Senior Information Security Risk Analyst

Warner Bros. Entertainment Inc.$102K — $190K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree required
  • 3-5 years of information security experience
  • At least 1 year in third-party risk management
  • Understanding of IP network infrastructure and data security practices
  • Excellent written and verbal communication skills
  • Detail-oriented with analytical and problem-solving abilities
  • Proactive approach to ownership and resolution of issues

Responsibilities

  • Conduct third-party vendor risk assessments using WBD processes and tools
  • Understand vendor services to evaluate risk and assessment scope
  • Identify and document deficiencies in vendor controls
  • Report assessment findings and risk levels to management
  • Perform peer reviews for consistency and detail in assessments
  • Monitor and review remediation plans for compliance
  • Ensure contracts have appropriate data security terms

Benefits

  • Flexible hybrid work schedule (3 days onsite)
  • Opportunity for professional growth and skill enhancement
  • Involvement in continuous improvement initiatives
  • Collaborative work environment
  • Exposure to global IT best practices in risk management
Full Job Description
*Must work a hybrid schedule (3 days onsite) out of our DC office.*

THE JOB:
The Senior Information Security Risk Analyst will support the assessment of information security risks across all of Warner Bros. Discovery’s (WBD’s) third party suppliers/vendors.  This role requires the ability to understand and assess information security risks posed by third parties and clearly communicate those risks to the business.  It will apply global IT industry best practices to ensure WBD uses third party information security risk management to foster business-enabling insights.

RISK ASSESSMENTS:

  • Use WBD processes and tools to perform 3rd party vendor risk assessments, for new and existing vendors
  • Work with business to understand the “what” and “how” of services provided by vendor to assess level of risk and scope of assessment
  • Perform timely assessments of Vendor controls to identify, document, and communicate key deficiencies to the business and Information Security management
  • Report on assessment outcomes, risk level and associated recommendations to remediate issues
  • Perform 2nd-level peer reviews of assessment outputs, prior to reports being finalized, to drive consistency and completeness of findings based on risk of engagement
  • Assist with follow-up on documentation requests for initial and periodic assessments

FINDINGS MANAGEMENT:

  • Monitor corrective action plans against agreed upon timelines
  • Review of remediation evidence for closure of findings

CONTRACT REVIEWS:

  • Review contracts to ensure appropriate data security terms are included
  • Provide comment and acceptable alternatives to vendor contract revisions, in alignment with defined guidance
  • Escalate provision changes, as needed

OTHER:

  • Assist with contract intake to ensure pipeline of assessments is managed in a timely and efficient manner
  • Provide periodic status updates
  • Maintain accurate and complete data within the identified system of record
  • Contribute to the team’s continuous improvement efforts by identifying opportunities and helping to implement them

THE ESSENTIALS:

  • BS/BA degree required
  • 3-5 years’ experience in information security, with at least one (1) year experience in third party risk management
  • Knowledge of IP network infrastructure (firewalls, intrusion detection/prevention), access control, data encryption and physical security; Cloud security knowledge a plus
  • Excellent communication skills, including the ability to communicate effectively in English, both written and verbal
  • Ability to present complex topics in clear, non-technical language
  • Ability to work collaboratively within team and across business and technology functions
  • Detail-oriented individual with critical thinking, analytical, and problem-solving skills
  • Demonstrated ability to be proactive and take ownership of and solve problems
  • Active learner - able to enhance personal, professional, and business growth through new knowledge and experiences
  • Ability to handle multiple assignments concurrently within an iterative environment

THE NICE TO HAVES:

  • One or more of the following certifications: CISSP, CRISC, CISA
  • 2+ years of prior experience in a related field (media, entertainment, business development or streaming services industry experience a plus)
  • Familiarity with streaming and similar products/services
  • Experience working in a national or global company

About Warner Bros. Entertainment Inc.

Warner Bros. Interactive Entertainment is an American video game publisher based in Burbank, California, and part of the newly-formed Global Streaming and Interactive Entertainment unit of Warner Bros. Discovery. WBIE was founded on January 14, 2004 under Warner Bros. and transferred to the Home Entertainment division when that company was formed in October 2005. WBIE manages the wholly owned game development studios TT Games, Rocksteady Studios, NetherRealm Studios, Monolith Productions, WB Games Boston, Avalanche Software, and WB Games Montréal, among others.
Learn more about Warner Bros. Entertainment Inc.
Industry
Founded
1918

Similar Jobs

More Jobs at Warner Bros. Entertainment Inc.

More Information Technology Jobs

Find similar Senior Information Security Risk Analyst jobs: