Information Security Sr Anlyst

Posted 2 Days Ago
Be an Early Applicant
Cary, NC, USA
In-Office
Senior level
Information Technology • Consulting
The Role
Leads information security governance, risk, and compliance activities, including contract, regulatory, cyber, supplier, and third-party risk management. Reviews controls, policies, evidence, and security requirements against NIST, ISO, SOC, and related frameworks. Supports audits, certifications, risk treatment plans, metrics, training, governance forums, and stakeholder responses while improving GRC processes through automation and technology.
Summary Generated by Built In

Object Technology Solutions, Inc (OTSI) has an immediate opening for a Sr. Information Security Analyst - GRC

 

Sr. Information Security Analyst – GRC (Cary, NC- Onsite)

Other Location: Overland Park, KS - Onsite

 

MAJOR RESPONSIBILITES:

        Contract Risk Management

        Proven experience reviewing client contract provisions related to data security, breach reporting, cyber resilience, and compliance certifications and measuring compliance in IT and security architecture and operations.

        Regulatory Compliance Risk Management

        Support independent certification and audit by working with D&IT peer groups and lines of business to collect documentation and evidence of security policies and operations

        Request and review documentation and evidence from control owners to certify and validate compliance to standards and industry-accepted best practice

        Monitor regulatory and legal landscape at a global scale and across market sectors and maintain awareness of compliance requirements

        IT Governance

        Act as an informed voice in development of policy and ensure alignment with regulatory, legal, and contractual requirements

        Assist establishment and enforcement of standards of practice documentation to be referenced by architecture and operations teams

        Contribute process and subject matter expertise in governance forums and cross-functional committees

        Cyber Risk Management

        Support establishment, collection, and ongoing improvement of metrics to measure effectiveness of cyber risk management and provide data-driven insight to decision makers and control owners

        Collaborate with peer D&IT groups to collect KPI’s, KRI’s and drive efficiency through automation and other means

        Supplier/Third Party Risk Management

        Contribute subject matter expertise through third party risk assessment process

        Identify and communicate risk of vendor engagements and mitigation actions to business owners and D&IT stakeholders

        Assist review of client security requirements in contracts and aggregate relevant clauses to inform contractual risk

        Miscellaneous:

        Assist development of user training aligned with cyber threat landscape, establish and implement metrics, and propose enhancements

        Support internal audit

        Assist with security certification/attestations/audits to demonstrate control effectiveness to independent service auditors/assessors and C3PAO’s

        Assist in development of risk treatment plans and monitoring progress of actions.

        Collaborate with members of the GRC team to ensure timely and quality deliverables to internal and external customers

        Contribute subject matter expertise in review and response to internal and external sourced GRC related requests

 

 

SKILLS AND ABILITIES REQUIRED:

        Bachelor’s degree in information systems, Information Security, or a related field

        7–10 years of experience in GRC executing or auditing against standards, frameworks, and industry regulations

        Demonstrated experience supporting GRC functions for global companies

        Solid proficiency in risk assessment methodologies and frameworks

        Proven ability to assess alignment of internal policy, process, control design and operations, and cyber risk management with regulatory standards and frameworks

        Strong collaboration with IT teams

        Familiarity with industry standards and frameworks (e.g., NIST CSF and supporting SP’s, ISO 27001, AICPA SOC)

        Working knowledge of cyber and privacy laws and regulations

        Solid understanding of information security principles and concepts

        Strong desire to create task and functional efficiencies through use of technology and tools, especially GenAI

        Preferred Qualifications

        Strong analytical, organizational, and communication skills

        Professional certifications such as CRISC, CISSP or others

        Experience with ServiceNow Risk Management platform

        Knowledge of FAR, DFARS, CMMC

        Experience with GRC platforms and risk management methodologies

        Ability to work independently and collaboratively as required

        Competencies

        Attention to detail and critical thinking

        Ethical judgment and integrity

        Ability to manage multiple tasks and deadlines

        Strong interpersonal and stakeholder engagement skills

 

About us

 

About us:

OTSI is a global technology partner providing enterprise IT consulting, digital solutions, and managed services. We help organizations modernize complex technology landscapes, harness the power of data, and build scalable AI-led ecosystems to accelerate innovation and business growth. With over 26 years of experience, we consistently turn complex challenges into success stories through our strong technical capabilities and deep industry knowledge. Our global team of 1,800+ professionals, spread across 6 countries, delivers cutting-edge solutions for customers across Banking, Financial Services, Insurance, Transportation & Logistics, Energy & Utilities, Healthcare & Life Sciences, Government, Hi-Tech, Telecom & Media, Manufacturing, and more.

 

Our focused technology areas:

·        AI/ML (Agentic AI Solutions, GenAI/LLMs, Natural Language Processing, Intelligent Processing, Physical Intelligence)

·        Data & Analytics (Data Architecture, Data Engineering, Data Migration, Data Modernization, Big Data, Analytics and BI)

·        Cloud (Cloud Computing, Cloud Migration, Cloud-Native Architecture, Hybrid and Multi-Cloud)

·        Digital Engineering (Application Modernization, Product Engineering, Platform Engineering, DevSecOps)

·        Quality Engineering (Manual Testing, Nonfunctional testing, Test Automation, Digital Testing)

·        Enterprise Platforms (SAP, Microsoft, Oracle, etc.)

Our focused industries and target segments:

·       Banking, Financial Services, & Insurance

·       Manufacturing, Transportation, & Logistics

·       Energy & Utilities

·       Telecom & Media

·       Healthcare & Lifesciences

·       Government & Public Sector (FED, SLED, & Partners)

·       Hi-Tech



Skills Required

  • Bachelor’s degree in information systems, information security, or a related field
  • 7–10 years of experience executing or auditing GRC activities against standards, frameworks, and industry regulations
  • Experience supporting GRC functions for global companies
  • Proficiency in risk assessment methodologies and frameworks
  • Experience assessing internal policy, process, control design, operations, and cyber risk management against regulatory standards and frameworks
  • Strong collaboration with IT teams
  • Familiarity with NIST CSF and supporting publications, ISO 27001, and AICPA SOC
  • Working knowledge of cyber and privacy laws and regulations
  • Understanding of information security principles and concepts
  • Ability to improve task and functional efficiency using technology and tools, especially GenAI
  • Strong analytical, organizational, and communication skills
  • Professional certifications such as CRISC or CISSP
  • Experience with the ServiceNow Risk Management platform
  • Knowledge of FAR, DFARS, and CMMC
  • Experience with GRC platforms and risk management methodologies
  • Ability to work independently and collaboratively
  • Attention to detail and critical thinking
  • Ethical judgment and integrity
  • Ability to manage multiple tasks and deadlines
  • Strong interpersonal and stakeholder engagement skills
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
Bengaluru
1,153 Employees
Year Founded: 1999

What We Do

Transform Your Business with OTSI Since 1999, OTSI has been at the forefront of IT consulting, technology solutions, and managed services. As a global innovator, we empower decision-makers to enhance efficiency, drive digital transformation, and unlock growth. With 15 offices in 6 countries and a Global Delivery Center in India, we offer flexible, scalable solutions with 24/7 support through our “Follow-the-Sun” model. Why Choose OTSI? Trusted by Fortune 500: Proven success with 100+ global clients. Industry Expertise: Serving sectors like Banking, Healthcare, Energy, Telecom, and more. Innovative Solutions: Cutting-edge technologies and tailored approaches for superior outcomes. Our Core Focus Areas: Data & Analytics: Big Data, Engineering, Modernization, Insights. Digital Transformation: Cloud Computing, Mobility, RPA, DevOps. QA & Automation: Comprehensive Testing, Automation, Digital QA. Enterprise Applications: Full-Stack Development, SAP, Microsoft, Custom Solutions. Disruptive Technologies: IoT/Edge Computing, Blockchain, AR/VR, Biometrics. Ready to Lead the Future? Partner with OTSI for customized solutions that drive productivity and growth. Let’s connect!

Similar Jobs

Lowe’s Logo Lowe’s

Account Manager

Consumer Web • eCommerce • Information Technology • Retail • Software • Analytics • App development
Hybrid
Charlotte, NC, USA
300000 Employees

Lowe’s Logo Lowe’s

Sr Analyst-Digital Commerce

Consumer Web • eCommerce • Information Technology • Retail • Software • Analytics • App development
Hybrid
Mooresville, NC, USA
300000 Employees

Lowe’s Logo Lowe’s

Sr Analyst-Pricing Business Partner

Consumer Web • eCommerce • Information Technology • Retail • Software • Analytics • App development
Hybrid
Mooresville, NC, USA
300000 Employees

Lowe’s Logo Lowe’s

Accountant

Consumer Web • eCommerce • Information Technology • Retail • Software • Analytics • App development
Hybrid
Mooresville, NC, USA
300000 Employees

Similar Companies Hiring

Standard Template Labs Thumbnail
Artificial Intelligence • Information Technology • Software
New York, NY
25 Employees
NODA AI Thumbnail
Artificial Intelligence • Information Technology • Software • Cybersecurity
Sydney, AU
54 Employees
Golden Pet Brands Thumbnail
Digital Media • eCommerce • Information Technology • Marketing Tech • Pet • Retail • Social Media
El Segundo, California
178 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account