Senior GRC Analyst
2 г. назад
PhilippinesWorldwideSeniorHybrid
Senior GRC Analyst role in cybersecurity operations focusing on governance, risk, and compliance.
О компании
- Find Your Connection to Endless Possibilities Are you a GRC professional looking for the next step in your career? If the opportunity to work in a global industry leader with a diverse culture excites you, this may be the role for you. With , you’ll find your connection to the world of sound and vision. We lead the world in AV networking media to pioneer the way people see and hear. Our products seamlessly manage hundreds of audio and video channels with one network, making us the industry standard. You’ll find us in the largest companies and institutions like the Sydney Opera House, NFL Media Headquarters, Microsoft, and even a 900-year old cathedral featured in Harry Potter. Our core values are the foundation of everything we do: Excellence, Courage, Integrity,
Обязанности
- Conduct risk assessments and third-party security assessments to identify potential gaps and vulnerabilities against ISMS policies, guidelines and associated controls.
- Design, implement, and conduct internal audits and report audit findings to management.
- Manage and maintain a GRC platform to track and report on compliance activities.
- Work closely with ISO27001 auditors to ensure successful audits and certification.
- Own the risk assessment process including maintaining the risk register, information asset register, and incident register.
- Monitor emerging and evolving product compliance legislation (e.g. EU AI Act, Cyber Resilience Act, Radio Equipment Directive) and standards, assess applicability and impact on 's products and platforms, and translate obligations into requirements for Engineering, Product, Legal and Operations.
- Collaborate with cross-functional teams to address compliance issues and drive continuous improvement efforts
- Stay up to date on the latest regulations, standards and trends in risk and compliance.
Требования
- Bachelor’s degree or industry certifications in information cybersecurity, risk management, governance, or a related field.
- 5+ years of direct experience in information security, with an emphasis on governance, risk and compliance.
- 3+ years of experience preparing for ISO27001 audits, as well as working with auditors to prepare audit responses.
- Thorough understanding of the ISO27001:2022 standard and associated guidelines.
- Experience with GRC Platforms such as, Vanta, SecureFrame or similar.
- Interpersonal skills (working with developers, engineers, business and operations & external stakeholders)
- Relevant certifications such as CISA, CISSP or CRISC are a plus.
- Ability to work independently and as part of a team
- Agile mentality: flexible, open to change and striving for continuous improvement