Sr GRC Analyst
Role details
Job location
Tech stack
Job description
The Sr GRC Analyst plays a key role in supporting the organizations governance, risk, and compliance program by leading complex risk assessments, advising stakeholders on security and compliance matters, and contributing to risk management strategy. This role evaluates security controls, supports audits and regulatory initiatives, and assists in the development and refinement of policies, standards, and procedures. The Sr GRC Analyst partners with business, technical, and compliance teams to identify, analyze, and mitigate information security risks while promoting a culture of security and accountability. Through use of GRC tools and continuous professional development, the role strengthens the organizations security posture and supports strategic risk management initiatives.
Requirements
Degrees / Work Experience / School Education: Bachelor's Degree in Information Systems, Business Management (And) Five (5) Years Work Experience of related industry experience (business).
(Or)
High School Diploma GED (And) Nine (9) Years Work Experience related industry experience (business).
(And)
Certified Information Privacy Professional (Or) Cert IS Auditor (Or) Cert IS Manager (Or) Cert Info Sys Security Prof (Or) Certified in Risk and Information Systems Control (Or) Global Information Assur Cert (Or) HealthCare IS and Privacy Practitioner. One must be obtained within 12 months of accepting position.
Communication Skills: Exceptional Verbal (Public Speaking) Writing/Correspondence
Proficiencies: MS Word Personal Computer
Job Attributes
Knowledge/Skills/Abilities: Analytical Abilities
Work Schedule: Eligible for Telecommute
Other Requirements: Knowledge of HIPAA Security rule, HITECH, Payment Card Industry (PCI). Previous IT audit experience, or equivalent combination of education and experience. Previous experience with ServiceNow and PowerBi preferred. Ability to evaluate, review and report on a range of information systems and applications to include' EPIC, Windows, Unix, IBM, Cisco