Information Security Sr Anlyst

OTSI

$110K — $130K *
Cary, NC 27513In-Person
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in information systems, Information Security, or a related field
  • 7-10 years of experience in GRC executing or auditing against standards
  • Demonstrated experience supporting GRC functions for global companies
  • Solid proficiency in risk assessment methodologies and frameworks
  • Strong collaboration skills with IT teams
  • Familiarity with industry standards (NIST CSF, ISO 27001)
  • Professional certifications such as CRISC, CISSP preferred

Responsibilities

  • Manage contract risk related to data security and compliance
  • Support independent certification and audit processes
  • Monitor global regulatory and compliance landscape
  • Contribute to IT governance policy development
  • Support establishment of cyber risk management metrics
  • Participate in third-party risk assessment processes
  • Develop user training aligned with the cyber threat landscape

Benefits

  • Opportunities for professional growth and development
  • Collaborative work environment with cross-functional teams
  • Engagement in cutting-edge security technologies
  • Exposure to a global regulatory framework
  • Potential for remote work flexibility on certain projects
Full Job Description
Job Description
Object Technology Solutions, Inc(OTSI) has an immediate opening for a Sr. Information Security Analyst - GRC

Sr. Information Security Analyst - GRC (Cary, NC- Onsite)

Other Location: Overland Park, KS - Onsite

MAJOR RESPONSIBILITES:
• Contract Risk Management
• Proven experience reviewing client contract provisions related to data security, breach reporting, cyber resilience, and compliance certifications and measuring compliance in IT and security architecture and operations.
• Regulatory Compliance Risk Management
• Support independent certification and audit by working with D&IT peer groups and lines of business to collect documentation and evidence of security policies and operations
• Request and review documentation and evidence from control owners to certify and validate compliance to standards and industry-accepted best practice
• Monitor regulatory and legal landscape at a global scale and across market sectors and maintain awareness of compliance requirements
• IT Governance
• Act as an informed voice in development of policy and ensure alignment with regulatory, legal, and contractual requirements
• Assist establishment and enforcement of standards of practice documentation to be referenced by architecture and operations teams
• Contribute process and subject matter expertise in governance forums and cross-functional committees
• Cyber Risk Management
• Support establishment, collection, and ongoing improvement of metrics to measure effectiveness of cyber risk management and provide data-driven insight to decision makers and control owners
• Collaborate with peer D&IT groups to collect KPI's, KRI's and drive efficiency through automation and other means
• Supplier/Third Party Risk Management
• Contribute subject matter expertise through third party risk assessment process
• Identify and communicate risk of vendor engagements and mitigation actions to business owners and D&IT stakeholders
• Assist review of client security requirements in contracts and aggregate relevant clauses to inform contractual risk
• Miscellaneous:
• Assist development of user training aligned with cyber threat landscape, establish and implement metrics, and propose enhancements
• Support internal audit
• Assist with security certification/attestations/audits to demonstrate control effectiveness to independent service auditors/assessors and C3PAO's
• Assist in development of risk treatment plans and monitoring progress of actions.
• Collaborate with members of the GRC team to ensure timely and quality deliverables to internal and external customers
• Contribute subject matter expertise in review and response to internal and external sourced GRC related requests

SKILLS AND ABILITIES REQUIRED:
• Bachelor's degree in information systems, Information Security, or a related field
• 7-10 years of experience in GRC executing or auditing against standards, frameworks, and industry regulations
• Demonstrated experience supporting GRC functions for global companies
• Solid proficiency in risk assessment methodologies and frameworks
• Proven ability to assess alignment of internal policy, process, control design and operations, and cyber risk management with regulatory standards and frameworks
• Strong collaboration with IT teams
• Familiarity with industry standards and frameworks (e.g., NIST CSF and supporting SP's, ISO 27001, AICPA SOC)
• Working knowledge of cyber and privacy laws and regulations
• Solid understanding of information security principles and concepts
• Strong desire to create task and functional efficiencies through use of technology and tools, especially GenAI
• Preferred Qualifications
• Strong analytical, organizational, and communication skills
• Professional certifications such as CRISC, CISSP or others
• Experience with ServiceNow Risk Management platform
• Knowledge of FAR, DFARS, CMMC
• Experience with GRC platforms and risk management methodologies
• Ability to work independently and collaboratively as required
• Competencies
• Attention to detail and critical thinking
• Ethical judgment and integrity
• Ability to manage multiple tasks and deadlines
• Strong interpersonal and stakeholder engagement skills

Similar Jobs

More Jobs at OTSI

More Information Technology Jobs

Find similar Information Security Sr Anlyst jobs: