Senior Information Security Analyst

November 2

Apply Now

Description

β€’ Prepares for and facilitates examinations by qualified security assessors for frameworks such as SOC, ISO 27001, and PCI-DSS. β€’ Works closely with other members of the Information Security, Risk, & Compliance team. β€’ Gathers and synthesizes data; presents conclusions; and offers risk mitigation, remediation and process improvement solutions to management. β€’ Works closely with control owners across the company and internal and external auditors to ensure requests are completed in a timely manner. β€’ Identifies potential business risks, operational and regulatory process deficiencies and improvement opportunities. β€’ Communicates risk findings and recommendations that are clear and actionable to all stakeholders. β€’ Performs technical risk assessments of third party suppliers' security and privacy controls. β€’ Maintains register of relevant suppliers/vendors, controls, and risks for ongoing vendor risk management activities. β€’ Assists in the initial triage of compliance, risk and security requests in the ticket management system to ensure efficiency and prioritization. β€’ Assists in maintaining our overall security awareness, role-based security trainings and phishing simulation programs across the enterprise. β€’ Assists in conducting user activity audits where required.

Requirements

β€’ 6+ years’ experience performing risk and compliance activities or open to less years with addition of relevant course work/degrees β€’ Experience managing multiple priorities independently and in a team environment to achieve goals. β€’ Excellent organizational, planning and time management skills. β€’ Excellent research and analytical skills. β€’ Excellent verbal and written communication skills. β€’ Ability to exercise good judgement and tact in dealing with Bonterra senior management. β€’ Proficient with technology and ability to learn our software systems, including GRC, ticketing and project management software and workflows. β€’ Proven track record of proactively identifying needs and implementing solutions. β€’ May hold one or more information systems security professional certifications (CRISC, CISA, CISSP, CISM, GSEC, GCFA, GCTI, CCSP, or other relevant Information Security certifications).

Benefits

β€’ Generous Flexible Time Off (FTO) Policy β€’ Up to 15 paid company holidays including some commemorating social justice events and self-care β€’ Paid volunteer time β€’ Resources for savings and investments β€’ Paid parental leave β€’ Paid sick leave β€’ Health, vision, dental, and life insurance with additional access to health and wellness programs. β€’ Opportunities to learn, develop, network, and connect

Apply Now

Similar Jobs

Built byΒ Lior Neu-ner. I'd love to hear your feedback β€” Get in touch via DM or lior@remoterocketship.com