GRC SECURITY ANALYST
Job Description
REQUIREMENTS
- A minimum of 5 years of related experience in GRC, security compliance, or risk management roles with a Bachelor’s degree; or 3 years and a Master’s degree; or equivalent work experience.
- Complete knowledge and full understanding of relevant security frameworks and standards (e.g., NIST CSF, SOC 2, ISO 27001, ISO 42001) and data privacy regulations (GLBA, GDPR, CCPA).
- Relevant industry certifications: Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), Certified Information Systems Auditor (CISA), Certified in Risk and Information Systems Control (CRISC), Artificial Intelligence Governance Professional (AIGP), or equivalent.
- Sophisticated analytical and problem-solving skills, with the ability to assess diverse, unusual, and complex security issues and develop effective solutions independently.
- Strong communication and interpersonal skills, with a proven ability to persuade differing audiences and advise senior stakeholders on difficult compliance matters.
- Familiarity with GRC technologies (i.e., Vanta, Drata, OneTrust, etc.), risk assessment tools, and practices specific to maintaining data integrity and confidentiality in the financial services or appraisal management industry.
- Detail-oriented focus on accuracy and thoroughness in documentation, reporting, and policy formulation.
- Commitment to maintaining the highest standards of confidentiality, integrity, and professionalism.
- Capacity to understand legacy and progressive technology and security controls along with respective risks. Working knowledge of technologies such as cloud computing, DevOps, and application security is required.
- Advanced proficiency in utilizing spreadsheets for comprehensive data analysis, audit metric tracking, and complex compliance reporting.
RESPONSIBILTIES
- Monitoring and enforcing compliance with critical security frameworks (such as NIST CSF, NIST RMF, ISO 27001/27002, SOC 2, ISO 42001) and industry-specific regulations (such as GLBA, CCPA, GDPR) pertinent to the financial services and real estate valuation sectors.
- Conducting comprehensive risk assessments of diverse scope to identify security vulnerabilities, evaluating the effectiveness of existing controls, and resolving a wide range of issues using judgment and interpretation.
- Developing, maintaining, and adapting security policies, procedures, and guidelines in alignment with industry best practices, client contractual requirements, and mortgage lending regulatory standards.
- Leading preparation and participation for internal and external security audits, adapting existing approaches to resolve audit findings based on limited information and precedent.
- Enhancing relationships with cross-functional teams to develop and implement remediation plans for identified security gaps and weaknesses.
- Evaluating the security posture of third-party vendors and assessing their compliance with contractual security requirements to protect sensitive financial and property data.
- Maintaining accurate records of compliance activities, findings, and remediation efforts, creating comprehensive reports for management, clients, and regulatory authorities as needed.
- Defining qualitative and quantitative metrics to assess the success of the security program and provide regular reports to security and business leadership.
- Staying abreast of emerging security threats, technologies, and regulatory changes in the financial and real estate tech space.
- Other relevant duties as assigned.
Are you interested in this position?
Apply by clicking on the “Apply Now” button below!
#CrossChannelJobs #JobSearch
#CareerOpportunities #HiringNow
#Employment #JobOpenings
#JobSeekers
#FacebookLinkedIn