IT GRC Lead - Remote

| United States +80 more | Remote
Apply
By clicking Apply Now you agree to share your profile information with the hiring company.

Donnelley Financial Solutions (DFIN) is a leader in risk and compliance solutions, providing insightful technology, industry expertise and data insights to clients across the globe. We’re here to help you make smarter decisions with insightful technology, industry expertise and data insights at every stage of your business and investment lifecycles. As markets fluctuate, regulations evolve and technology advances, we’re there. And through it all, we deliver confidence with the right solutions in moments that matter. 

Summary:

The IT Governance, Risk and Compliance (GRC) Lead position is an individual contributor role responsible for the implementation and operation of IT GRC activities for the Enterprise. The IT GRC Lead will help further and maintain IT GRC - leveraging the organizations security standards and applicable compliance regulations and IT Compliance with applicable IT standards, laws, and regulations. This individual will have a strong understanding of the SSAE 18 AICPA reporting standards, and an understanding of compliance frameworks supported such as SOC1, SOC2 (Security, Availability, Confidentiality, Processing Integrity, and Privacy Trust Service Principles), NIST, HITRUST, HIPAA and GDPR. This position reports to the Director of GRC within the CISO organization.

 

Candidate should be able to “lead from the front”, have a strong sense of ownership and be able to work autonomously. Candidate should also demonstrate our CISO org behavior of: Engagement, Maintaining a Consultative Mindset, Accountability and Emotional Intelligence

Responsibilities:

Candidate will be directly responsible for leading and/or supporting GRC initiatives:

  • Annual IT audit programs including SSAE-18 SOC2, SOX 404, ISO 27001, NIST CSF, NIST 800-171, NIST 800- 218 certification(s) and HiTrust initiatives.
  • Integrate IT GRC requirements into broader technology governance processes (e.g., cybersecurity, operational readiness, SDLC, enterprise architecture, ITIL processes, client security, supply chain security), ensuring IT GRC and Compliance practices are operating across all facets of the enterprise.
  • Elevate Cyber risk-management function, including risk register and risk lifecycle processes (i.e., identification, assessment, remediation, exception/acceptance).
  • Support of Control Framework(s) including:
    • Designing, reviewing and testing effective IT/Security controls
    • Control Self-Assessment program (CSA/SCA) which is inclusive of testing key controls such as patch management, backup process, vulnerability management, cybersecurity and network related controls
  • Interpret regulations affecting control standards and suggests methods of updating policies and practices that address any risk concerns so as to maintain IT and regulatory compliance.
  • Identify, define and update security standards and policies for servers, endpoints, network infrastructure, and cloud environments with supporting audit and reporting processes
  • Liaise with engineering, IT operations, IT Infrastructure, IT security, HR, Marketing and business teams to provide accurate and timely responses to internal and external audit requests and related activities.
  • Advocate for all business areas while accounting for and balancing risk
  • Produce and maintain appropriate, KPIs, Metrics and Reporting

Qualifications:

  • 8 or more years working in IT Governance, Risk and Compliance
  • 8 or more years of Information Technology related work experience.
  • 5 or more years’ experience in SOC/SOX related audits.
  • 5 or more years’ experience with Risk/Control Risk frameworks (NIST CSF, ISO, COBIT)
  • 5 or more years’ experience with Vulnerability Management
  • 3 years of experience with Cloud Governance, cloud applications and Infrastructure
  • Identity Governance and Administration (IGA) or Access Management experience
  • Experience working in the Financial Services Industry and/or Fintech
  • Experience leading projects and service delivery initiatives.
  • Internal/external customer facing experience


Ideal Expertise:

To excel in this role, the ideal candidate should possess the following expertise:

  • Subject matter expertise in IT Governance, Risk, and Compliance (GRC) discipline, with in-depth knowledge of IT Service Delivery, ITIL, and Project Management.
  • Strong understanding of current cybersecurity concepts, tools, and technology.
  • Proven experience in SSAE18 SOC, SOX, or HiTrust audits for medium to large enterprises.
  • Proficiency in risk frameworks and ISO27001, along with experience in Risk/Control Risk frameworks (NIST CSF, ISO, COBIT, COSO).
  • Technical proficiency in key IT areas, including UNIX, DNS, Windows Server, Internet routing, TCP/IP protocols, Network technologies, Active Directory, and foundational technology concepts.
  • Expertise in risk assessment procedures, policy formation, role-based authorization methodologies, authentication technologies, and knowledge of cyber-attack techniques.
  • Ability to relate business requirements and risks to technology implementation for security-related issues.
  • Strong cybersecurity acumen
  • Knowledgeable in IT Service Delivery, ITIL and Project Management.
  • Deep understanding of cybersecurity concepts including tools/technology
  • Working knowledge and experience with MS Office products including Word, Excel, PowerPoint & Visio and SharePoint 
  • Expert in writing/updating documentation to include standards, policies and procedures
  • Experience with industry tools (e.g., ServiceNow, Archer, Process Unity, Panorays, Omada)
  • O365 (Word, PowerPoint, SharePoint, OneDrive, Teams, Excel, PowerBI)
  • Continuous control monitoring and automation
  • Ability to be a trusted advisor relative to all things GRC related

Preferred Skills:

  • Demonstrated leader with team-oriented interpersonal skills; ability to effectively interface with a broad range of team members and roles.
  • Ability to work independently with or without direction and/or supervision.
  • Ability to prioritize workload and multitask. Flexibility and adaptability in work approach.
  • Ability to work directly with internal and external audit partners.
  • Calmness, clarity and due diligence process oriented and works well under pressure and has ability to maintain confidentially.
  • Strong written and verbal communication skills and maintains attention to detail

Donnelley Financial Solutions (DFIN) is a leader in risk and compliance solutions, providing insightful technology, industry expertise and data insights to clients across the globe. We’re here to help you make smarter decisions with insightful technology, industry expertise and data insights at every stage of your business and investment lifecycles. As markets fluctuate, regulations evolve and technology advances, we’re there. And through it all, we deliver confidence with the right solutions in moments that matter. 

Read Full Job Description
Apply Now
By clicking Apply Now you agree to share your profile information with the hiring company.
Candidate Location Eligibility:
Albuquerque, NM
Ann Arbor, MI
Atlanta, GA
Austin, TX
Baltimore, MD
Baton Rouge, LA
Birmingham, AL
Boise, ID
Boston, MA
Buffalo, NY
Charleston, SC
Charlotte, NC
Chicago, IL
Cincinnati, OH
Cleveland, OH
Colorado, CO
Columbus, OH
Dallas-Fort Worth, TX
Dayton, OH
Des Moines, IA
Detroit, MI
Fayetteville-Springdale-Rogers, AR
Greensboro, NC
Hampton Roads, VA
Hartford, CT
Houston, TX
Huntsville, AL
Indianapolis, IN
Jacksonville, FL
Kansas City, MO
Las Vegas, NV
Lexington, KY
Lincoln, NE
Little Rock, AR
Los Angeles, CA
Louisville, KY
Madison, WI
Memphis, TN
Miami, FL
Milwaukee, WI
Minneapolis–Saint Paul, MN
Nashville, TN
New Orleans, LA
New York City, NY
Ogden, UT
Oklahoma City, OK
Omaha, NE
Orlando, FL
Other US Location
Palm Bay-Melbourne-Titusville
Pensacola, FL
Peoria, IL
Philadelphia, PA
Phoenix – Mesa – Scottsdale, AZ
Pittsburgh, PA
Portland, ME
Portland, OR
Providence, RI
Provo, UT
Raleigh-Durham, NC
Reno, NV
Richmond, VA
Rochester, NY
Sacramento, CA
Salt Lake City, UT
San Antonio, TX
San Diego, CA
San Francisco, CA
San Luis Obispo, CA
Santa Cruz, CA
Seattle, WA
Spokane, WA
St. Louis, MO
Tallahassee, FL
Tampa Bay, FL
Tucson, AZ
Tulsa, OK
Washington DC
Wichita, KS
Wilmington, NC

Technology we use

  • Engineering
    • C#Languages
    • JavaLanguages
    • PythonLanguages
    • SqlLanguages
    • jQueryLibraries
    • ReactLibraries
    • AngularFrameworks
    • Angular.JSFrameworks
    • ASP.NETFrameworks
    • KubernetesFrameworks
    • Node.jsFrameworks
    • TerraformFrameworks
    • DynamoDBDatabases
    • Microsoft SQL ServerDatabases
    • MongoDBDatabases
    • MySQLDatabases
    • NoSQLDatabases
    • SAP HANADatabases
    • TeradataDatabases
    • Microsoft AzureServices
    • New RelicServices

An Insider's view of DFIN

What projects are you most excited about?

In transforming and improving FinTech products, excitement comes from the challenge of knowing that the problems are complex, yet the solutions must be easy to use. When we start a new project, I can't wait to sink my teeth into understanding the problem space, talking to users, designing the solution, and seeing it through to release.

Dan

Principal Product Designer

What makes someone successful on your team?

Active and honest listening – Contrary to the stereotypical, extroverted sales rep, some of my most effective and insightful client interactions are when I do the least amount of talking, and the most active listening. Client insight is exponentially easier to excavate when you stop “pitching” – and start listening.

Carey

Senior Sales Representative

What is your vision for the company?

Our business plan reflects the change in products DFIN is selling today versus what we sell in five years. DFIN today is a company that offers a lot of professional services that we added software to, but the goal is to become a SaaS company that has services to support it.

Stephen

SVP, Global Head of Engineering

What does your typical day look like?

The role of a software engineer is really about creating computational systems and ensuring they behave as designed. My day-to-day is focused mostly on writing code that provides new functionality within our products that we see a need for in the market—and providing quality control to be certain it works properly.

Herve

Senior Software Engineer

What are DFIN Perks + Benefits

DFIN Benefits Overview

The world continues to change in ways we never expected, but there is one constant: your safety and well-being is a top priority, and DFIN has you covered with our benefits.

Culture
Volunteer in local community
Partners with nonprofits
Open door policy
OKR operational model
Team based strategic planning
Open office floor plan
Employee resource groups
Employee-led culture committees
Quarterly engagement surveys
Hybrid work model
Employee awards
Flexible work schedule
We value a work / life balance at DFIN.
Remote work program
We have partial and fully remote opportunities at DFIN.
Diversity
Documented equal pay policy
Dedicated diversity and inclusion staff
Highly diverse management team
Mandated unconscious bias training
Diversity manifesto
Diversity employee resource groups
Hiring practices that promote diversity
Diversity recruitment program
Health Insurance + Wellness
Flexible Spending Account (FSA)
Disability insurance
Dental insurance
Vision insurance
Health insurance
Life insurance
Wellness programs
Mental health benefits
Wellness days
Financial & Retirement
401(K)
401(K) matching
Company equity
Employee stock purchase plan
Performance bonus
Child Care & Parental Leave
Childcare benefits
Generous parental leave
Family medical leave
Family Medical Leave granted under the Family and Medical Leave Act (FMLA).
Adoption Assistance
Return-to-work program post parental leave
Vacation + Time Off
Unlimited vacation policy
Generous PTO
Paid holidays
Paid sick days
Flexible time off
Floating holidays
Bereavement leave benefits
Hardship benefits
Office Perks
Commuter benefits
Company-sponsored outings
Free snacks and drinks
Some meals provided
Company-sponsored happy hours
Onsite office parking
Employee parking available
Fitness stipend
Mother's room
Onsite gym
Professional Development
Job training & conferences
Lunch and learns
Promote from within
Mentorship program
Continuing education available during work hours
Online course subscriptions available
Customized development tracks
Paid industry certifications
Personal development training
Apprenticeship programs

Additional Perks + Benefits

DFIN has implemented a Employee Stock Purchase Program.

More Jobs at DFIN

Apply Now
By clicking Apply Now you agree to share your profile information with the hiring company.
Learn more about DFINFind similar jobs like this