Senior Analyst, Information Security Governance, Risk, and Compliance

2 weeks ago


Madison Alabama, United States Hexagon Asset Lifecycle Intelligence Full time

Key Responsibilities:


As a vital member of the Corporate Information Security - Governance, Risk, and Compliance team, you will report directly to the Director of Information Security - Governance, Risk, and Compliance at Hexagon.

This role necessitates close collaboration with cross-functional teams across Hexagon divisions to effectively manage information security risks, ensuring adherence to all necessary compliance standards and regulations. This will be achieved through the establishment of governing policies, implementation of a robust security control framework, conducting thorough security risk and control assessments, and maintaining current knowledge of applicable compliance requirements.

Specific duties of a Senior Information Security GRC Analyst include:

1. Assisting in the development, implementation, and ongoing maintenance of the information security risk and controls program.


2. Supporting the execution and evaluation of a comprehensive information security controls framework while formulating innovative risk mitigation strategies in partnership with cross-functional teams.

3. Governing and reporting on findings, tracking progress, and ensuring that corrective actions are both complete and sustainable.

4. Engaging with both technical and non-technical stakeholders and leaders on topics related to information security risk and controls management, as well as program-specific reporting.


5. Keeping abreast of current cybersecurity threats, vulnerabilities, trends, and best practices to proactively enhance the information security risk and controls program.

6. Supporting the identification and assessment of information security risks, response and mitigation efforts, and control monitoring and reporting.

7. Collecting and evaluating information, including aiding auditors, investigations, and customer inquiries.

8. Developing and executing tests to assess the design and effectiveness of key controls as required for compliance.

9. Reviewing test findings, identifying control weaknesses, presenting results, and recommending actions to address issues.

10. Assisting in the completion of customer questionnaires.

11. Contributing to root cause analysis on incidents to uncover underlying causes.

12. Participating in the company’s business continuity plan and cybersecurity table-top exercises.

What distinguishes you?

- Possession of one or more relevant certifications (e.g., CRISC, CISSP, CISM, CISA, CCSP, ISO 27001 Lead Auditor)

- Proven ability to manage multiple projects, achieve critical milestones, and adapt priorities in a dynamic environment.

- Demonstrated effective engagement and ownership, showcasing a sense of urgency while ensuring accuracy and quality.

- Proficiency with Governance, Risk, and Compliance (GRC) systems.

Qualifications:
- Bachelor’s Degree in computer science, computer engineering, management information systems, information technology, or a related field. An equivalent combination of education, certifications, and experience may be considered in lieu of a degree.

- A minimum of 8 years of experience in an Information Security GRC role, with expertise and accomplishments directly relevant to this position.


- Familiarity with information security standards and compliance requirements such as ISO 27001, CIS Controls, NIST, CMMC, TISAX, GDPR, etc.

- Experience with IT/information security technologies and controls (e.g., cybersecurity, network, infrastructure, applications, cloud services, projects, etc.).

- Experience in implementing internal controls, including evaluating the design and operational effectiveness of controls.

- Advanced knowledge of testing techniques and data analysis principles, along with the ability to interpret results.

- Strong communication, presentation, and relationship management skills with both technical and non-technical audiences.

- Willingness to travel internationally.

- Proficiency in English (both written and verbal).

Citizenship Requirement:
Due to the nature of this position and its involvement with government-related contractual obligations, applicants must be U.S. citizens.

Hexagon will not sponsor applicants for a work visa for this position.

#LI-JS1

#LI-REMOTE
  • It Security

    1 month ago


    Madison, United States AMERICAN FAMILY MUTUAL INSURANCE CO Full time

    JOB REQUIREMENTS: Collaborates with others in the division to analyze security, threats, risks, and exposures, determines the causes of security deviations, and suggests procedures to halt future incidents and improve security. The analyst will develop techniques and procedures for conducting IS and cyber security analysis, risk assessments, and compliance...


  • Madison, Wisconsin, United States Information Resource group, Inc. Full time

    Job OverviewPosition: Cyber Security AnalystRole Summary: The Cyber Security Analyst will engage in a variety of proactive and reactive tasks aimed at safeguarding organizational assets and data integrity.Key Responsibilities:Identify and implement use cases and policies to manage emerging threats, enhancing the overall security framework.Collaborate with IT...


  • Alabama, United States SAIC Full time

    Position OverviewSAIC is seeking a dedicated Cybersecurity Specialist to join our team in a fully remote capacity. This role is pivotal in supporting the US Army Corps of Engineers Revolutionary IT Services (USACE RITS) program by overseeing the implementation, configuration, operation, and maintenance of an automated patch and vulnerability management...

  • Security Analyst II

    4 weeks ago


    Madison, United States Vision It US Full time

    Job DescriptionJob DescriptionCandidates MUST be WI residents or willing to relocate to WI at their own expense prior to starting. This position can work 100% remotely (within the state of WI).The Wisconsin Department of Natural Resources is looking for a Cyber Security Analyst with 5 - 7 years' experience in a medium to large company with a diverse user...


  • Madison, Wisconsin, United States Conselium Compliance Search Full time

    Position Overview:The Chief Officer of Compliance and Privacy is a pivotal role within our organization, overseeing the development and execution of comprehensive compliance and privacy strategies.Industry: HealthcareLocation: Wisconsin (on-site role with relocation package available)Why This Role Matters:Be part of a rapidly expanding organization with a...


  • Madison, United States Novalink Solutions LLC Full time

    Job DescriptionJob DescriptionThe Wisconsin Department of Natural Resources is looking for a Cyber Security Analyst with 5 - 7 years’ experience in a medium to large company with a diverse user base. The DNR is dedicated to the preservation, protection, effective management, and maintenance ofWisconsin's natural resources. DNR is responsible for...


  • Madison, United States Banner Defense, Inc. Full time

    Information Security Analyst Want to be part of a passionate and determined team? Join our team!Company Overview: Be a part of our passionate and determined team on a mission to use our skills and experiences to make a difference in the defense and aerospace industry!! Position Overview: In this role, you will orchestrate daily client delivery for the...


  • Madison, United States Banner Defense, Inc. Full time

    Job DescriptionJob DescriptionInformation Security AnalystWant to be part of a passionate and determined team?Join our team!Company Overview:Be a part of our passionate and determined team on a mission to use our skills and experiences to make a difference in the defense and aerospace industry!!Position Overview:In this role, you will orchestrate daily...


  • Madison, United States Sundial Software Full time

    The State of Wisconsin DNR is looking for one (1) Security Analyst II.The first-round posting was unsuccessful as we were looking for more of a “Security Generalist”. Someone who we could “plug and play” into various situations as they arose. Each individual was more of a specialist in one, maybe two domains. They were all very qualified, just not...

  • Security Analyst-III

    3 months ago


    Madison, United States Serigor Inc. Full time

    Job DescriptionJob DescriptionJob Title: Security Analyst-III (REMOTE)Location: Madison, WIDuration: 1+ MonthsJob Description:The service being provided through this RFS will be responsible for developing and maintaining system security plans, ensuring compliance with client policy, standards, and regulatory requirements, and conducting thorough security...


  • Madison, Wisconsin, United States General Dynamics Information Technology Full time

    Job Summary:The Information Systems Security Officer (ISSO) will be responsible for ensuring the appropriate operational security posture is maintained for an information system. This includes working in close collaboration with the Information Systems Security Manager (ISSM) and Information Security Officer (ISO) to manage the security aspects of an...


  • Alabama, United States Agilent Full time

    Position Overview Agilent is dedicated to fostering innovations that enhance the quality of life. We serve life science, diagnostic, and applied market laboratories globally with our advanced instruments, services, consumables, applications, and expertise. Our mission is to empower customers to uncover the insights they need to make impactful...


  • Madison, United States General Dynamics Information Technology Full time

    Type of Requisition:RegularClearance Level Must Currently Possess:Top Secret/SCIClearance Level Must Be Able to Obtain:Top Secret SCI + PolygraphSuitability:Public Trust/Other Required:NoneJob Family:Information SecurityJob Qualifications:Skills:Information Security, Information Security Management, Information System SecurityCertifications:Cisco Certified...


  • Madison, United States Vertex Limited Full time

    Information Systems Security Officer (ISSO) - "W-TRS" Working across the globe, V2X builds smart solutions designed to integrate physical and digital infrastructure from base to battlefield. We bring 120 years of successful mission support to improve security, streamline logistics, and enhance readiness. Aligned around a shared purpose, our $3.9B company and...

  • Credit Risk Analyst

    2 days ago


    Madison, Wisconsin, United States Infinity Systems Full time

    Job DescriptionAt Infinity Systems, we are seeking a highly skilled Credit Risk Analyst to join our team. As a Credit Risk Analyst, you will play a critical role in evaluating the creditworthiness of our corporate clients and ensuring the integrity of our lending practices.Key Responsibilities:Develop and maintain credit templates and contracts that meet the...


  • Madison, United States Banner Defense, Inc. Full time

    Job DescriptionJob DescriptionSenior Acquisition AnalystStep into a role where you can truly make a difference!Be a part of our passionate and determined team on a mission to use our skills and experiences to make a difference in the defense and aerospace industry.Position Description:Banner Defense is in search of a Senior Acquisition Analyst to serve the...


  • Madison, WI, United States General Dynamics Information Technology Full time

    Information Security Information Security, Information Security Management, Information System Security Certifications: Cisco Certified Network Associate (CCNA) Security - Cisco, GICSP: Global Industrial Cyber Security Professional - Global Information Assurance Certification (GIAC), GSEC: GIAC Security Essentials Certification - Global Information...


  • Madison, United States Tanson Corp Full time

    Job DescriptionJob DescriptionDescription:This is a repost. Please do NOT submit previous candidates. PLEASE SEE UPDATED JOB DESCRIPTION ATTACHMENT AND REQUIRED SKILLS. The first-round posting was unsuccessful as we were looking for more of a "Security Generalist". Someone who we could "plug and play" into various situations as they arose. Each individual...


  • Madison, Wisconsin, United States Sundial Software Full time

    Position Overview: The State of Wisconsin Department of Natural Resources (DNR) is seeking a qualified individual for the role of Security Analyst II. This position requires a versatile professional who can adapt to various security challenges as they arise.About the Department: The Wisconsin DNR is committed to the stewardship of the state's natural...


  • Alabama, United States Agilent Full time

    Position Overview Agilent is dedicated to fostering innovations that enhance life quality. We equip laboratories globally in life sciences, diagnostics, and applied markets with essential instruments, services, consumables, and expert guidance. Our mission is to empower clients to uncover the insights they need to make impactful contributions to...