In addition to QTS Core Values, the successful candidate will demonstrate:
Responsibilities
- Leverage the GRC platform to align frameworks, regulatory requirements , risks, controls and documentation into a cohesive governance structure that supports operational execution, continuous monitoring, and data driven reporting on the effectiveness of QTS security and compliance programs.
- Provide visibility into the program maturity, risk posture , and control effectiveness through reporting and dashboards.
- Provide internal s upport for internal audits of the program as well as the external audits of the SOC1 & SOC2, ISO 27001 & ISO 22301, PCI DSS, FISMA / NIST 800-53, DOD CMMC, and HITRUST audit cycles , by facilitating evidence collection, stakeholder engagement, and issue remediation
Requirements
- Working knowledge of one or more of the following frameworks, standards, and regulatory requirements:
- HITRUST
- SOC 1
- SOC 2
- PCI DSS
- ISO 27001
- ISO 22301
- FISMA / NIST 800-53
- NIST Cybersecurity Framework (CSF)
- DoD Cybersecurity Maturity Model Certification (CMMC)
- The ideal candidate may hold, or be actively pursuing, one or more of the following certifications:
- Certified Information Systems Security Professional (CISSP)
- GIAC Security Essentials Certification (GSEC)
- Certified Information Systems Auditor (CISA)
- Certified in Risk and Information Systems Control (CRISC)
- GIAC Critical Controls Certification (GCCC)
Senior Technical Compliance Analyst in overland park at Unknown Company
This position is listed as full time and onsite.