Cyber GRC Analyst

News Corporation
Austin, TX, United States
about 1 month ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
3 years minimum
Compensation
$80,000.0 - $110,000.0
Working hours
Regular working hours
Job source

Tech stack

Amazon Web Services Cloud Computing Control Objectives for Information and Related Technology (COBIT) Cyber Security Information Systems PCI Data Security Standards Information Technology

Job description

As a GRC analyst your roles will support and maintain the Realtor.com Cyber GRC Program

along with the BISO and central GRC function, including the development, implementation

and maintenance of cyber security policies, standards, guidelines and processes to ensure

compliance is maintained and risk is managed.

What’s the role?

  • Work with key internal and external stakeholders to ensure compliance with PCI

DSS, Privacy and GDPR compliance requirements, audits and assessments.

  • Assist in the risk assessment process and report on enterprise-wide and third-party

security controls

  • Support in the implementation of key security initiatives across the organisation

  • Support management of audits, external assessments and assurance processes

including, but not limited to PCI DSS and NIST CSF

  • Develop and manage meaningful metrics to measure and track cyber risks and the

effectiveness of the governance, risk and compliance function

  • Conduct compliance readiness assessments and assurance activities against

policies, standards requirements

  • Track technology and cyber related audit findings and actions

  • Assist with the development of measurable cyber security standards that align with

policy control objectives

  • Support user and specialist user education and awareness exercises for employees

  • Assist in the development of effective measurement and simplified reporting of cyber

security risks within the business

  • Assist with third party security assessments against industry standards as well as

News UK control standards

  • Assist in maintaining the cyber security risk register

Requirements

The Governance, Risk and Compliance (GRC) Analyst will have a good understanding of

security and privacy principles as well as a sound understanding of regulatory and

compliance requirements affecting a US business., * 3+ years’ experience within Cyber Security or related fields

  • Demonstrated experience in governance, risk and compliance in dynamic and

complex cyber security, technology and business environment

  • Strong knowledge and experience with Industry Frameworks and Standards such as

NIST CSF, PCI DSS and ISO 27001

  • Good working knowledge of Cloud infrastructure, especially AWS

  • Previous experience working in a SOX compliance environment is desirable

  • Strong oral and written communication skills

  • Qualification in Information Security, Computer Science, Engineering or similar

  • Professional security certifications such as Certified Information Systems Security

Professional (CISSP), Certified Information Security Manager (CISM), Certified

Information Systems Auditor (CISA), Certified in Risk and Information Systems

Control (CRISC) or similar preferred

Benefits & conditions

Base Pay Range: $80,000 - $110,000 + Bonus

We’re committed to offering competitive and flexible compensation to attract top talent. This pay range reflects our good faith estimate for the role and may vary based on a candidate’s experience, skills, location, and other relevant factors.

For bonus-eligible roles, targets are determined based on multiple considerations, including market benchmarks and individual contributions.

For benefits-eligible roles, we offer a comprehensive and competitive benefits package covering health, retirement, wellbeing, and more, along with optional benefits to meet the diverse needs of our employees.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:49 min

Container hosting options available on Amazon Web Services

Federico Fregosi · WWC 2022

2:27 min

Introduction to WebAssembly in a cloud computing context

Edo Edo · WWC 2024

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · WWC 2022

5:03 min

Navigating new cybersecurity compliance frameworks and laws

Kurt Eder · LIVE

2:51 min

Alibaba Cloud developer resources and cloud computing training

Cheng Zhang · LIVE

59 sec

Proving regulatory compliance to auditors and chief officers

Mike Bursell Mike Bursell · WWC Europe 2026

Videos

See all

Related articles

See all