GRC Analyst

Insight Global
San Jose, CA, United States
about 1 month ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Working hours
Regular working hours
Job source

Tech stack

Control Objectives for Information and Related Technology (COBIT) Cyber Security Identity and Access Management Information Technology Audit RSA Archer Platform Hardware Infrastructure CIS Benchmarks

Job description

Insight Global is seeking a Technology Risk Governance Analyst to support a Fortune 100 fintech organization. This individual will evaluate technology exception requests, standards deviations, and risk acceptance activities across cloud and on-premises environments. The ideal candidate has experience within GRC, technology risk, or information security and can effectively assess control gaps, compensating controls, and overall risk exposure., * Review, assess, and manage technology exception and risk acceptance requests.

  • Analyze control gaps and evaluate associated risk, impact, and mitigating controls.
  • Partner with engineering, security, and business stakeholders to collect supporting information and facilitate reviews.
  • Track exception requests through approval, renewal, and closure processes.
  • Maintain risk documentation, exception inventories, and governance records.
  • Prepare reporting and trend analysis on exception activity, recurring risks, and control deficiencies.
  • Ensure governance requirements, standards, and risk records remain accurate and up to date.

We are a company committed to creating diverse and inclusive environments where people can bring their full, authentic selves to work every day. We are an equal opportunity/affirmative action employer that believes everyone matters. Qualified candidates will receive consideration for employment regardless of their race, color, ethnicity, religion, sex (including pregnancy), sexual orientation, gender identity and expression, marital status, national origin, ancestry, genetic factors, age, disability, protected veteran status, military or uniformed service member status, or any other status or characteristic protected by applicable laws, regulations, and ordinances. If you need assistance and/or a reasonable accommodation due to a disability during the application or recruiting process, please send a request to HR@insightglobal.com.To learn more about how we collect, keep, and process your private information, please review Insight Global’s Workforce Privacy Policy: https://insightglobal.com/workforce-privacy-policy/.

Requirements

  • 5-8+ years of experience in Information Security, Technology Risk, IT Audit, Governance, Risk & Compliance (GRC), or a related field.
  • Experience conducting risk assessments and control gap analyses within enterprise technology environments.
  • Strong understanding of security controls, technology governance, and risk management principles.
  • Experience supporting both cloud and on-premises infrastructure environments.
  • Ability to assess technology exceptions, standards deviations, and compensating controls.
  • Experience working cross-functionally with engineering, security, infrastructure, and business teams.
  • Strong written and verbal communication skills with the ability to articulate technical risks to non-technical audiences. - Experience managing technology exception, risk acceptance, or waiver processes within a large enterprise.
  • Familiarity with common security and control frameworks such as NIST, ISO 27001, CIS Controls, or COBIT.
  • Experience using GRC platforms for risk tracking and governance workflows.
  • Background in regulated industries such as financial services, fintech, healthcare, or technology.
  • Understanding of identity and access management, authentication controls, infrastructure security, and security governance practices.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on dejobs.org

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:14 min

Securing analysis platforms via network access controls

Jennifer Reif · LIVE

2:15 min

Auditing container configurations against CIS benchmark security standards

Madhu Akula · LIVE

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · WWC 2022

2:17 min

Governing enterprise IT as a global automotive CIO

Katrin Lehmann Katrin Lehmann +1 · Coffee With Developers

3:39 min

Validating data queries and infrastructure security configurations

Philipp Krenn · WWC 2023

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

Videos

See all

Related articles

See all