IT GRC Analyst II

State Employees' Credit Union

$85K — $100K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Minimum 5 years of IT Security and/or IT Risk Management experience in a mid-to-large company
  • Effective communication skills, both verbal and written
  • Teamwork and collaboration aptitude
  • Proficient in conducting risk and controls assessments
  • Familiarity with industry security standards like NIST and ISO 27001

Responsibilities

  • Identify and monitor technology risks in internal and external environments
  • Quantify inherent and residual IT risk levels for analytics and management reporting
  • Develop and track remediation plans with milestones, monitoring owner progress
  • Execute risk management processes and contribute to process improvement
  • Perform risk assessments and aggregate reporting for Audit and Regulatory compliance
  • Collaborate with stakeholders to create consistent IT risk reporting and metrics

Benefits

  • Professional growth opportunities
  • Flexible working environment
  • Collaborative and supportive work culture
  • Access to training programs and resources
  • Participation in health and wellness initiatives
Full Job Description
Position Overview: The IT GRC Analyst II assess, tests, documents, and monitors the SECU technology ecosystem to ensure the IT control environment effectively mitigates risks associated with an everchanging threat landscape. The IT GRC Analyst will possess a wide range of technical and interpersonal skills to bridge the gap between technology organizations and the business. Must have a big-picture perspective, ability to execute end-to-end risk management processes, and ability to quickly establish trust and build productive relationships across multiple departments. The IT GRC Analyst will require expertise to perform technology risk assessments, provide input to and/or document IT policies, standards, and guidelines, develop, monitor, and track risk remediation plans, and aggregate and report key risk metrics to senior stakeholders.

Responsibilities:

20% Identify, document, and monitor technology risks present across both internal and external (vendor / cloud) environments

20% Quantify inherent and residual IT risk levels to enhance analytics, inform prioritizations, and for use in management reporting

20% Work with risk remediation owners to establish remediation plans with milestones and target dates, and monitor progress towards remediation, escalating as appropriate

20% Execute technology risk management processes and provide input to support continuous improvement of process and program design

10% Perform risk and controls assessments while aggregating reporting for Audit and/or Regulatory issues.

10% Partner with relevant stakeholders to establish clear and consistent IT risk reporting, metrics, KRIs, and KPIs to inform decision making

Required Relevant Experience: Minimum 5 years

Required Knowledge, Abilities, Skills:
  • Teamwork, collaboration, self-driven and effective communication skills - both written and verbal.
  • 5 years of IT Security and/or IT Risk Management experience working in a mid-to-large size company

Basic proficiency or ability to learn one or more of the following:
  • Risk and controls assessments
  • Documenting and maintaining IT Policies / Standards
  • IT Risk aggregation, reporting, KPI/KRIs
  • Issues management
  • Third party risk management

Working knowledge of various industry security standards and frameworks including: NIST, ISO 27001, ISF Standard of Good Practice (SoGP), etc.

Desired Knowledge, Abilities, Skills:
  • 5+ years working in a financial institution.
  • Knowledge of modern enterprise and security architectures, their challenges, common approaches to overcome their challenges, and their inherent security strengths and weaknesses.
  • Professional certifications such as: CISSP, CISA, CISM, GIAC, CGEIT, CRISC, OSCE, or other relevant industry certification
  • Experience working within a DevOps environment


Disclaimer

State Employees' Credit Union reserves the right to fill this role at a higher/lower level based on business need.

Similar Jobs

More Jobs at State Employees' Credit Union

More Information Technology Jobs

Find similar IT GRC Analyst II jobs: