Applicants must have current authorization to work in the United States on a full-time basis.
Reporting to the Manager or Sr.Manager, IT Risk and Compliance, the Senior GRC analyst will be responsible for supporting the day to day IT compliance, data governance, and IT risk management functions.The role will include primary responsibility for the defining, creating, and managing IT policies and standards in support of legal and regulatory compliance needs as well as general IT and organizational information security practices.
PRINCIPAL RESPONSIBILITIES:
Audit and assess firm wide plan for IT Risk and Compliance policies and rules - log-in and passwords, etc.Participate in process and control documentation pertaining to controls implementation.Develop and implement operational and enterprise governance frameworks.
Perform business impact analysis and assist with development of IT/InfoSec risk register. Operationalization of a metrics and reporting function to continually report on meaningful security, risk and compliance metrics for operational and executive management.Develop and manage the automation of KPIs & KRIs reporting that align with operational/business risk.
Support internal and external audit process for relevant compliance concerns and risk management to re mediate new and outstanding issues including PCI, SOX, ISO,NIST,Issuers etc.
Support vendor due-diligence process and help to lead and define overall third party risk management efforts including contracts ,performance etc.
Perform periodic gap assessments across product lines to validate compliance on an ongoing basis.Driving remediation activities from identification,remediation plan and closure for various information systems and processes.
Other data security projects as assigned. Liaise on with GPS counterparts for compliance reporting & continually enhancing the risk & compliance framework implemented for the project.
REQUIRED SKILLSET,:
Certification:Preferable Cobit, MOR (Management of Risk) and ITIL V3 Expert or ITIL Managing Professional
Education:
Education:Bachelor
Field of Study:Computer Science,Information Systems,Information Technology,Software Engineering, Information Security
Experience:Typically 5 years business experience; exhibit strong basic execution capabilities and begin to take on more responsibility
Technical Skills:Working knowledge of the regulatory environment Encore operates in and associated requirements - e.g. SOX, PCI, GLBA, ISO
Other Skills:Ability to follow guidelines and identify and resolve problems
Languages:English
PREFERRED SKILLSET
Languages: English & Spanish; French a plus
Education:
Degree:Master or Advanced
Field of Study:Computer Science,Information Systems,Information Technology,Software Engineering,Information Security
Experience:Experience working for a publicly traded company in a similar role or with a reputable auditing /consulting firm
Starting Compensation
Annual Salary: $93,800.00 - $121,800.00 (Amount based on office location, relevant experience, skills, and competencies)
Our compensation and benefits programs were created with an 'Employee-First Approach' focused on supporting, developing, and recognizing YOU. We offer a wide array of wellness and mental health initiatives, support volunteerism, and environmental efforts, encourage employee education through leadership training, skill-building, and tuition reimbursements, and always strive to provide promotion opportunities from within.