Menu

Sr. Security Governance, Risk & Compliance Analyst

at Early Warning Services in Chicago, Illinois, United States

Job Description

At Early Warning, we've powered and protected the U.S. financial system for over thirty years with cutting-edge solutions like Zelle, Paze, and so much more. As a trusted name in payments, we partner with thousands of institutions to increase access to financial services and protect transactions for hundreds of millions of consumers and small businesses.

Positions located in Scottsdale, San Francisco, Chicago, or New York follow a hybrid work model to allow for a more collaborative working environment.

Candidates responding to this posting must independently possess the eligibility to work in the United States, for any employer, at the date of hire. This position is ineligible for employment Visa sponsorship.

Overall Purpose

The Sr. Security Governance, Risk & Compliance Analyst provides comprehensive activities supporting information security governance, risk, and compliance, including but not limited to: developing, assessing and recommending security policies, standards, and procedure updates in accordance with legal, regulatory, and contractual requirements; conducting and leading risk management activities; driving security risk assessment and remediation activities; analyzing and improving the internal controls testing program; facilitating audits and assessments; information security issues oversight; developing and improving security training and awareness activities.

Essential Functions
Plan and support the Security Governance, Risk and Compliance programs and department initiatives.
Oversee the security policy program, which includes policy drafting, managing approvals in the Governance, Risk, and Compliance tool, facilitating cross-functional input, and ensuring compliance with policies.
Design and improve internal control testing program and practices; advise management on control design and implementation.
Provide consultation to management on regulatory, legal, and contractual requirements.
Act as Point of Contact and Project Manager for Information Technology and Security focused external and internal audits and assessments (SOC-2, GLBA, FISMA, PCI DSS, FFIEC, & others).
Assess information security risk and recommend mitigation activities in alignment with Enterprise and Operational Risk Management requirements.
Document work performed for all audits and assessments and provide support for required responses.
Track and report on compliance metrics for assigned areas.
Present to executive staff, business line leaders, and external customers on various security topics (risks, issues, policies, governance trends, compliance gaps, etc.).
Participate and lead security awareness programs efforts (security awareness training, Company communications, events, etc.)
Serve as a mentor for Security Governance, Risk and Compliance staff.
Effectively communicate Security-related risks, control gaps/failures, and vulnerabilities to business owners.
Lead the issues management efforts, including risk identification and remediation for Security.
Support the company's commitment to risk management and protecting the integrity, availability, and confidentiality of systems and data.
The above job description is not intended to be an all-inclusive list of duties and standards of the position. Incumbents will follow instructions and perform other related duties as assigned by their supervisor.

Minimum Qualifications
Education and experience typically obtained through completion of a bachelor's degree.
Minimum of 5 or more years of direct/ related experience in security, governance, risk, and compliance, risk management, IT audit, information technology, or related.
Proficient in ISO 27000, PCI DSS, NIST 800-53a, SIG, FFIEC handbooks, Service Organization Controls in accordance with SSAE No. 18, GLBA, and FCRA.
Required certification in one of CISA, CISSP, CCSP, CRISC, GSNA, CGIH, or equivalent or ability to sit for one of the certifications within the first 12 months of hire
Excellent written/verbal communication skills, with ability to present to peers and co-workers.
Background and drug screen.

Preferred Qualifications
Additional related education and/or experience preferred.
Prior financial services or FinTech experience.
Certifications in any of the following: Security+, CISA, CISSP, CCSP, CRISC, GSNA, GCIH, or equivalent.
Prior GRC, Information Security & Technology Consulting, or Advisory experience with leading consulting firms such as KPMG, Deloitte, E&Y, PWC is highly desirable.
Experience with security-related technologies including GRC Technologies, Identity and Access Management tools, Single-sign-on technologies, and Security-focused systems.

Physical Requirements

Working conditions consist of a normal... For full info follow application link.

Early Warning is an equal opportunity employer that takes affirmative action to employ, and advance in employment, qualified minorities, women, individuals with disabilities and covered veterans.

 

To view full details and how to apply, please login or create a Job Seeker account
How to Apply Copy Link

Job Posting: 12090844

Posted On: Jul 31, 2024

Updated On: Jul 31, 2024

Please Wait ...