IT AUDITING (Governance and Compliance)

Posted 7 Days Ago
Be an Early Applicant
Deerfield Beach, FL, USA
In-Office
Senior level
Information Technology • Consulting
The Role
The Senior Governance and Compliance Analyst facilitates IT audits, regulatory assessments, control testing, remediation, and security framework maturity evaluations. The role develops policies and procedures, manages GRC initiatives, performs gap analyses, supports vendor and contract security reviews, and coordinates disaster recovery governance. It requires collaboration with auditors, control owners, business stakeholders, and executives while maintaining compliance with frameworks and regulations including NIST, COBIT, CCPA, HIPAA, GLBA, SOC 1, and NY DFS 500.
Summary Generated by Built In

Title:  IT AUDITING (Governance and Compliance)  Auditing Is Key
Location: Hybrid (Deerfield Beach, FL)
Duration: 12 months +

Sr. Governance and Compliance Analyst
The Governance and Compliance Sr. Analyst will report to the Governance, Risk and Compliance Manager and support the Information Security department to provide the highest quality assurance program to our customers.  The Governance and Compliance Sr. Analyst will perform a critical role in providing IT governance and compliance as a service, including assessments, compliance program management and assurance, and control framework maturity evaluations. The Governance and Compliance Sr. Analyst will manage, measure, operationalize and communicate a myriad of compliance initiatives across the enterprise, including but not limited to SOC 1 Type 2, MAR, NY DFS 500, CCPA, HIPAA. Collaboration with business areas within JM Family will be a key success criterion for this individual.  
 
Responsibilities:

  • Facilitate IT audits and assessments, including remediation of any findings noted
  • Ensure compliance with regulatory requirements (e.g., SOC 1 Type 2, MAR, NY DFS 500, CCPA) and internal controls, with proactive validation of controls.
  • Review regulatory and compliance matters related to information technology, as the shared-service provider for all business units, and perform necessary gap analysis
  • Implement and maintain an information technology, including security and privacy, controls framework
  • Develop and maintain IT policies, standards, and procedures
  • Act as an advocate for information security practices
  • Execute program tasks related to the evaluation of security control framework maturity, such as stakeholder interviews, documentation reviews, and maturity quantification.
  • Engage control owners (of varying information security acumen and expertise) and key stakeholders across the enterprise to collect and test evidence and assess compliance to various requirements (external regulatory and contractual, as well as internal controls)
  • Maintain and foster relationships and trust with key partners throughout the company
  • Maintain compliance and risk management initiatives in a GRC platform
  • Understand contractual elements with third parties and intelligently speak on the security requirements of a contract from an information security point of view
  • Maintain reliable, up-to-date information from the government and across the industry regarding the identification of new security standards and governance
  • Establish governance around disaster recovery function and collaborate with key business and IT leaders to develop security and disaster recovery standards and action plans
  • As directed, conduct periodic internal assessments for security risk and compliance
  • Perform other essential duties as assigned

 

Desired Skills

  • Project management skills for managing multiple complex activities
  • Knowledge of controls frameworks and applicable regulatory compliance mandates (e.g., NIST, CIS CSC, COBIT, CCPA, HIPAA, GLBA, SOC 1 Type 2, MAR)
  • Conduct research to keep abreast of the latest security issues, third-party vendors, and applications as needed

 

Qualifications/Requirements

  • Working knowledge of governance and compliance, including policy, process, governance, controls frameworks, and regulatory environments
  • Knowledge to evaluate, build and optimize security program elements as assigned (e.g., logical access control, application security, vendor risk management, network security, privacy)
  • Experience in working with auditors
  • Strong organizational skills with ability to thrive in a sense-of-urgency environment, leveraging best practices, and approaching any problem as a team-player with a can-do attitude
  • Strong written and verbal communication skills and ability to interface with all levels of business and executive leadership
  • Excellent analytical, problem solving, and decision-making skills, applied with a solution-focused attitude
  • Strong self-directed work habits, exhibiting initiative, drive, creativity, maturity, self-assurance and professionalism

 

License /Certificate (any of the following a plus):

CISSP, CISA, CISM, CIPP, GIAC



Skills Required

  • Working knowledge of governance and compliance, including policy, process, governance, control frameworks, and regulatory environments
  • Knowledge of evaluating, building, and optimizing security program elements, including logical access control, application security, vendor risk management, network security, and privacy
  • Experience working with auditors
  • Project management skills for managing multiple complex activities
  • Knowledge of controls frameworks and regulatory compliance mandates, including NIST, CIS Controls, COBIT, CCPA, HIPAA, GLBA, SOC 1 Type 2, and MAR
  • Strong organizational skills and ability to work in a high-urgency environment
  • Strong written and verbal communication skills with the ability to engage business and executive leadership
  • Excellent analytical, problem-solving, and decision-making skills
  • Self-directed work habits, initiative, creativity, maturity, self-assurance, and professionalism
  • CISSP, CISA, CISM, CIPP, or GIAC certification
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Austin, TX
433 Employees
Year Founded: 2004

What We Do

Established in 2004, 3Core System is a certified small minority owned business providing ERP Systems Integration, AMS, IT Consulting and Staff Augmentation Services to Fortune 1000, SMB, and State, Local and Education (SLED) customers. While our System Integration services help organizations achieve digital and cloud transformation objectives, AMS Services help increase the availability of critical services of end user applications. On the other hand, our IT Consulting Services would provide subject matter experts to help you assist with specific project needs and the Staff Augmentation services help you balance workload and achieve budget parameters. >ERP System Integration Services: 3Core Systems is an SAP Silver Partner and authorized service provider offering technical architecture, application design and configuration, integration, testing, data migration and solution adoption services for solutions including SAP SuccessFactors, SAP HCM On-Premises and SAP Business Intelligence >Application Management Services (AMS): We offer post go-live, System Health Check and Optimization, Function Enhancements, Integration Monitoring, Release, and patch services. Our AMS services span across SAP Solutions including ERP (S/4 HANA), Financial Management, Human Capital Management, Data and Analytics, Supply Chain, CRM, and Customer Experince. >IT Consulting and Staffing Augmentation Services: Ever since its inception, 3Core Systems has been offering IT Consulting and Staff Augmentation solutions including temporary, long-term, project based and contract staffing services that could be personalized based on your needs. Our staffing services span across emerging technologies and legacy solutions including but not limited to Artificial Intelligence, Machine Learning, Data Science, Cloud, ERP, CRM, BI/BW/ETL, Database, Web & E-Commerce, UI/UX, Network & Security and Mobile.

Similar Jobs

Dynatrace Logo Dynatrace

Senior Data Analyst

Artificial Intelligence • Big Data • Cloud • Information Technology • Software • Big Data Analytics • Automation
Remote or Hybrid
United States
5600 Employees
90K-110K Annually

Enverus Logo Enverus

Consulting Geologist, Anadarko Basin - Contract - 26330

Big Data • Information Technology • Software • Analytics • Energy
In-Office or Remote
2 Locations
1800 Employees
60-75 Hourly
Hybrid
Jacksonville, FL, USA
205000 Employees
Hybrid
Middleburg, FL, USA
205000 Employees

Similar Companies Hiring

Axle Health Thumbnail
Artificial Intelligence • Healthtech • Information Technology • Logistics
Santa Monica, CA
25 Employees
NODA AI Thumbnail
Artificial Intelligence • Information Technology • Software • Cybersecurity
Sydney, AU
54 Employees
Golden Pet Brands Thumbnail
Digital Media • eCommerce • Information Technology • Marketing Tech • Pet • Retail • Social Media
El Segundo, California
178 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account