As the Information Company, our mission at OpenText is to create software solutions and deliver services that redefine the future of digital. Be part of a winning team that leads the way in Enterprise Information Management.
Senior Security Analyst (Governance & Risk)
Working in the Global Information Security team, the Senior Governance and Risk Analyst will be expected to understand a wide array of IT security controls, processes and concepts. The Risk Analyst will provide support for our Security Risk Management methodology and be specifically responsible for executing risk assessments for our product/platforms/services and our 3rd party vendors. The role will also be required to apply risk review concepts in support of audit controls for ISO27001, SOC1, and SOC2 on the Open Text Commercial platforms. This is a hands-on role that will require detailed knowledge of security concepts, governance models, commercial platform processing, risk models, security controls, security audits and other common IT and security domain concepts.
You are great at:
- Assisting the Global Information Security (GIS) team to service and support governance and risk management initiatives
- Applying security policy and risk assessments to Open Text business units
- Managing risk assessments for 3rd party security vendors and vendor contracts on behalf of GIS
- Analyzing risk review results and determining risk management and mitigation actions
What it takes:
- Bachelor’s Degree in Information Systems, Business Administration, or similar degree, or equivalent experience preferred.
- 5+ years in security compliance, risk and governance
- Knowledge of merger an acquisition processes and ability to analyze security risk for M&A activities
- Strong inter-personal skills are required to work across multiple internal teams and to handle customer interface meetings on security related topics.
- Ability to write clear and concise polices and communications that are easily consumed by a large target audience
- Familiar with commonly used information security concepts, best practices and standard procedures
- Knowledge of security controls, and governance and risk management frameworks
- Capable of working under pressure in a continually changing environment
- Audit framework knowledge for ISO27001, SOC1 & SOC2 desired
- Strong written and verbal communication skills
- Ability to work alone with minimal supervision effectively and efficiently
- Ability to participate in key proactive security programs.
- CISA, CISM, CISSP or other IT certifications preferred