GRC Analyst (in-office)

Hydac International GmbH

$80K — $95K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Degree in computer science, IT security, or engineering, or equivalent experience.
  • Strong passion for information security.
  • Experience with conducting audits (TISAX, NIST/CMMC, ISO27001) is preferred.
  • Collaborative team player with interdisciplinary skills.
  • Effective communication and customer relationship skills.
  • Fluent in English; German language skills are a plus.

Responsibilities

  • Develop and enhance the Information Security Management System (ISMS).
  • Create and maintain information security guidelines with the IT security team.
  • Develop and sustain information security policies and procedures.
  • Conduct threat and risk analyses.
  • Update training materials for information security policies.
  • Set training schedules for employees and track completion metrics.
  • Conduct internal audits for TISAX, ISO2700x, and NIST standards worldwide.
  • Lead interactions with internal and external cyber security auditors.
  • Support continuous improvement and maintenance of cyber security activities.
  • Assist in reporting information security performance indicators.
  • Coordinate business continuity and incident response plans.
  • Act as a subject matter expert in information security for the enterprise.

Benefits

  • Comprehensive medical, dental, and vision insurance.
  • Generous paid holidays and paid time off.
  • 401k plan with company matching contributions.
  • Flexible spending account (FSA) options.
  • Short-term disability and life insurance coverage.
  • Pet insurance available.
Full Job Description
The GRC Analyst will join an organization with flat hierarchies, high dynamics, and quick decisions. You will become a member of a young and dedicated team. In this role, you will be a subject matter expert in the team as well as in the whole organization for the continuous development of our Information Security Management System, and its rollout to other HYDAC entities. Furthermore, you will be responsible for internal ISMS audits according to country specific standards such as TISAX, ISO2700x and NIST. You will report to Information Security Manager located in the USA, while assisting the global team. The position will require up to 25% travel including the possibility of international travel.

You will make an impact in this role by:
  • Support the further development of the information security management system (ISMS).
  • Create and maintain the information security guidelines and concepts together with the IT security team.
  • Support the development and maintenance of information security policies, procedures, standards, controls, and other related documents.
  • Creation of threat and risk analyses.
  • Coordinate updates to training materials that support the information security policies and procedures.
  • Setup of training schedules for all Employees and provide KPI's on completion and success.
  • Carry out internal TISAX, ISO2700x, NIST (CMMC) and ISMS audits worldwide.
  • Coordinate and lead interactions with internal and external cyber security auditors.
  • Support cyber security maintenance and continuous improvement activity identified through internal processes or cyber security related audits.
  • Coordinate interactions with internal and external cyber security auditors.
  • Support reporting related to information security key performance indicators and status reporting.
  • Support business continuity planning, cyber security incident response and management. Coordinate incident response plan creation and updates.
  • Support the enterprise as an information security subject matter expert.
  • Execute control activities to evidence our compliance with IT controls.
  • Consult management, teams, and individuals to provide strategic and tactical direction regarding enterprise information security requirements, policies, procedures, and standards.
  • Assist with the operational duties of the ISMS team.
  • Perform other duties as assigned.


Requirements

To be considered for the GRC Analyst role, you must have the following minimum qualifications:
  • Successfully completed a degree in computer science, IT security, engineering or comparable professional experience.
  • You also have a high affinity for information security.
  • Ideally, you have already gained experience in conducting audits (TISAX, NIST/CMMC, ISO27001).
  • Team player and the ability to work effectively in an interdisciplinary team.
  • Effective interpersonal and customer relationship skills.
  • English fluently, German is a plus.


Due to access to government customer information, US citizenship is required.

This is an in-office position in Bethlehem, PA. Relocation is not offered for this position.

HYDAC offers employees a comprehensive medical/dental/vision plan, paid holidays, PTO, 401k with company matching, FSA account, short term disability and life insurance, and pet insurance.

Click the "apply" button to be considered for this opening!

Similar Jobs

More Jobs at Hydac International GmbH

More Information Technology Jobs

Find similar GRC Analyst (in-office) jobs: