Job Description
Object Technology Solutions, Inc(OTSI) has an immediate opening for a Sr. Information Security Analyst - GRC
Sr. Information Security Analyst - GRC (Cary, NC- Onsite)
Other Location: Overland Park, KS - Onsite
MAJOR RESPONSIBILITES:
• Contract Risk Management
• Proven experience reviewing client contract provisions related to data security, breach reporting, cyber resilience, and compliance certifications and measuring compliance in IT and security architecture and operations.
• Regulatory Compliance Risk Management
• Support independent certification and audit by working with D&IT peer groups and lines of business to collect documentation and evidence of security policies and operations
• Request and review documentation and evidence from control owners to certify and validate compliance to standards and industry-accepted best practice
• Monitor regulatory and legal landscape at a global scale and across market sectors and maintain awareness of compliance requirements
• IT Governance
• Act as an informed voice in development of policy and ensure alignment with regulatory, legal, and contractual requirements
• Assist establishment and enforcement of standards of practice documentation to be referenced by architecture and operations teams
• Contribute process and subject matter expertise in governance forums and cross-functional committees
• Cyber Risk Management
• Support establishment, collection, and ongoing improvement of metrics to measure effectiveness of cyber risk management and provide data-driven insight to decision makers and control owners
• Collaborate with peer D&IT groups to collect KPI's, KRI's and drive efficiency through automation and other means
• Supplier/Third Party Risk Management
• Contribute subject matter expertise through third party risk assessment process
• Identify and communicate risk of vendor engagements and mitigation actions to business owners and D&IT stakeholders
• Assist review of client security requirements in contracts and aggregate relevant clauses to inform contractual risk
• Miscellaneous:
• Assist development of user training aligned with cyber threat landscape, establish and implement metrics, and propose enhancements
• Support internal audit
• Assist with security certification/attestations/audits to demonstrate control effectiveness to independent service auditors/assessors and C3PAO's
• Assist in development of risk treatment plans and monitoring progress of actions.
• Collaborate with members of the GRC team to ensure timely and quality deliverables to internal and external customers
• Contribute subject matter expertise in review and response to internal and external sourced GRC related requests
SKILLS AND ABILITIES REQUIRED:
• Bachelor's degree in information systems, Information Security, or a related field
• 7-10 years of experience in GRC executing or auditing against standards, frameworks, and industry regulations
• Demonstrated experience supporting GRC functions for global companies
• Solid proficiency in risk assessment methodologies and frameworks
• Proven ability to assess alignment of internal policy, process, control design and operations, and cyber risk management with regulatory standards and frameworks
• Strong collaboration with IT teams
• Familiarity with industry standards and frameworks (e.g., NIST CSF and supporting SP's, ISO 27001, AICPA SOC)
• Working knowledge of cyber and privacy laws and regulations
• Solid understanding of information security principles and concepts
• Strong desire to create task and functional efficiencies through use of technology and tools, especially GenAI
• Preferred Qualifications
• Strong analytical, organizational, and communication skills
• Professional certifications such as CRISC, CISSP or others
• Experience with ServiceNow Risk Management platform
• Knowledge of FAR, DFARS, CMMC
• Experience with GRC platforms and risk management methodologies
• Ability to work independently and collaboratively as required
• Competencies
• Attention to detail and critical thinking
• Ethical judgment and integrity
• Ability to manage multiple tasks and deadlines
• Strong interpersonal and stakeholder engagement skills