обновлено 4 часа назад
IT Risk & Compliance Analyst (Cybersecurity)
84 000 - 94 000$
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
IT Risk & Compliance Analyst (Cybersecurity): Supporting IT compliance, audit readiness, cybersecurity findings management, and risk management across security, IT, internal audit, and business stakeholders with an accent on SOX IT General Controls, evidence management, and regulatory frameworks. Focus on coordinating audits, tracking remediation plans, mapping controls to NIST frameworks, and improving compliance workflows through automation and standardization.
Location: Remote anywhere within the United States; occasional travel to the Andover, Massachusetts office and approximately 10% business travel.
Salary: $84,000–$94,000 yearly.
Company
develops water products and smart, connected, sustainable water solutions for residential and commercial customers.
What you will do
- Coordinate IT compliance, audit activities, cybersecurity findings management, and risk workstreams across security, IT, internal audit, business stakeholders, and external assessors.
- Support SOX IT General Controls planning, evidence collection, documentation review, control testing, auditor inquiries, and issue resolution.
- Administer compliance, audit, findings, and risk information in Optro (AuditBoard) and other systems of record.
- Track findings, remediation plans, risks, action items, milestones, dependencies, and stakeholder commitments through closure.
- Prepare control documentation, status reports, metrics, dashboards, management reports, training materials, and stakeholder communications.
- Identify opportunities to improve compliance workflows through automation, evidence reuse, reporting enhancements, and standardization.
Requirements
- Bachelor’s degree in accounting, finance, information systems, business administration, risk management, compliance, cybersecurity, or a related field, or equivalent experience.
- Three to five years of experience in IT compliance, IT audit, internal audit, risk management, controls, GRC, or information security compliance.
- Working knowledge of IT General Controls and SOX compliance requirements.
- Experience with GRC, audit, risk management, ticketing, or evidence management platforms such as Optro (AuditBoard), ServiceNow GRC, Archer, MetricStream, or Jira.
- Ability to coordinate multiple priorities and workstreams, document processes, maintain audit evidence, and communicate clearly with stakeholders.
- Must establish employment eligibility and complete background checks and required pre-employment testing.
Nice to have
- Experience administering Optro (AuditBoard), including workflows, evidence requests, testing documentation, issue management, risk tracking, dashboards, and reporting.
- Familiarity with NIST Cybersecurity Framework, NIST SP 800-53, ISO 27001, GDPR, U.S. privacy regulations, and SEC cybersecurity disclosure requirements.
- Experience with cybersecurity assessments, penetration testing findings, vulnerability remediation, risk reviews, or security exception processes.
- CISA, CRISC, CIA, CISSP, or active pursuit of one of these certifications.
- Experience with Power Automate, SQL, Python, APIs, or similar automation and reporting technologies.
Culture & Benefits
- Remote work in an office environment with occasional office attendance for meetings, training, or business needs.
- Medical and dental coverage, retirement benefits, paid holidays, and paid time off.
- Family-building benefits, including paid maternity and paternity leave.
- Professional development opportunities and educational reimbursement.
- Fitness reimbursement and employee discount programs.
- Team-oriented, supportive culture focused on integrity, accountability, continuous improvement, innovation, and transparency.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
5 дней назад
Senior Analyst, IT Risk & GRC (Cybersecurity)
90 500 - 143 000$
15 часов назад
Senior Security Analyst, GRC (Fintech)
2 дня назад
Compliance Management Lead
108 960 - 130 000$
5 дней назад
Security Risk & Compliance Analyst (Cybersecurity)
85 100 - 154 420$
1 день назад
Senior Analyst, Information Security Risk and Compliance (Cybersecurity)
6 дней назад