3rd Party Assessments/Audits include PCI and TQS #5. Leading Archer migration to ServiceNow for the GRC (Governance, Risk & Compliance) program.
Essential Functions
· Manage information technology security policy and standards change process including working with cross-functional SMEs to assess the impact of requested changes
· Identify gaps and conduct impact analysis of the existing information security policy frameworks in order to drive continual improvement
· Lead audits in areas of cybersecurity including the Payment Card Industry Digital Security Standard (PCI-DSS)
· Collaborate with Cross Functional teams in regards to Security Requirements in order to address risk
· Develop and oversee user IT security awareness and training programs company wide
· Identifying and articulating risk in terms of business impact and likelihood, as well as suggesting reasonable strategies for mitigation and or provide compensating controls
· Identify and coordinate changes to GRC module to meet CyberSecurity Risk Management direction
· Lead metrics and measures program which reports to leadership
Knowledge/Skills/Abilities
· Exceptional aptitude, attitude, and work ethic
· Excellent communication and organizational skills, including the ability to present options in business terms to both technical and business staff including executives.
· Technical Writing
· ServiceNow
· Knowledge of capability of third party risk assessment
· Able to Identify areas for automation and be able to map workflow
· Change Approval Board (CAB)
· Team lead to help with on-boarding, training and work distribution
· Detailed knowledge and experience working with PCI DSS and NIST Control Standards would allow you to hit-the-ground running
· Working knowledge of information security and computer network, server, database, and user access technologies
Education & Experience / Licenses & Certification
· Bachelor’s degree or equivalent experience in Information Technology or Risk Management
· 5 plus years working in a similar role
· Preferred Certifications: (PCI ISA, CRISC, CISSP, etc.).