Sr IT Controls
6 days ago
Medline is looking for a Senior IT Controls & Risk Specialist to play a critical role in establishing and managing an IT controls framework for the enterprise. Reporting to the IT Controls & Risk Manager, this position will lead the design, development, and implementation of information and technology risk management policies, standards, processes, and best practices and drive adoption through effective enterprise change management, education and awareness. Additionally, the specialist will evaluate the compliance of new and existing technology solutions against applicable controls.
Job Description
MAJOR RESPONSIBILITIES
Controls Framework Design, Implementation, and Management
- Control Framework Development: Analyze, design, create, and maintain a unified IT controls framework drawing from leading industry frameworks and applicable regulatory requirements (e.g. NIST CSF, CIS, HITRUST, PCI, etc.)
- Documentation: Create comprehensive documentation for the controls framework, including risks, control objectives, and implementation guidelines. Align with existing enterprise policies and develop policies to fill identified gaps.
- Stakeholder Engagement: Collaborate with cross-functional teams to ensure stakeholder buy-in and alignment with organizational risk tolerance.
- Compliance Evaluation: Assess new and existing technologies for compliance with applicable controls.
- Risk Register Management: Maintain a risk register to manage non-compliance and track remediation efforts.
- Tool Administration: Lead the configuration of GRC tools used for IT risk management processes.
- Material Development: Develop tailored written and verbal awareness materials for different audiences, supporting user education initiatives.
- Drive communication campaigns to ensure employee adoption using metrics to measure and track success.
- Communication Planning: Execute a communication plan for impacted audiences when process and policy changes are made.
- Relationship Building: Build trusted relationships with IT Compliance, Information Security, Legal, and Corporate Compliance teams to ensure message alignment and cross-functional collaboration.
Education
Bachelor's Degree in Information Technology, Information Security, Risk Management, Business Administration, or related field. Or equivalent combination of education, professional certifications, and relevant work experience.
Certification / Licensure
None required.
Work Experience
3+ years professional experience within IT Controls and Frameworks, IT Risk Management, IT Internal Controls, or related GRC field.
Knowledge / Skills / Abilities
- Experience developing or maintaining a controls-based IT compliance framework
- Experience evaluating or auditing web-based software technologies against company or regulatory requirements
- Experience deploying or supporting risk management, compliance, information security, information governance, or privacy programs across a large enterprise
- In-depth understanding of NIST CSF, CIS, NIST 800-53, HITRUST, CMMC, PCI DSS, or similar frameworks. Ability to describe framework scope, composition, and implementation strategies.
- Familiar with the technical components of software technologies, including APIs, web services, and common web and cloud application integration and architecture patterns
- Experience with modern GRC tools and other technologies supporting IT risk management activities
- Experience applying change management methodologies to support IT risk management initiatives
- Strong written and verbal skills, including a demonstrated ability to translate complex or technical information into concepts that are easily understood
- Proven ability to effectively interact with, manage, and influence cross-functional teams and partners
8+ years of professional experience in Technology Risk, Information Security, or leadership role in a technical area within a highly regulated industry.
Certification / Licensure
Certification in relevant GRC discipline (e.g., CISA, CISM, CRISC, CISSP, CGRC) or IT governance frameworks (e.g., ITIL).
Knowledge / Skills / Abilities
- Experience implementing or using AuditBoard CrossComply, AuditBoard ITRM, or other TPRM, Privacy, or GRC tools
- Participation in IT compliance and audit processes
- Experience organizing process information and technical concepts into a knowledge base for wider audience consumption, leveraging diagrams or infographics and knowledge management tools
- Experience driving successful, insight-based, creative communications plans that deliver against program objectives, on time and within budget
- Experience deploying policy or technology changes across a large enterprise and measuring and reporting program process over time.
- Understanding of fundamental Information Governance concepts (e.g., records retention, data protection, data handling)
- Knowledge of enterprise change management methodologies
- Familiarity with SAP security model and its integration with GRC products
- Familiarity with M365 governance and compliance settings
Medline Industries, LP, and its subsidiaries, offer a competitive total rewards package, continuing education & training, and tremendous potential with a growing worldwide organization.
The anticipated salary range for this position:
$96,200.00 - $144,560.00 Annual
The actual salary will vary based on applicant's location, education, experience, skills, and abilities. This role is bonus and/or incentive eligible. Medline will not pay less than the applicable minimum wage or salary threshold.
Our benefit package includes health insurance, life and disability, 401(k) contributions, paid time off, etc., for employees working 30 or more hours per week on average. For a more comprehensive list of our benefits please click here. For roles where employees work less than 30 hours per week, benefits include 401(k) contributions as well as access to the Employee Assistance Program, Employee Resource Groups and the Employee Service Corp.
We're dedicated to creating a Medline where everyone feels they belong and can grow their career. We strive to do this by seeking diversity in all forms, acting inclusively, and ensuring that people have tools and resources to perform at their best. Explore our Belonging page here.
Medline Industries, LP is an equal opportunity employer. Medline evaluates qualified individuals without regard to race, color, religion, gender, gender identity or expression, sexual orientation, national origin, age, disability, neurodivergence, protected veteran status, marital or family status, caregiver responsibilities, genetic information, or any other characteristic protected by applicable federal, state, or local laws.
-
Sr Analyst IT Internal Controls
2 weeks ago
Northbrook, IL, United States Medline Full timeJob Summary We are seeking a highly motivated and experienced Senior IT Internal Controls Analyst to grow Medline's IT Internal Controls program. This person will play a key role in ensuring our IT systems and processes comply with regulations and industry best practices. A successful candidate will have experience designing, documenting, testing, and...
-
Sr. Field Maintenance Technician
6 days ago
Northbrook, IL, United States Waterway Carwash Full timeOverviewWaterway Carwash has an immediate opportunity for a multi-facility Sr. Field Maintenance Technician supporting Waterways Chicago locations. This position performs and coordinates all necessary and ongoing maintenance of the car wash systems and technology while simultaneously being responsible for each location's preventative maintenance schedule,...
-
Sr. Field Maintenance Technician
3 days ago
Northbrook, IL, United States Waterway Carwash Full timeOverviewWaterway Carwash has an immediate opportunity for a multi-facility Sr. Field Maintenance Technician supporting Waterways Chicago locations. This position performs and coordinates all necessary and ongoing maintenance of the car wash systems and technology while simultaneously being responsible for each location's preventative maintenance schedule,...
-
Sr. Field Maintenance Technician
2 weeks ago
Northbrook, IL, United States Waterway Carwash Full timeOverviewWaterway Carwash has an immediate opportunity for a multi-facility Sr. Field Maintenance Technician supporting Waterways Chicago locations. This position performs and coordinates all necessary and ongoing maintenance of the car wash systems and technology while simultaneously being responsible for each location's preventative maintenance schedule,...
-
Sr. Field Maintenance Technician
2 weeks ago
Northbrook, IL, United States Waterway Carwash Full timeOverviewWaterway Carwash has an immediate opportunity for a multi-facility Sr. Field Maintenance Technician supporting Waterways Chicago locations. This position performs and coordinates all necessary and ongoing maintenance of the car wash systems and technology while simultaneously being responsible for each location's preventative maintenance schedule,...
-
Sr. EHS Auditor
1 week ago
Northbrook, IL, United States CF Industries Full timeAt CF Industries, our mission is to provide clean energy to feed and fuel the world sustainably. Our employees are focused on safe and reliable operations, environmental stewardship, and disciplined capital and corporate management. By joining CF, you will be part of a team that brings their varied experiences, wide-ranging knowledge and diverse talents...
-
Sr. EHS Auditor
2 weeks ago
Northbrook, IL, United States CF Industries Full timeAt CF Industries, our mission is to provide clean energy to feed and fuel the world sustainably. Our employees are focused on safe and reliable operations, environmental stewardship, and disciplined capital and corporate management. By joining CF, you will be part of a team that brings their varied experiences, wide-ranging knowledge and diverse talents...
-
Sr Analyst Business Systems IT
3 days ago
Northbrook, IL, United States Medline Full timeJob Summary This is your opportunity to make a real impact with an industry leader and Chicago Tribune Top Workplace that has experienced double digit growth for last 50+ years. Medline is seeking a talented individual with knowledge of and experience with the Coupa application. This role requires attention to detail, strong analytical skills, and the...
-
Sr Developer Analyst IT
6 days ago
Northbrook, IL, United States Medline Full timeJob Summary The Dynamics D365 Lead Developer Analyst is responsible for defining and leading the technical architecture for Microsoft Dynamics 365 Customer Service platform, with a primary focus on the customer service workspace. This role will be responsible for the development of scalable, secure, and high-performing solutions aligned with business...
-
Sr Developer Analyst IT
1 week ago
Northbrook, IL, United States Medline Full timeJob Summary The Dynamics D365 Lead Developer Analyst is responsible for defining and leading the technical architecture for Microsoft Dynamics 365 Customer Service platform, with a primary focus on the customer service workspace. This role will be responsible for the development of scalable, secure, and high-performing solutions aligned with business...