
Senior Information Security Analyst
Posted Jul 30

Posted Jul 30
This is a fully remote position, open to applicants in United States.
• Prepares and facilitates examinations conducted by qualified security assessors for frameworks including SOC, ISO 27001, and PCI-DSS.
• Collaborates closely with other members of the Information Security, Risk, & Compliance team.
• Collects and synthesizes data; presents findings; and proposes risk mitigation, remediation, and process enhancement solutions to management.
• Works alongside control owners throughout the organization and internal and external auditors to ensure timely completion of requests.
• Identifies potential business risks, deficiencies in operational and regulatory processes, and opportunities for improvement.
• Communicates risk findings and actionable recommendations clearly to all stakeholders.
• Conducts technical risk assessments of third-party suppliers' security and privacy controls.
• Maintains a register of relevant suppliers/vendors, controls, and risks for ongoing vendor risk management activities.
• Aids in the initial triage of compliance, risk, and security requests in the ticket management system to ensure efficiency and prioritization.
• Supports the maintenance of overall security awareness, role-based security training, and phishing simulation programs across the enterprise.
• Assists in conducting user activity audits when necessary.
• 6+ years of experience in risk and compliance activities, or fewer years with the addition of relevant coursework or degrees.
• Exceptional organizational, planning, and time management abilities.
• Strong research and analytical skills.
• Excellent verbal and written communication capabilities.
• Ability to exercise sound judgment and diplomacy when interacting with Bonterra senior management.
• Proficient in technology with the ability to learn our software systems, including GRC, ticketing, and project management software and workflows.
• Demonstrated history of proactively identifying needs and implementing effective solutions.
• May possess one or more information systems security professional certifications (CRISC, CISA, CISSP, CISM, GSEC, GCFA, GCTI, CCSP, or other relevant Information Security certifications).
• Comprehensive benefits package that promotes your health, well-being, and professional growth.
• Bonuses, incentives, equity, and a thorough benefits program.
Team Cymru
CRH Consultoria em Recursos Humanos
Medtronic
Get handpicked remote jobs straight to your inbox weekly.