Analyst, Information Security GRC

Intercontinental Exchange Holdings, Inc.

$80K — $95K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in Information Security, Engineering, MIS, CIS, or related field or equivalent experience
  • Familiarity with Systems Administration and/or IP Networking is advantageous
  • Experience with Regulatory Compliance processes is a plus
  • Background in financial services, especially exchanges or trading facilities, is preferred
  • Ability to communicate metrics to senior management and boards is beneficial
  • Possession of advanced certifications, such as CISSP, is preferred
  • Strong technical writing and communication skills are required

Responsibilities

  • Generate regular reports using automated and manual processes on the status of the Information Security program
  • Maintain Information Security policies and departmental procedures, ensuring alignment with control standards
  • Organize departmental documentation and respond to regulator, audit, and customer inquiries effectively
  • Conduct periodic recertification processes for access protocols and regular access reviews
  • Develop and implement company-wide security awareness and education programs
  • Create and manage the risk assessment platform to document and report on assessments and remediation activities

Benefits

  • Exposure to a global Information Security program
  • Involvement with a diverse range of business products under a leading company
  • Opportunity to contribute to a best-in-class cybersecurity environment
  • Engagement in the dynamic field of Governance, Risk, and Compliance
  • Professional development through education and advanced certification opportunities
Full Job Description
Overview

Job Purpose

The Analyst, Information Security GRC is part of a team responsible for the global Information Security program.  The role would gain exposure to the full suite of businesses and products which underpin the Parent ICE company.

 

Information Security (“IS”) is charged with:

  • Preventing impactful cybersecurity and physical security incidents,
  • maintaining a reputation with customers, regulators, and key stakeholders as running a best-in-class cybersecurity and physical security program, and
  • avoiding negative impact to business agility and growth from cybersecurity and physical security policies and controls.

Governance, Risk, and Compliance maintain said policies, ensure controls are operating effectively via assessment and attestation, and own the vulnerability management program to identify and correct any problems within.

 

Responsibilities

  • Security Metrics – Uses automated and manual processes to produce regular reports communicating the status of the Information Security program
  • Policies and Procedures – Maintains corporate Information Security policies and departmental procedures and maps them to relevant control standards
  • Regulator, Audit, and Customer Inquiries – Organizes and updates departmental documentation and responds to inquiries in an organized and repeatable fashion
  • Recertification – Operates periodic processes to ensure hire, transfer, and termination protocols are complied with and regular access reviews are conducted
  • Security Awareness – Builds and maintains company awareness and education programs
  • Risk Assessment – Builds and operates the company platform to document, measure, and report assessments, risks, controls, findings, and remediation activity

 

Knowledge and Experience

  • University degree in Information Security, Engineering, MIS, CIS, or related discipline or equivalent years of experience required
  • Experience with Systems Administration and/or IP Networking is a plus
  • Experience with Regulatory Compliance is a plus
  • Experience in an exchange, trading facility, or financial services is a plus
  • Experience with senior management and board metrics generation and communication is a plus
  • Advanced certifications (for example, the CISSP)
  • Advanced technical writing and/or communication education and experience

 

Specific Technologies

Excel, Workflow automation tools, Data collection, normalization, indexing, correlation, and visualization.  Scripting, regular expressions, string-parsing, light SDLC, and project management.  NIST Cyber Security Framework, CIS, and GRC Platforms.

}

Similar Jobs

More Jobs at Intercontinental Exchange Holdings, Inc.

More Information Technology Jobs

Find similar Analyst, Information Security GRC jobs: