GRC Information Security Analyst
3 weeks ago
Build an Aviation Career You're Proud Of
At StandardAero, we use our ingenuity and know-how to find solutions for the simple to the most complex challenges in aviation. Together, we get the job done and done well. Our stability, resources, and respectful culture supports you in building a solid career with a great team you can count on day in and day out for the long term.
Working as part of the Information Security office under the CISO, within the IT department at StandardAero, the GRC Analyst will be responsible for leading the day-to-day Information Security and Cybersecurity compliance requirements, data governance, and information security risk management functions. The role will include primary responsibility for defining, creating, and managing Information Security Policies and Standards including exception management, Key Risk Indicator (KRI) reporting as well as overall Information Security program management support.
The GRC Analyst will also support the development and maintenance of an organization wide Cyber Education and awareness program to include awareness communications, training course development, and social engineering testing.
Responsibilities include:
- Develop IT and organizational policies and standards in support of legal and regulatory compliance needs as well as general IT and organizational information security practices.
- Identify key cybersecurity requirements for StandardAero based on understanding the organization business objectives, cybersecurity risk appetite and considering: key threats, regulatory, legal and customer requirements, and technology trends.
- This role oversees compliance with Information Security Policies and Standards including exception management, Key Risk Indicator (KRI) reporting as well as overall Program Management support.
- Support the development and maintenance of the risk register, tracking identified risks and remediation efforts.
- Work with leadership to prioritize and remediate risks based on potential impact.
- Partners with Third-Party Risk Management (TPRM) to continuously improve the TPRM program as the subject matter experts for Information Security and Cyber Security.
- Completes vendor assessments for engagements, including management reporting.
- Responsible for identifying, prioritizing, monitoring and reporting technology risks and controls including performing risk and controls assessments.
- Works closely with the operational, technical, and corporate function personnel to foster a technology risk management culture, challenge assumptions and to assist in communicating a holistic risk profile of technology risk to management and various stakeholders.
- Collaborate closely with the legal department to provide oversight of customer's cyber security compliance requirements reporting.
- Interfaces between both internal and external auditors for compliance initiatives, including providing requested audit inputs.
- Stay current on security industry trends, relevant federal government and customer specific compliance requirements, and security best practices.
- Provides assistance to system users relative to information systems security matters.
- Creates information security and cyber awareness communications and training content for all employees.
- Assists with social engineering testing and remedial training for all employees.
- Supports the overall program management function including KRI and metric reporting, audit, and roadmap reporting for senior management.
- Advise internal customers on applicability and interpretation of the standards' requirements.
- Interact with related stakeholders to ensure consistent application of cybersecurity policies and standards.
- Other duties may be assigned.
Requirements
- Must be authorized to work in the U.S.
- Bachelor's degree in a related field and/or two (4) years of work-related experience in Information Security or Information Technology.
- Travel as required (up to 10%).
Preferences
- Certified Information Systems Security Professional (CISSP), Certified Information Systems Auditor (CISA) or other industry certification.
- 4+ years of work related experience in information technology.
- 4+ years of work related experience in IT Risk, Compliance, Audit and/or Advisory.
- Must have and maintain or be able to obtain within one year of employment at least one of the following certification: CISSP, CISA, CRISC or equivalent designation.
- Familiarity with technology processes, risks and issues including within infrastructure, information security, SDLC and Enterprise Service Management utilizing various IT controls frameworks, NIST Risk Management Framework Special Publication 800-53, NIST 800-171 family of controls.
Benefits that make life better:
- Comprehensive Healthcare
- 401(k) with 100% company match; up to 5% vested
- Paid Time Off starting on day one
- Bonus opportunities
- Health- & Dependent Care Flexible Spending Accounts
- Short- & Long-Term Disability
- Life & AD&D Insurance
- Learning & Training opportunities
Raising the Standard of Excellence since 1911
With over a century of proven excellence, StandardAero has become an industry leader in MRO services and customized solutions in the aerospace field. Our shared values and learning-based culture inspire our team to exceed their potential and power our customers' missions worldwide. With on-the-job training, advancement opportunities, and excellent benefits, StandardAero invites you to experience a fulfilling and meaningful career with us.
Inclusivity Is Our Standard
StandardAero offers equal employment opportunities for all. Our supportive environment celebrates diversity with no room for harassment or discrimination of any kind. We invite you to bring your authentic self to our team and experience our welcoming culture.
-
GRC Analyst
2 days ago
Dallas, Texas, United States Futran Tech Solutions Pvt. Ltd. Full timeGRC Analyst Full Time Dallas Tx - Hybrid FOCUS • Ensure secure communications systems relied upon for our ANSP Program, with concentrated attention towards risk, governance, vulnerability management, policies, and standards. RESPONSIBILITIES • Develop and implement security policies and standards, ensuring compliance with industry regulations and best...
-
GRC Analyst
3 weeks ago
Dallas, Texas, United States Diverse Lynx Full timeJC# - 40110 GRC Analyst Full Time Dallas Tx - Hybrid FOCUS • Ensure secure communications systems relied upon for our ANSP Program, with concentrated attention towards risk, governance, vulnerability management, policies, and standards. RESPONSIBILITIES • Develop and implement security policies and standards, ensuring compliance with industry regulations...
-
GRC analyst
6 days ago
Dallas, Texas, United States Futran Tech Solutions Pvt. Ltd. Full timeJob Details Wipro Limited (NYSE: WIT, BSE: 507685, NSE: WIPRO) is a leading technology services and consulting company focused on building innovative solutions that address clients' most complex digital transformation needs. Leveraging our holistic portfolio of capabilities in consulting, design, engineering, and operations, we help clients realize their...
-
GRC Analyst
23 hours ago
Dallas, Texas, United States Concord Servicing Full timeJob Description Job Description Concord Servicing, is a full-scope loan servicer delivering compliant, flexible, and scalable portfolio servicing solutions to meet the demands of loan originators and capital providers – and their customers – in multiple asset classes. Concord is seeking an enthusiastic and detail-oriented entry-level GRC Analyst to join...
-
GRC Analyst
22 hours ago
Dallas, Texas, United States Concord Servicing Full timeConcord Servicing, is a full-scope loan servicer delivering compliant, flexible, and scalable portfolio servicing solutions to meet the demands of loan originators and capital providers – and their customers – in multiple asset classes. Concord is seeking an enthusiastic and detail-oriented entry-level GRC Analyst to join our team. This role offers a...
-
IT Security Analyst
1 week ago
Dallas, Texas, United States Addison Group Full timeJob Description Job Description Job Title: IT Security Analyst - GRCSalary Expectations: $ K - 15% target bonus6-month contract to hireLocation: Irving, TX, USMy Notes:We are looking to bring on an IT Security Analyst - GRC who will play a crucial role in developing, implementing, and maintaining a strong IT security governance framework and practices. We...
-
Information Security Consultant
6 days ago
Dallas, Texas, United States Futran Tech Solutions Pvt. Ltd. Full time**Key Responsibilities**The GRC analyst will be responsible for:Developing and implementing security policies and standards to ensure compliance with industry regulations and best practices.Conducting risk assessments and vulnerability assessments to identify and mitigate security risks.Managing the vulnerability management program, including vulnerability...
-
GRC Analyst
1 week ago
Dallas, Texas, United States Wipro Full timeWipro Limited (NYSE: WIT, BSE: 507685, NSE: WIPRO) is a leading technology services and consulting company focused on building innovative solutions that address clients' most complex digital transformation needs. Leveraging our holistic portfolio of capabilities in consulting, design, engineering, and operations, we help clients realize their boldest...
-
Senior GRC Analyst
4 weeks ago
Dallas, Texas, United States Insight Global Full time• Insight Global is looking for a Senior GRC Analyst to join one of their utility clients in the DFW area. • • • This individual will be responsible for assisting with the implementation of AuditBoard • Responsibilities will include implementing frameworks and controls within GRC tools, working heavily with policies, processes, procedures and...
-
Principal Information Security Analyst
2 days ago
Dallas, Texas, United States Southern Glazer's Wine & Spirits Full timeOverview The Principal Information Security Risk Analyst is responsible for assessing IT risk both internally as well as third parties to help secure SGWS data and information. The person in this position will need to have extensive knowledge of information security risk and third-party risk management, as well as the various technologies within the...
-
Cyber security with GRC
2 weeks ago
Dallas, Texas, United States ARK InfotechSpectrum Full timeRole: Cyber security with GRCLocation: Dallas, TX Only US Citizen, Role Summary & Key Responsibilities: Lead the design and architecture of GRC solutions that integrate risk assessments, DR planning, privacy controls, and regulatory...
-
GRC Operations Manager
6 days ago
Dallas, Texas, United States Futran Tech Solutions Pvt. Ltd. Full time**The Ideal Candidate**We are looking for a highly skilled and experienced GRC analyst who can lead our security efforts.The ideal candidate will have strong communication and stakeholder collaboration skills to effectively communicate security risks, governance strategies, and policy recommendations to diverse stakeholders, including technical teams,...
-
Sr GRC Analyst
4 weeks ago
Dallas, Texas, United States UT Southwestern Medical Center Full timeWHY UT SOUTHWESTERN? With over 75 years of excellence in Dallas-Fort Worth, Texas, UT Southwestern is committed to excellence, innovation, teamwork, and compassion. As a world-renowned medical and research center, we strive to provide the best possible care, resources, and benefits for our valued employees. Ranked as the number 1 hospital in Dallas-Fort...
-
Sr GRC Analyst
1 day ago
Dallas, Texas, United States UT Southwestern Medical Center Full timeWHY UT SOUTHWESTERN? With over 75 years of excellence in Dallas-Fort Worth, Texas, UT Southwestern is committed to excellence, innovation, teamwork, and compassion. As a world-renowned medical and research center, we strive to provide the best possible care, resources, and benefits for our valued employees. Ranked as the number 1 hospital in Dallas-Fort...
-
Technical GRC Consultant
1 day ago
Dallas, Texas, United States United Software Group Full timeJob Responsibilities:As a Technical GRC Consultant, you will play a critical role in designing and developing scalable, open applications using Java, C#, and JavaScript. You will also perform server-side configuration management of the RSA Archer Control Panel, develop API interfaces for integration with RSA Archer, and implement risk management frameworks...
-
SAP GRC Consultant-Enterprise Platform
3 weeks ago
Dallas, Texas, United States TEPHRA Full time:Job Description (Please provide summary of the position):• Excellent communication skill with process understanding• hands on experience of GRC access control on version 5.3 and 10.1• Experience in role design and change management process• Good knowledge of security concepts in ECC, SRM, HANA, BW and portal• Expert in SSO setup and...
-
SAP GRC Consultant-Enterprise Platform
5 days ago
Dallas, Texas, United States Tephra Inc. Full time: Job Description (Please provide summary of the position):• Excellent communication skill with process understanding• hands on experience of GRC access control on version 5.3 and 10.1• Experience in role design and change management process• Good knowledge of security concepts in ECC, SRM, HANA, BW and portal• Expert in SSO setup and...
-
SAP GRC Consultant-Enterprise Platform
4 weeks ago
Dallas, Texas, United States TEPHRA Full time: Job Description (Please provide summary of the position): • Excellent communication skill with process understanding • hands on experience of GRC access control on version 5.3 and 10.1 • Experience in role design and change management process • Good knowledge of security concepts in ECC, SRM, HANA, BW and portal • Expert in SSO setup and...
-
SAP GRC Consultant-Enterprise Platform
4 weeks ago
Dallas, Texas, United States Tephra Inc. Full time: Job Description (Please provide summary of the position):• Excellent communication skill with process understanding• hands on experience of GRC access control on version 5.3 and 10.1• Experience in role design and change management process• Good knowledge of security concepts in ECC, SRM, HANA, BW and portal• Expert in SSO setup and...
-
Enterprise GRC Professional
4 days ago
Dallas, Texas, United States Aditi Consulting Full timeWe are looking for a dedicated and experienced Enterprise GRC Professional to join our team at Aditi Consulting. As a critical member of our organization, you will be responsible for participating in developing and maintaining the overall Governance Risk and Compliance (GRC) management process and strategy from a compliance framework and oversight point of...