GRC Analyst Job at ASCENDING, Richmond, VA

cVhZdVhNa2J4Nk9PYUNPTkF0NDh2cGxoZ2c9PQ==
  • ASCENDING
  • Richmond, VA

Job Description

Job Description

Job Description

Location: HYBRID 
601 S Belvidere St, Richmond, VA 23220

Job Overview:

The Information Security and Privacy Specialist will play a critical role in ensuring the organization's information security controls are effectively implemented and maintained. This position will involve working with stakeholders across various business areas, as well as with external vendors, to ensure the highest level of security compliance is achieved. The role includes participating in Information Security and Privacy initiatives, maintaining security documentation, assisting in project management, and contributing to the development and implementation of security standards.

Key Responsibilities:
  • Lead and contribute to Information Security and Privacy efforts across all business units and vendor engagements, ensuring the application and adherence to appropriate security controls.
  • Utilize a Governance Risk and Compliance (GRC) system to manage and update security-related information, records, and documentation.
  • Collaborate with business stakeholders to develop and maintain Information System Security Plans (SSP).
  • Represent the Information Security Office (ISO) in PMO-led projects, ensuring appropriate ISO representation in significant business initiatives.
  • Work cross-functionally with various teams and users to identify business challenges, propose security solutions, facilitate compliance, and communicate security-related updates clearly and effectively.
  • Support the development and ongoing maintenance of information security standards and processes, including conducting research from reputable sources.
  • Assist in creating controls documentation, including system diagrams, risk assessments, and control narrative drafts for business approval.
  • Review vendor contracts, agreements, and documentation to ensure they include adequate information security protections.
Required Qualifications:
  • A minimum of 3 years of demonstrated experience in Information Security governance, risk, and compliance.
  • Strong knowledge of information security principles and practices.
  • Extensive understanding of IT infrastructure planning, implementation, and management with an emphasis on security.
  • Ability to manage workload independently, prioritize tasks, and meet deadlines with minimal supervision.
  • Familiarity or experience with security frameworks such as NIST, ISO 27001, COBIT, etc.
  • Superior organizational skills and keen attention to detail.
  • Ability to adapt to ambiguous situations and re-prioritize tasks as necessary.
  • Experience drafting and updating Information Security and Privacy policies, standards, and procedures.
  • Ability to interpret and analyze security documentation, including flow diagrams and process maps.
  • Understanding of contract terms and conditions, particularly regarding security protections.
  • Proficiency in creating diagrams, flowcharts, and spreadsheets using desktop software.
  • Strong written communication skills, with the ability to write clearly and concisely for various audiences.
Preferred Qualifications:
  • Bachelor's degree in Computer Science, Information Systems, or a related field.
  • Relevant certifications such as Certified Information Systems Auditor (CISA) or Certified Information Systems Security Professional (CISSP).
  • Experience in the financial services industry.
  • Knowledge of controls related to cloud security and application security.
  • Understanding of regulatory compliance requirements, including GLBA, GDPR, PCI, and other privacy regulations such as GDPR, CCPA, and VCDPA.

Powered by JazzHR

JTRzMUpXrC

Job Tags

Contract work,

Similar Jobs

American Alarm & Communications

Fire Alarm Technician/Inspector Job at American Alarm & Communications

 ...Description Job Description Electronic Alarms, a division of American Alarm & Communications, Inc. is hiring for a Fire Alarm Technician/Inspector that is licensed in RI. We offer a competitive benefits package as well as salary! Come and be part of our team!... 

Oregon State University

Associate Dean of Academics, College of Agricultural Sciences Job at Oregon State University

 ...Recommended Full-Time Salary Range: Salary is commensurate with skills, education and experience Job Summary: The College of Agricultural Sciences is seeking an Associate Dean of Academics. This is a full-time (1.00 FTE ), 12-month, professional faculty position.... 

Halff

Project Manager - Water and Wastewater Job at Halff

 ...of work and budgets. * Pump station, water storage, and/or pipeline design experience required. * Water/Wastewater treatment experience...  ..., Subsurface Utility Engineering/Utility Coordination, Surveying, Transportation, Water Resources and Water/Wastewater. Halff... 

UPMC - Pittsburgh Medical Center

Clinical Pharmacist Specialist-Internal Medicine Job at UPMC - Pittsburgh Medical Center

 ...Job Description Clinical Pharmacist Specialists work as part of a patient care team, focusing on safe and effective medication management for specialized patient populations. They provide direct patient-centered care, collaborate with interdisciplinary teams, and ensure... 

Garrett Popcorn Shops

Digital Content Manager Job at Garrett Popcorn Shops

 ...Garrett Popcorn Shops and Frango Chocolate. We are looking for a Digital Content Freelancer, who will support content marketing strategies to...  ...infrastructure projects, or other e-commerce projects Manage web content updates in the CMS Research trends, identify...