Risk Management & Controls Assurance - Sr. Analyst

| Detroit, MI, USA | Hybrid
Sorry, this job was removed at 5:28 p.m. (CST) on Tuesday, April 30, 2024
Find out who's hiring in Detroit, MI.
See all Data + Analytics jobs in Detroit, MI
Apply
By clicking Apply Now you agree to share your profile information with the hiring company.

Description
Work Arrangement:
This role is categorized as hybrid. This means the successful candidate is expected to report to Warren, MI three times per week, at minimum.
The Role:
The Cybersecurity Risk Management and Controls Assurance Sr. Analyst role supports the activities of the Information Security and Risk Management - Governance, Risk & Compliance group. This role will work with a team of security professionals and will play a pivotal part in ensuring the effectiveness and alignment of our Cybersecurity practice with industry best practices, regulatory requirements, and business objectives. This role will be responsible for executing the organization's cybersecurity risk management strategy, proactively identifying, assessing, and mitigating inherent risks to GM's critical data, networks, and infrastructure. This role is also instrumental in regularly evaluating the adequacy of the design and operating effectiveness of cybersecurity controls, identifying potential weaknesses, and ensuring appropriate actions plans are in place to reduce residual risks and improving GM's overall risk posture.
What You'll Do:

  • Risk & Unified Controls Framework:
    • Assist in the development and maintenance of a comprehensive GRC framework, tailored for our Cybersecurity program, aligning with industry standards (e.g., NIST CSF, ISO 27001), regulations, and organizational goals.
    • Ensure clear control ownership and alignment across all ISRM functions.
    • Maintain essential GRC documentation, including processes, procedures, and risk registers.
    • Integrate GRC processes with enterprise-wide cybersecurity initiatives, processes, and reporting requirements.
  • Risk Management:
    • Implement a comprehensive risk management process, including a quantifiable means to calculate both inherent and residual risks, and GM's overall risk posture.
    • Conduct regular risk assessments of cybersecurity threats, vulnerabilities, and environmental factors affecting the business.
    • Analyze and prioritize identified risks based on their impact and likelihood.
    • Execute risk mitigation strategies, including potential control implementation and enhanced monitoring mechanisms, aligned to industry best practices.
    • Monitor and track mitigation results, assess impacts to residual risks, and recommend adjustments to the unified controls framework.
    • Report and present on risk management progress to stakeholders.
  • Controls Assurance:
    • Perform regular evaluations to assess the adequacy of the design and operating effectiveness of existing cybersecurity controls.
    • Identify control gaps and weaknesses, recommending solutions for improvement.
    • Conduct validations to ensure root causes of identified deficiencies are properly addressed.
    • Monitor and track progress on control remediation efforts to closure.
  • Reporting and Communication:
    • Develop clear and concise reports on risk assessments and control effectiveness status for senior management and relevant stakeholders.
    • Collaborate between cybersecurity and other departments on risk and cybersecurity control related matters.
    • Communicate effectively with cross-functional teams to build understanding and support for risk and controls related initiatives.
  • Data & Automation:
    • Manage and maintain ISRM's GRC platform, analytics, and reporting (i.e., ServiceNow IRM)
    • Assist in the migration to ServiceNow IRM and configure the Information Risk Management module.
    • Support and maintain the Risk & Controls Dashboard
    • Collaborate with Security Architecture and Services team to populate risk related data in the Security Data Lakehouse
    • Assist in driving the organization to a continuous controls monitoring and reporting environment.
  • Continuous Improvement:
    • Identify opportunities to improve the effectiveness and efficiency of our GRC program.
    • Implement initiatives to enhance the overall cybersecurity posture of the organization.
    • Stay informed about evolving cybersecurity threats, regulations, and best practices.


Additional Description
Your Skills & Abilities (Required Qualifications):

  • Bachelor's degree in Cybersecurity, Computer Science, or related field
  • Minimum 5 years of experience in cybersecurity, GRC, computer science, or related field.
  • Prior experience with global, geographically disbursed, teams.
  • In-depth knowledge of risk management and compliance frameworks (e.g., FAIR, ERM, COSO).
  • In-depth knowledge of industry standards, and best practices (e.g., NIST CSF, ISO 27001, NIST 800-53, etc.).
  • Familiarity with cybersecurity related legal /regulatory requirements (e.g., SOX, PCI-DSS, GDPR, CCPA, etc.).
  • Understanding of incident response, threat intelligence, and vulnerability management processes.
  • Experience managing GRC software tools and platforms (e.g., ServiceNow IRM, IBM OpenPages).
  • Strong analytical, problem-solving, critical thinking, and organization skills.
  • Strong decision-making skills, and attention to detail and accuracy.
  • Ability to assist in the management of multiple, highly complex projects concurrently, and prioritize effectively.
  • Excellent communication, presentation, and interpersonal skills.
  • Ability to collaborate effectively with stakeholders across all levels of the organization.
  • Ability to work independently and as part of a team.
  • Adaptability, openness to change, and willingness to learn new skills.
  • Strong work ethic and commitment to excellence.


What Will Give You A Competitive Edge (Preferred Qualifications):

  • Relevant professional certifications (e.g., CGRC, CRISC, CISA, CISSP, PMP).
  • Database Management, programming, and data analytics experience


GM DOES NOT PROVIDE IMMIGRATION-RELATED SPONSORSHIP FOR THIS ROLE. DO NOT APPLY FOR THIS ROLE IF YOU WILL NEED GM IMMIGRATION SPONSORSHIP (e.g., H-1B, TN, STEM OPT, etc.) NOW OR IN THE FUTURE.
About GM
Our vision is a world with Zero Crashes, Zero Emissions and Zero Congestion and we embrace the responsibility to lead the change that will make our world better, safer and more equitable for all.
Why Join Us
We aspire to be the most inclusive company in the world. We believe we all must make a choice every day - individually and collectively - to drive meaningful change through our words, our deeds and our culture. Every day, we want every employee, no matter their background, ethnicity, preferences, or location, to feel they belong to one General Motors team.
Total Rewards | Benefits Overview
From day one, we're looking out for your well-being-at work and at home-so you can focus on realizing your ambitions. Learn how GM supports a rewarding career that rewards you personally by visiting Total Rewards resources.
Diversity Information
General Motors is committed to being a workplace that is not only free of unlawful discrimination, but one that genuinely fosters inclusion and belonging. We strongly believe that workforce diversity creates an environment in which our employees can thrive and develop better products for our customers. We encourage interested candidates to review the key responsibilities and qualifications for each role and apply for any positions that match their skills and capabilities. Applicants in the recruitment process may be required, where applicable, to successfully complete a role-related assessment(s) and/or a pre-employment screening prior to beginning employment. To learn more, visit How we Hire
Equal Employment Opportunity Statement (U.S.)
General Motors is proud to be an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran.
Accommodations (U.S. and Canada)
General Motors offers opportunities to all job seekers including individuals with disabilities. If you need a reasonable accommodation to assist with your job search or application for employment, email us [email protected] or call us at 800-865-7580. In your email, please include a description of the specific accommodation you are requesting as well as the job title and requisition number of the position for which you are applying.

Read Full Job Description
Apply Now
By clicking Apply Now you agree to share your profile information with the hiring company.

Technology we use

  • Engineering
  • Product
  • Sales & Marketing
  • People Operations
    • C#Languages
    • C++Languages
    • JavaLanguages
    • JavascriptLanguages
    • KotlinLanguages
    • Objective-CLanguages
    • PerlLanguages
    • PythonLanguages
    • ScalaLanguages
    • SqlLanguages
    • SwiftLanguages
    • TypeScriptLanguages
    • jQueryLibraries
    • ReactLibraries
    • AngularFrameworks
    • Angular.JSFrameworks
    • DockerFrameworks
    • HadoopFrameworks
    • JupyterFrameworks
    • Node.jsFrameworks
    • React NativeFrameworks
    • Ruby on RailsFrameworks
    • SparkFrameworks
    • SpringFrameworks
    • SpringBootFrameworks
    • QuarkusFrameworks
    • JunitFrameworks
    • MSUnitFrameworks
    • Cloud Native Frameworks
    • ContainersFrameworks
    • RESTFrameworks
    • MicroservicesFrameworks
    • BigQueryDatabases
    • HiveDatabases
    • MongoDBDatabases
    • OracleDatabases
    • PostgreSQLDatabases
    • SAP HANADatabases
    • AWS (Amazon Web Services)Services
    • Microsoft AzureServices
    • Google AnalyticsAnalytics
    • TableauAnalytics
    • PowerBIAnalytics
    • AxureDesign
    • CanvaDesign
    • PhotoshopDesign
    • JIRAManagement
    • LinkedIn SalesNavigatorCRM
    • BeameryCRM
    • Adobe CampaignLead Gen
    • Microsoft TeamsCollaboration

An Insider's view of General Motors

How would you describe the company’s work-life balance?

GM has a people-first culture that inspires everyone to help each other and improve themselves. It fosters a workplace of inclusivity instead of focusing solely on company results. I really feel like I am seen as an individual and that my work has an impact at GM.

Navya

Data Analyst, Data Management and Analytics Group

What projects are you most excited about?

I’m currently working on the Cruise AV and Cruise Origin, along with ADAS projects. I enjoy working in the new technology space because it allows me to think creatively and come up with innovative ideas to solve problems.

Victoria

Autonomous Vehicle Validation

How does the company support your career growth?

GM continually allows me the flexibility to pursue a variety of assignments and roles in accordance with my interest and evolving skillset. With each move, I’ve found satisfaction through increased responsibility and overall scope of work. The key to success is understanding the business while building and growing your leadership acumen.

Charles

Program Engineering Manager, Battery Electric Vehicles

How do you make yourself accessible to the rest of the team?

I want my team members to feel like they’re working with me, not for me. So, I make myself vulnerable to my team. I share my failures and ask for help. Likewise, I try to create an open, safe and trusted environment for them to discuss their challenges. I share my success stories to inspire them to realize their career aspirations.

Sri

Director, Ultifi Data Platform Services

How has your career grown since starting at the company?

I started as a calibration test engineer, then moved into our Immersive Lab, where I leveraged cutting-edge technology to speed up engineering and design processes. Now, I’m using that experience as an Integration Design Engineer in our Advanced Studio. These opportunities enabled my professional growth and I can’t wait for my future in innovation.

Jeremiah Hamlin

Design Engineer

What are General Motors Perks + Benefits

Culture
Volunteer in local community
Partners with nonprofits
Open door policy
OKR operational model
Team based strategic planning
Open office floor plan
Employee resource groups
Employee-led culture committees
Quarterly engagement surveys
Hybrid work model
Flexible work schedule
Remote work program
Diversity
Documented equal pay policy
Dedicated diversity and inclusion staff
Mandated unconscious bias training
Diversity manifesto
Mean gender pay gap below 10%
Diversity employee resource groups
Hiring practices that promote diversity
Health Insurance + Wellness
Flexible Spending Account (FSA)
Disability insurance
Dental insurance
Vision insurance
Health insurance
Life insurance
Wellness programs
Team workouts
Mental health benefits
Transgender health care benefits
Financial & Retirement
401(K)
401(K) matching
Employee stock purchase plan
Performance bonus
Charitable contribution matching
Child Care & Parental Leave
Childcare benefits
Generous parental leave
Family medical leave
Adoption Assistance
Return-to-work program post parental leave
Fertility benefits
Vacation + Time Off
Generous PTO
Paid volunteer time
Paid holidays
Paid sick days
Flexible time off
Floating holidays
Office Perks
Company-sponsored outings
Company-sponsored happy hours
Onsite office parking
Recreational clubs
Relocation assistance
Onsite gym
Professional Development
Job training & conferences
Tuition reimbursement
Lunch and learns
Promote from within
Mentorship program
Continuing education stipend
Continuing education available during work hours
Online course subscriptions available
Customized development tracks
Paid industry certifications
Personal development training

More Jobs at General Motors

Apply Now
By clicking Apply Now you agree to share your profile information with the hiring company.
Learn more about General MotorsFind similar jobs like this