INFOSEC Risk Analyst

4 weeks ago


Sacramento, United States The Judge Group Full time
Location: Sacramento, CA
Salary: $40.00 USD Hourly - $45.00 USD Hourly
Description: Our client is currently seeking a INFOSEC Risk Analyst

The governance, risk, and compliance (GRC) InfoSec Risk analyst is responsible for supporting the security direction of the business and elevating the company's security posture. The GRC InfoSec Risk analyst is expected to support the security strategy of the business within new and existing information system capabilities. Consequently, the position requires both an understanding of legacy systems, as well as new technologies and requirements. The GRC InfoSec Risk analyst is also responsible for the analysis and implementation of policies and maintenance.
The ideal candidate is technical and possesses at least five years of experience in IT security, compliance, or risk management.

In tandem with IT and security leadership, the GRC InfoSec Risk analyst consistently assesses and validates the assurance of the security program. As a primary point of contact for internal and external auditors, the GRC InfoSec Risk analyst monitors progress and enforces resolution of outstanding issues that may lead to non-compliance or security threats to the business. As a key member of the IT GRC team, the GRC security analyst must focus on strong risk management and corporate resiliency, and not be driven solely by compliance. The position requires a diverse background to understand a variety of systems, including new technologies and legacy systems considered business critical.

TASKS, DUTIES, FUNCTIONS:

1. Conduct enterprise-wide, ongoing risk analysis in tandem with compliance and security. 2. Maintain oversight in a GRC-related platform. 3. Identify strengths and weaknesses in the GRC program as they relate to privacy, security, business resiliency and compliance frameworks. 4. Document, formulate and enforce areas of security improvement that balance risk with business operations and do not diminish efficiencies or innovation. 5. Maintain strong oversight of third parties, vendors and business partners to safeguard against undue risk presented by external entities. Escalate to GRC management and business unit leads when points of weakness are discovered. 6. Analyze findings, and document, recommend and report program gaps to GRC leadership. 7. Monitor current and proposed security changes impacting regulatory, privacy and security industry best practice guidance. Apply GRC expertise across key lines of business, including products, practices and procedures. 8. Define qualitative and quantitative metrics to assess the success of the GRC program and provide regular reports to GRC, Security, and business leadership. 9. Ensure security and technology teams maintain up-to-date configuration documentation for systems and processes. Maintain rigorous oversight of security systems and security configuration administration to reduce risk to enterprise systems and accounts. 10. Act as a key participant in incident response to track occurrence and resolution, with strict documentation and reporting. 11. Work in tandem with security, audit and risk management leadership to perform ongoing security program assessments and create annual strategic technology and budgetary directives. 12. Attend and fully engage in change and project management meetings. 13. Liaison with auditors, both internal and external, to maintain and implement controls for compliance and privacy laws. 14. Act as a point of contact for disaster recovery and business continuity as it relates to security frameworks, compliance and privacy laws. 15. Perform other duties as assigned.

PHYSICAL SKILLS, ABILITIES, AND EXERTION UTILIZED IN THE PERFORMANCE OF THESE TASK:

1. At least five plus years' experience in cybersecurity as a practitioner and with at least two to thre plus years exposure with various security frameworks.

2. Strong business acumen and security technology skills for well-rounded proficiency, as well as proven ability to align with security practices and compliance responsibilities. 3. Experience and understanding of various regulatory requirements and laws, including but not limited to PCI, SOX, HIPAA, GDPR and GLBA. Additional experience in one or more of the following: ISO 27001/2, ITIL or NIST. 4. Exceptional written and verbal communication skills, and proven ability to translate security and risk to all levels of the business. 5. Capacity to understand legacy and progressive technology and security controls along with respective risk. Working knowledge of technologies such as cloud computing, DevOps and application security is required. 6. Up-to-date understanding of a wide range of incident response, system configuration, vulnerability management and hardening guidelines. 7. Track record of acting with integrity, taking pride in work, seeking to excel, being curious and adaptable, and communicating effectively. 8. Proven project leadership with both legacy and emerging technologies to assess and manage business risk and enforce security controls. 9. Prior team leadership experience preferred. 10. Must be self-directed, able to work on own initiative. 11. Ability to work under pressure and tight deadlines; may be required to work extended hours to complete tasks.

ORGANIZATIONAL CONTACTS & RELATIONSHIPS:

1. INTERNAL: All levels of staff and management, including Senior Management.

2. EXTERNAL: Members, vendors, suppliers, government agencies, industry associations and peers at other financial institutions.

QUALIFICATIONS: 1. EDUCATION: Bachelor's degree in Business Administration, Accounting, Management Information Systems or Computer Science is strongly preferred. Advanced Degree in Business Administration or other related area is preferred.

2. EXPERIENCE: Minimum five years' experience in cybersecurity as a practitioner and with at least two to three plus years exposure with various security frameworks, experience in a technology risk, security, or compliance role preferably in a financial institution. Detailed understanding of risk management and controls assurance. Strong understanding of information security controls and standards such as ISO 27001/2, NIST, CSF, and related frameworks. Thorough understanding of various regulatory requirements and laws such as, but not limited to PCI, SOX, HIPAA, HITRUST, GDPR and GLBA. Experience in a role balanced between business stakeholders and a central technology service organization. Certifications, such as CISSP, CRISC, CISA, CIPP, CISM, are well regarded.

3. KNOWLEDGE / SKILLS:

• Must have strong written skills, communication skills, and possess the ability to building trust and relationships with senior executives. This diversified position requires a strong ability to multitask. • Strong analytical, problem solving, and decision-making skills to effectively understand and resolve complex strategies and issues. • Must have good interpersonal skills and the ability to interact with employees at all levels of responsibility within the organization. PHYSICAL REQUIREMENTS: 1. Prolonged sitting throughout the workday with occasional mobility required. 2. Corrected vision within the normal range. 3. Hearing within normal range. A device to enhance hearing will be provided if needed. 4. Ability to lift 20 lbs. as may be required. 5. Occasional movements throughout the department daily to interact with staff, accomplish tasks, etc. 6. May require long work hours to accomplish tasks. 7. Occasional travel may be required locally, statewide, and throughout the United States to attend seminars and vendor group meetings.

Overnight travel and evening schedules included. 8. Prolonged use of telephone to accomplish tasks. LICENSES / CERTIFICATIONS: Holds or is working toward one or more of the following: CISSP, CRISC, CGEIT or GRCP. Project Management Professional (PMP) and (PfMP) certifications from the Project Management Institute (PMI) or Certified Business Analyst Professional (CBAP) from the International Institute of Business Analysis (IIBA) preferable, but not required.

Contact: aflores@judge.com

This job and many more are available through The Judge Group. Find us on the web at www.judge.comPandoLogic. Keywords: Risk Analyst, Location: SACRAMENTO, CA - 95811 , PL: 593016117

  • Sacramento, United States Benefit & Risk Management Services, Inc. Full time

    Job DescriptionJob DescriptionSummary: The Quality Assurance Analyst I will coordinate and perform quality assurance testing of computer programs and various program output data/files; and conduct various types of analysis including workflows and processes. Essential Duties and Responsibilities include the following. Other duties may be assigned.Works on...


  • Sacramento, United States Benefit & Risk Management Services, Inc. Full time

    Job DescriptionJob DescriptionSummary: The Quality Assurance Analyst I will coordinate and perform quality assurance testing of computer programs and various program output data/files; and conduct various types of analysis including workflows and processes. Essential Duties and Responsibilities include the following. Other duties may be assigned.Works on...

  • Business Analyst

    2 weeks ago


    Sacramento, United States Oak Technical Inc Full time

    Oak Technical Services (OTS) is looking for a full time business analyst to work in a CA State PMO as a requirements business analyst. This will be a remote work position, but occasional attendance at the project office in downtown Sacramento may be required. This is an open current position; OTS offers paid time off and strong compensation. Work...

  • IT Business Analyst

    5 days ago


    Sacramento, United States Sabot Consulting Full time

    **IT Business Analyst - MMIS** **Location**: Remote **Salary**: $90-155k Sabot Consulting is seeking an IT Business Analyst that will play a crucial role in analyzing, designing, and implementing technical solutions to meet our organization's business needs on a MMIS project. This role involves evaluating existing systems and processes, identifying areas...

  • IAM Analyst

    2 weeks ago


    Sacramento, United States Mindlance Full time

    Job Description:We are seeking a skilled and detail-oriented Identity and Access Management (IAM) Analyst to join our IT team. As an IAM Analyst, you will play a crucial role in maintaining the security and integrity of our organization's digital assets by ensuring appropriate user access and managing access privileges. You will be responsible for supporting...

  • Quantitative Analyst

    1 month ago


    Sacramento, California, United States California State Teachers' Retirement System Full time

    The CalSTRS Investments Branch is seeking an experienced individual to work as an Investment Officer II, CalSTRS on the Investment Strategy and Risk team.The Investment Strategy & Risk (ISR) team is responsible for managing the total fund, drawing on global best practices with the aim of building a resilient, globally diversified investment portfolio. The...


  • Sacramento, United States Cache Creek Casino Resort Full time

    Being a part of the Cache Creek team comes with amazing benefits:Great PayOpportunities to GrowGas DiscountsDental InsuranceLife InsurancePaid Time Off (PTO)Recognition ProgramFree meals in our Employee Dining Room Weekly PaychecksAffordable HealthcareMedical InsuranceVision Care Insurance401k Savings PlanTuition ReimbursementEmployee DiscountsDirect...


  • Sacramento, United States Cache Creek Casino Resort Full time

    Being a part of the Cache Creek team comes with amazing benefits:Great PayOpportunities to GrowGas DiscountsDental InsuranceLife InsurancePaid Time Off (PTO)Recognition ProgramFree meals in our Employee Dining Room Weekly PaychecksAffordable HealthcareMedical InsuranceVision Care Insurance401k Savings PlanTuition ReimbursementEmployee DiscountsDirect...


  • Sacramento, United States Cache Creek Casino Resort Full time

    Being a part of the Cache Creek team comes with amazing benefits:Great PayOpportunities to GrowGas DiscountsDental InsuranceLife InsurancePaid Time Off (PTO)Recognition ProgramFree meals in our Employee Dining Room Weekly PaychecksAffordable HealthcareMedical InsuranceVision Care Insurance401k Savings PlanTuition ReimbursementEmployee DiscountsDirect...

  • Actuarial Analyst

    3 days ago


    Sacramento, California, United States State Of California Full time

    Under the direction of the Actuary Supervisor, the Actuarial Analyst performs the preliminary actuarial reviews of insurer rates for Property and Casualty lines of business to ensure compliance with California regulations. Duties include, but are not limited to: reviewing the completeness of Property and Casualty rate and class plan applications, reconciling...

  • Business Analyst

    2 weeks ago


    West Sacramento, United States LanceSoft Full time

    Job Description: Minimum Techincal Qualifications: At least seven (7) years of experience within the last ten (10) years working as a Business Analyst with large organizations, leading or participating in the technical implementation of software/systems/applications automating complex business processes, performing all the following activities: Assessment...

  • Business Analyst

    5 days ago


    West Sacramento, United States LanceSoft Full time

    Job Description: Minimum Techincal Qualifications: At least seven (7) years of experience within the last ten (10) years working as a Business Analyst with large organizations, leading or participating in the technical implementation of software/systems/applications automating complex business processes, performing all the following activities: Assessment...


  • Sacramento, United States Sabot Consulting Full time

    Business Solutions Analyst Location : Sacramento, CA Onsite Salary : $90-165k Sabot Consulting is currently seeking a Business Solutions Analyst resource to lead and perform activities to establish and document needs, requirements, processes, policies, standards, rules, roles, and responsibilities necessary to manage a Data Catalog. This includes assisting...


  • Sacramento, United States Stantec Full time

    At Stantec, we believe that good design shapes and influences our lives. We strive to design purposeful spaces that are also meaningful for our communities. Join our team of creative professionals and work with us to create inspiring spaces for all. Our office is looking to hire a professional Project Controls Analyst to support our growing team. Your...


  • Sacramento, United States Stantec Full time

    At Stantec, we believe that good design shapes and influences our lives. We strive to design purposeful spaces that are also meaningful for our communities. Join our team of creative professionals and work with us to create inspiring spaces for all. Our office is looking to hire a professional Project Controls Analyst to support our growing team. Your...


  • Sacramento, California, United States Proofpoint Full time

    It's fun to work in a company where people truly BELIEVE in what they're doingWe're committed to bringing passion and customer focus to the business.Senior People Data AnalystThis position will play a critical role in uncovering actionable insights from complex data sets to inform strategic decision-making across the organization. This role will collaborate...


  • Sacramento, California, United States Proofpoint Full time

    It's fun to work in a company where people truly BELIEVE in what they're doingWe're committed to bringing passion and customer focus to the business.Senior People Data AnalystThis position will play a critical role in uncovering actionable insights from complex data sets to inform strategic decision-making across the organization. This role will collaborate...


  • West Sacramento, United States Estrada Consulting Incorporated Full time

    **Job Details**: - Assessment of analysis scope and tasks. - Planning business analysis tasks. - Elicitation, definitions and documentation of various business, user, and system requirements. - Modeling and documenting functional requirements. **At least seven (7) years of experience within the last ten (10) years producing business analysis deliverables...


  • Sacramento, United States LanceSoft Full time

    Job Title: Project Controls AnalystLocation: REMOTE FROM HOME IN CALIFORNIA TO START - Then HYBRID FROM PG&E OFFICEDuration: Temp-to-Hire (after 520 hours worked Minimum) Pay Rate Range $55 - $65/Hourly on W2MANAGER COMMENTS/REQUIREMENTS: Client has kicked off the largest program in the history of the utility sector - Undergrounding of Electric distribution...


  • Sacramento County, CA, United States Public Employees Retirement System Full time

    **Anticipated Interview Dates**: We anticipate holding virtual interviews the week of June 3, 2024. **Telework Information**: This position is eligible for a hybrid work schedule, with up to two days of remote work and three days or more onsite, per week. Do you have a passion for Compliance and Risk Management? Do you enjoy creating and maintaining...