Security GRC Specialist II
2 months ago
At Kirkland & Ellis, we are united in our ambition and drive to move forward. We share core values that help us achieve excellence: collaboration, talent empowerment, service, inclusion, respect and gratitude. Our people are our greatest asset, and we invest in the brightest talent and encourage a diversity of perspectives and strengths to create dynamic teams that operate at the pinnacle of their field. Our talented professionals show up every day knowing they will engage in meaningful work, continuous learning and professional development.
As one of the world's leading law firms, we serve a broad range of clients with market-leading practices in private equity, M&A and other complex corporate transactions; investment fund formation and alternative asset management; restructurings; high-stakes commercial and intellectual property litigation; and government, regulatory and internal investigations. We handle the most complicated and sophisticated legal matters because we don't just meet industry standards, we create them. We bring innovation and entrepreneurialism to every engagement and, as a result, have long-standing client relationships with leading global corporations and financial sponsors. With 6,500 employees (including 3,500 lawyers) operating from 20 offices across the United States, Europe, the Middle East and Asia, we are one of the largest law firms in the world and a top financial performer.
Essential Job Functions
The Security GRC Specialist II is a key member of the Governance, Risk, and Compliance (GRC) team, leading and executing various services within the team. This role requires expertise in Information Security, providing consulting to both technical and non-technical management and user community, and performing essential risk and compliance management functions within the Security Governance department. Key GRC services include Enterprise Risk Management (ERM), managing the lifecycle of policies and standards, overseeing the Security Vendor Risk program, managing the Security Awareness program, ensuring Controls Assurance, conducting vendor and client risk assessments, and administering GRC platforms and tools.
Current openings will focus on Enterprise Risk, Compliance Management, Cyber Risk Quantification (CRQ).
ESSENTIAL FUNCTIONS
- Lead process improvements, enhance control maturity, and communicate risk across assigned GRC service activities, incorporating NIST and ISO 27001 principles for continuous improvement. Apply the FAIR framework to enhance risk assessment accuracy and effectiveness.
- Lead efforts in risk quantification to assess and prioritize risks. Design, implement, and maintain a Risk Certification Framework that ensures all risk management activities align with industry standards and internal policies.
- Develop and deliver detailed risk reports that provide actionable insights to senior management. Leverage CRQ methodologies to support data-driven decision-making and risk communication.
- Lead the creation and maintenance of security policies, standards, processes, guidelines, and support documentation.
- Lead and support processes to ensure IT systems meet cybersecurity and risk requirements. Conduct evaluations of IT programs or components for compliance with published standards, manage exceptions, and process requests for exceptions to security controls.
- Ensure appropriate treatment of risk, compliance, and assurance from both internal and external perspectives.
- Serve as a subject matter expert for Information Security, consulting with technical and non-technical clients, management, and staff.
- Respond to security assessments, questionnaires, and audits from clients and third-party business partners promptly. Document and perform assessments as needed and review contracts for security requirements.
- Ensure security awareness training is aligned, defined, and executed. Evaluate cyber training/education courses and methods based on instructional needs.
- Administer the GRC technology platforms.
Education, Work Experience, Skills
- Bachelor's degree or five (5) years of work experience in IT Security is required.
- Four (4) years of Information Security experience required, with hands-on technical experience preferred.
- Strong understanding of Cyber Risk Quantification is required (risk quantification methodologies and applying statistical analysis to evaluate and prioritize risks.)
- Proficiency in statistical analysis and quantitative methods, particularly in the context of risk management and reporting.
- Strong knowledge of Security frameworks and technologies such as ISO 27001, NIST, SOC, SIG are required.
- FAIR Framework experience required. Hands-on experience with the FAIR framework, with the ability to apply its principles to evaluate and manage information security risks.
- Technical writing experience is required, with a preference for instructional content and educational writing.
- Strong communication skills, including message creation and verbal presentations, with tact and diplomacy, are required.
- Strong knowledge of risk management principles and practices required.
- Strong knowledge of security administration and role-based security controls required.
- Three or more years of experience managing timelines and being self-directed is preferred.
- Experience in managing GRC tools (administrative and/or engineering) is preferred.
- Ability to interview, gather, and understand content from subject-matter experts.
- Maintain accurate records and manage client security and risk requests required.
- Ability to complete and assist in client security questionnaires, vendor risk, and security assessments regarding the firm's security program and controls.
- Demonstrate the ability to communicate technical topics effectively to varied audiences, including IT Subject Matter Experts, senior management, and non-technical users.
- Communicate succinctly and effectively.
- Prior IT Security experience in the legal industry is preferred.
- Strong organizational and problem-solving skills are required.
- Strong project and time management skills are required.
- Ability to work independently and as a team member is required.
- Hands on experience of Quantitative Risk Management applications/platforms required.
- Broad awareness of and exposure to diverse security tools and their capabilities, including commercial and open-source options.
- Strong knowledge of risk management principles and practices.
- Strong knowledge of security administration and role-based security controls.
- Strong knowledge and use of GRC platforms.
- Knowledge of host and network-based anti-malware technologies.
- Knowledge of authentication technologies and interactions between diverse authentication platforms, both on-site and remote.
- Knowledge of client and server firewalling technologies and capabilities.
- Knowledge of security event management (SIEM), event correlation and analysis technologies.
- Knowledge of data encryption technologies.
- Strong knowledge of Intrusion Detection and Intrusion Prevention technical capabilities.
- Knowledge of web filtering and email SPAM prevention techniques.
- Knowledge of vulnerability assessment and forensic investigations tools.
- Knowledge of mobile device security and Mobile Device Management solutions.
- Knowledge of Privileged Access Management technologies.
- Certified Information Systems Security Professional (CISSP), Certified Information Security Auditor (CISA), Certified Information Security Manager (CISM), FAIR Training and Certifications, or other relevant training and certifications are preferred.
How to Apply
Thank you for your interest in Kirkland & Ellis LLP. To complete an application and submit your resume, please click "Apply Now."
Equal Employment Opportunity
All employment decisions, including the recruiting, hiring, placement, training availability, promotion, compensation, evaluation, disciplinary actions, and termination of employment (if necessary) are made without regard to the employee's race, color, creed, religion, sex, pregnancy or childbirth, personal appearance, family responsibilities, sexual orientation or preference, gender identity, political affiliation, source of income, place of residence, national or ethnic origin, ancestry, age, marital status, military veteran status, unfavorable discharge from military service, physical or mental disability, or on any other basis prohibited by applicable law.
Closing Statement
The www.kirkland.com job postings and recruiting mailbox are for candidates only. If you are a recruiter, search firm or employment agency, and do not have a signed contract with Kirkland & Ellis LLP ("K&E") and have not been asked specifically to submit candidates, you will not be compensated in any way for your referral of a candidate even if K&E hires the candidate. Direct contact with K&E employees in an attempt to present candidates is inappropriate and will be a factor in determining any future professional relationship with the Firm. #LI-Hybrid #LI-JN1
-
GRC Technology Specialist
4 weeks ago
Austin, Texas, United States Wipro Full timeJob Description:We are seeking a highly skilled GRC Technology Analyst to join our team at Wipro. As a key member of our team, you will be responsible for building complex reports using IBM Cognos Analytics 11.0 and higher versions.Key Responsibilities:Design and build relational and dimensional reports using Cognos Analytics.Develop strong SQL skills to...
-
Governance, Risk and Compliance
3 months ago
Austin, United States Texas Department of Aging & Disability Services Full timeJob Description: As a Cybersecurity Analyst III at the Texas Department of Family and Protective Services (DFPS) you will have at least three years of related experience and be responsible for developing and implementing effective governance frameworks, risk management strategies, and compliance programs to mitigate potential risks and ensure adherence to...
-
Senior Information Security GRC Analyst
4 weeks ago
Austin, United States DISCO Full timePROFILE SUMMARY The Information Security GRC Analyst supports the security governance and risk and compliance programs. They perform reviews, assessments, and audits, conduct research, and facilitate communication to internal and external stakeholders where necessary. They monitor, coordinate, and implement documentation to support security, compliance, and...
-
GRC Technology Analyst
1 month ago
austin, United States Wipro Full timeLocation: Austin, TXOnsiteJob Description:* Good experience in building relational & dimensional reports using IBM Cognos Analytics 11.0 and higher versions.* Should be strong in SQL to work on complex queries in SQL Server database and Oracle databases* Basic Cognos admin experience for L2 support like setting security, providing Cognos access to users,...
-
GRC Technology Analyst
2 months ago
Austin, United States Wipro Full timeLocation: Austin, TXOnsiteJob Description:* Good experience in building relational & dimensional reports using IBM Cognos Analytics 11.0 and higher versions.* Should be strong in SQL to work on complex queries in SQL Server database and Oracle databases* Basic Cognos admin experience for L2 support like setting security, providing Cognos access to users,...
-
Security Specialist
2 months ago
Austin, United States Security Industry Specialists Full timeAbout this position: •Department: Operations •Location (City/State): Austin, TX •Employment Type: Full Time About us: Security Industry Specialists, Inc. (SIS) provides security solutions to some of the most recognized companies and brands in the world. We deliver services that consistently exceed those of our peers. We accomplish this through...
-
Security Officer
6 months ago
Austin, United States Priebe Security Services, Inc Full timeSecurity OfficerSecurity Officer Benefits:Competitive pay structure - yearly pay increases!Comprehensive benefitsPaid time offCompany paid Gold's Gym membershipProfessional developmentCareer advancement opportunitiesQuality work environments that value their well-being, diversity and individuality.In honor of your previous Military Service, Priebe Security...
-
Cybersecurity Governance Specialist
1 month ago
Austin, Texas, United States Texas Department of Aging & Disability Services Full timeJob Title: Cybersecurity Governance SpecialistAs a Cybersecurity Governance Specialist at the Texas Department of Family and Protective Services (DFPS), you will play a critical role in developing and implementing effective governance frameworks, risk management strategies, and compliance programs to mitigate potential risks and ensure adherence to industry...
-
Security Manager
3 weeks ago
austin, United States Priebe Security Services, Inc. Full timeThe Security Manager will serve as liaison between Priebe Security and client contracted Security team. This position directly reports to the Division Manager, and is responsible for overall management of property safety and security program including security officer staffing and performance. Motivates and develops staff by providing leadership and...
-
Security Manager
3 weeks ago
Austin, United States Priebe Security Services, Inc. Full timeThe Security Manager will serve as liaison between Priebe Security and client contracted Security team. This position directly reports to the Division Manager, and is responsible for overall management of property safety and security program including security officer staffing and performance. Motivates and develops staff by providing leadership and...
-
Security Manager
3 weeks ago
Austin, United States Priebe Security Services, Inc. Full timeThe Security Manager will serve as liaison between Priebe Security and client contracted Security team. This position directly reports to the Division Manager, and is responsible for overall management of property safety and security program including security officer staffing and performance. Motivates and develops staff by providing leadership and...
-
Security Manager
3 weeks ago
austin, United States Priebe Security Services, Inc. Full timeThe Security Manager will serve as liaison between Priebe Security and client contracted Security team. This position directly reports to the Division Manager, and is responsible for overall management of property safety and security program including security officer staffing and performance. Motivates and develops staff by providing leadership and...
-
Program Specialist II
1 month ago
Austin, Texas, United States Texas Department of Aging & Disability Services Full timeJob Summary: We are seeking a highly skilled and motivated Program Specialist II to join our team at the Texas Department of Aging & Disability Services. This role will work under minimal supervision from the Continuous Quality Improvement (CQI) Team Manager, within the Immunization Information System (IIS) Unit. The successful candidate will be responsible...
-
Data Security Specialist
4 weeks ago
Austin, Texas, United States IDR, Inc. Full timeData Security SpecialistPosition Overview:A data security specialist is needed to join our team at IDR, Inc. in Austin, TX. As a key member of our cybersecurity team, you will be responsible for performing queries and generating reports about fraud trends using security and fraud analysis tools. Your expertise in risk management frameworks and security...
-
QA Specialist II
3 weeks ago
Austin, United States Experis Full timeOur client, the medical device manufacturing industry, is seeking a QA Specialist II to join their team. The ideal candidate should have heavy documentation and quality control, which will align successfully with the organization. Job Title: QA Specialist II Location: Boulevard, Austin, TX 78759 Pay Range:$32/hr on W2 Duration : 9-month...
-
IT Support Specialist II
1 month ago
Austin, Texas, United States TEXAS DEPARTMENT OF MOTOR VEHICLES Full timeJob SummaryWe are seeking a highly skilled IT Support Specialist II (Hybrid) to join our team at the Texas Department of Motor Vehicles. As a key member of our Information Technology Services Division, you will provide technical support for our computing environment, including desktop computers, laptops, tablets, printers, scanners, and other related...
-
Grant Specialist II-IV
1 month ago
Austin, Texas, United States GENERAL LAND OFFICE Full timeJob SummaryThe GENERAL LAND OFFICE is seeking a highly skilled Grant Specialist II-IV to join our team. As a key member of our CDR-Grant Management program area, you will be responsible for performing grant development, coordination, and administration work.Key ResponsibilitiesMonitor grant and/or contract budgets for timely and compliant expenditures in...
-
Target Security Specialist
2 months ago
Austin, United States Target Full timeTarget - 10107 Research Blvd [Asset Protection / Loss Prevention] As a Security Specialist at Target, you'll: Contribute to a team in the development of a secure work environment for all Target team members, temporary workers, vendors and visitors; Execute routines to identify and investigate theft; Help advance Assets Protection partnerships through...
-
Target Security Specialist
7 hours ago
Austin, United States Target Full timeTarget - 8601 Research Blvd [Asset Protection / Loss Prevention] As a Security Specialist at Target, you'll: Contribute to a team in the development of a secure work environment for all Target team members, temporary workers, vendors and visitors; Execute routines to identify and investigate theft; Help advance Assets Protection partnerships through...
-
Security Administrator Specialist
2 months ago
Austin, United States Smart IMS Full timeThe Department of Information Resources (DIR) requires the services of (1) Security Administrator- Specialist hereafter referred to as Worker, who meets the general qualification of Security Administrator Specialist and the specifications outlined in this document for Texas Parks and Wildlife Department. Conduct Supply Chain Risk (third party hosted...