Senior GRC Analyst
Role details
Job location
Tech stack
Job description
We are seeking a skilled and experienced Senior GRC Analyst, to join the Governance, Risk, and Compliance (GRC) team. The Senior GRC Analyst will be a key member of TE Connectivity's GRC team, working within the TE Information Solutions (TEIS) department to strengthen our cybersecurity posture and risk management framework. This role combines strategic leadership with hands-on execution, focusing on the development and implementation of comprehensive GRC strategies that align with business objectives and drive innovation across the organization. The Senior GRC Analyst will lead the execution and coordination of IT security governance, risk, and compliance processes, ensuring adherence to a wide range of global government and industry regulations and standards.
Role also available in Czech Republic, Poland and Spain Your main tasks:
- This individual will focus on the execution and coordination of IT security governance, risk and compliance processes related to a broad range of global government and industry regulations and requirements.
- Lead IT control testing and gap analysis in support of TE's information security programs and compliance efforts, including Sarbanes Oxley (SOX), EU NIS2, UK CyberEssentials, the US Defense Federal Acquisition Regulation Supplement (DFARs) 7012 & Cybersecurity Model Maturity Certification (CMMC).
- Work with business and technical groups to assess IT risks, recommend enhanced governance and controls, perform self-assessments and recommend improvements in control design.
- Create and maintain documentation regarding TE's security and operational controls to support audits and certifications.
- Oversee and govern security controls that should meet TE global IT policy and regulatory requirements.
- Perform and update IT risk assessments, maintain governance repositories and documentation and leverage security metrics to track progress.
- Ensure data subject to regulations and advanced protection requirements are safeguarded during M&A & IT transformation activities.
- Work with corporate and BU Legal teams to ensure alignment on cyber risk reporting requirements, customer contractual requirements and serve as a point person for segment and BU CIOs.
- Identify gaps in the design and operating effectiveness of controls and identify improvements that reduce risk and/or align TE with industry recognized internal control frameworks.
- Complete security assurance questionnaires from internal and external stakeholders, including customers and cyber-insurers.
Requirements
- General knowledge of information security and controls and related technologies, including identity & access management; database, operating system, and network security; endpoint security; application security; data protection and leakage; vulnerability management; security logging and monitoring.
- Familiarity with regulations relevant to IT security and compliance for a public, global manufacturing company (e.g. SOX, PCI, HIPAA, US and international privacy regulations; US and international cybersecurity regulations and export restrictions such as DFARS, ITAR and UKML) and/or Controls Frameworks (e.g., COSO, COBIT, NIST, ISF Standards of Good Practice, ISO 27001); and industry or regionally specific certifications (e.g., TISAX; UK CyberEssentials).
- Experience with any of the following is a plus: manufacturing and OT/ICS systems; support of or experience with Risk Management Systems (e.g. Archer or others), IT audit; governance for IT outsourcing; risk management frameworks; and Kaizen/lean methodologies.
- Ability to track and manage numerous parallel activities.
- Ability to identify opportunities for continuous improvement and execute on them.
- Ability to work efficiently and independently with minimal supervision (i.e., self-motivated, and willing to stretch to meet important deadlines).
- Ability to work successfully in a cross-functional team environment.
- Bachelor's degree (High School +4 years)
- Active security certification (CISSP, CISM, CRISC or CISA) or equivalent is a plus
- Years of experience: 4 - 7 years or more
Benefits & conditions
Employee stock purchase plan, 401(k), Health insurance, Paid time off, Life insurance, Disability insurance, * Competitive base salary commensurate with experience: $133,000-166,200 (subject to change dependent on physical location)
- Posted salary ranges are made in good faith. TE Connectivity reserves the right to adjust ranges depending on the experience/qualification of the selected candidate as well as internal and external equity.
- Total Compensation = Base Salary + Incentive(s) + Benefits, * A comprehensive benefits package including health insurance, 401(k), disability, life insurance, employee stock purchase plan, paid time off and voluntary benefits.