Job DescriptionTitle:IT AUDITING (Governance and Compliance)Auditing Is Key Location: Hybrid (Deerfield Beach, FL)
Duration: 12 months +
Sr. Governance and Compliance Analyst The Governance and Compliance Sr. Analyst will report to the Governance, Risk and Compliance Manager and support the Information Security department to provide the highest quality assurance program to our customers.The Governance and Compliance Sr. Analyst will perform a critical role in providing IT governance and compliance as a service, including assessments, compliance program management and assurance, and control framework maturity evaluations. The Governance and Compliance Sr. Analyst will manage, measure, operationalize and communicate a myriad of compliance initiatives across the enterprise, including but not limited to SOC 1 Type 2, MAR, NY DFS 500, CCPA, HIPAA. Collaboration with business areas within JM Family will be a key success criterion for this individual.
Responsibilities:- Facilitate IT audits and assessments,including remediation of any findings noted
- Ensure compliance with regulatoryrequirements (e.g., SOC 1 Type 2, MAR, NY DFS 500, CCPA) and internalcontrols, with proactive validation of controls.
- Review regulatory and compliance mattersrelated to information technology, as the shared-service provider for allbusiness units, and perform necessary gap analysis
- Implement and maintain an informationtechnology, including security and privacy, controls framework
- Develop and maintain IT policies,standards, and procedures
- Act as an advocate for informationsecurity practices
- Execute program tasks related to theevaluation of security control framework maturity, such as stakeholderinterviews, documentation reviews, and maturity quantification.
- Engage control owners (of varyinginformation security acumen and expertise) and key stakeholders across theenterprise to collect and test evidence and assess compliance to variousrequirements (external regulatory and contractual, as well as internal controls)
- Maintain and foster relationships andtrust with key partners throughout the company
- Maintain compliance and risk managementinitiatives in a GRC platform
- Understand contractual elements with thirdparties and intelligently speak on the security requirements of a contractfrom an information security point of view
- Maintain reliable, up-to-date informationfrom the government and across the industry regarding the identificationof new security standards and governance
- Establish governance around disasterrecovery function and collaborate with key business and IT leaders todevelop security and disaster recovery standards and action plans
- As directed, conduct periodic internalassessments for security risk and compliance
- Perform other essential duties as assigned
Desired Skills- Project management skills formanaging multiple complex activities
- Knowledge of controlsframeworks and applicable regulatory compliance mandates (e.g.,NIST, CIS CSC, COBIT, CCPA, HIPAA, GLBA, SOC 1 Type 2, MAR)
- Conduct research to keepabreast of the latest security issues, third-party vendors, andapplications as needed
Qualifications/Requirements- Working knowledge of governanceand compliance, including policy, process, governance, controlsframeworks, and regulatory environments
- Knowledge to evaluate, buildand optimize security program elements as assigned (e.g., logical accesscontrol, application security, vendor risk management, network security,privacy)
- Experience in working withauditors
- Strong organizational skillswith ability to thrive in a sense-of-urgency environment, leveraging bestpractices, and approaching any problem as a team-player with a can-doattitude
- Strong written and verbalcommunication skills and ability to interface with all levels of businessand executive leadership
- Excellent analytical, problemsolving, and decision-making skills, applied with a solution-focusedattitude
- Strong self-directed workhabits, exhibiting initiative, drive, creativity, maturity, self-assuranceand professionalism
License /Certificate (any of the following a plus):
CISSP, CISA, CISM, CIPP, GIAC
Skill SetWorking knowledge of governance and compliance, including policy, process, governance, controls frameworks, and regulatory environments Knowledge to evaluate, build and optimize security program elements as assigned (e.g., logical access control, application security, vendor risk management, network security, privacy) Experience in working with auditors