Unknown Company

Information Security Analyst II

bellevue, wa • Posted 6 days ago
Onsite Contract General

Senior Analyst, DSO Policy Assurance TeamAs a member of the DSO Policy Assurance Team, the Senior Analyst will be instrumental in enabling adherence to corporate security policies via procedural and automated controls. This individual will become a subject matter expert on cybersecurity policies and governing them and will support business and technology organizations in enabling that adherence. They will identify, track and manage remediation and mitigation activities related to cybersecurity policy adherence.

This position will consult on organizational strategy, define, and manage cybersecurity policy scope, propose security tools, and process changes that could impact cybersecurity policies, ensure security and technology teams have prepared appropriate evidence for the required policy assessments, and monitor the progress of any associated activities.Main Responsibilities:Responsible for leading strategic key initiatives that take a proactive approach to cybersecurity policy adherence.Responsible for managing or supporting the budget for assigned projects and initiatives.Responsible for aligning policies and cybersecurity controls required to support new technologies, designs, remediation, planning and other related effortsResponsible for identifying policies and their non-compliance and work collaboratively with partner team for resolution; manage escalations and resulting timelines to ensure complianceResponsible for development, testing and communication of controls related to cybersecurity policiesResponsible for leading and/or participating in reviews, assessments, and/or certificationsConsult with management on organizational strategy and goalsOverall management, progress tracking, and reporting of the related respective tasksResponsible for managing assigned vendor relationships and resolution of stakeholder issuesConsult and advise business and partners on control implementation and solutions; support the development of new processes where control gaps existWorking closely with cross-functional teams and develop strong liaison relationshipsQualifications:4-7 years Information technology, IT Audit, GRC (Governance, Risk, Compliance) or related field2-5 years IT security control development, control testing, risk remediation, and reporting1-3 years IT security or IT security infrastructure experienceExperience with eGRC systems, compliance scope management or risk management processesExperience with managing internal and external regulatory related audits and assessmentsKnowledge of the IT technology stack and ability to interface the network, technology, application, business, and legal representativesExperience with project management (planning, organizing, and managing resources to bring about the successful completion of specific project goals and objectives)Ability to identify problems, analyze data and present conclusions effectivelyStrong verbal, written and presentations skillsAbility to read, identify and interpret policies, regulations, and contract security requirementsDesired: Certification in one of the following: CIPP, CIPM, CIPT, CISA, CISSP.

Back to Job Search