6 дней назад
Senior IT GRC Analyst (Cybersecurity)
80 051 - 165 000$
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Senior IT GRC Analyst (Cybersecurity): Leading cybersecurity governance, risk, and compliance for a banking environment with an accent on ServiceNow GRC, control frameworks, SOX IT audits, and regulatory readiness. Focus on evaluating technology risks, managing remediation issues, coordinating audit evidence, and aligning security controls with NIST, FFIEC, CIS, ITIL, COBIT, and applicable regulations.
Location: Fully onsite in Hillsboro, Oregon, United States
Salary: $80,051–$165,000 per year, with possible performance-based incentive compensation.
Company
provides banking services and offers a comprehensive employee benefits package.
What you will do
- Lead cybersecurity and IT governance, risk, and compliance activities, including maintaining the IT operating model, policies, standards, and process documentation.
- Perform formal technology risk analyses and self-assessments using NIST CSF, FFIEC, CIS, ITIL, COBIT, ISO 27002, and related frameworks.
- Develop, analyze, and monitor technology and security controls to support compliance with approved standards, policies, and regulatory expectations.
- Manage end-to-end GRC issue workflows in ServiceNow, including intake, validation, prioritization, remediation tracking, evidence management, and closure.
- Coordinate SOX IT audit activities, including scope clarification, evidence collection, submission, issue tracking, status reporting, and resolution.
- Identify new assets, evaluate their risks, track cybersecurity program gaps, and advise technology teams and business stakeholders on compliance readiness.
Requirements
- Bachelor’s degree in computer science or an equivalent field preferred.
- 7–10 years of experience in information security, IT audit, information technology operations, or a combination of these areas.
- ServiceNow IRM/GRC experience, including workflow design and optimization, reporting, and feature implementation.
- Knowledge of risk management, internal audit, information security management, systems and network concepts, access controls, encryption, network security, security operations, threat modeling, and security architecture.
- Knowledge of PCI DSS, GLBA, HIPAA, FFIEC requirements, and other applicable financial-services regulations.
- Ability to work cross-functionally, build stakeholder relationships, and respond effectively to changing priorities.
Culture & Benefits
- Healthcare coverage including medical, dental, and vision plans.
- 401(k) retirement savings plan with employer match for qualifying contributions.
- Paid vacation, sick days, volunteer days, and holidays.
- Life and disability insurance, employee assistance, mental health resources, identity theft protection, legal support, and insurance discounts.
- Tuition assistance and access to an online discount marketplace.
- Occasional travel may be required.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
1 день назад
IT Risk & Compliance Analyst (Cybersecurity)
84 000 - 94 000$
6 дней назад
GRC, Vulnerability Management Analyst (Cybersecurity)
7 дней назад
Sr Manager, InfoSec Governance Risk and Compliance (GRC)
112 000 - 208 000$
2 дня назад
Senior Security Analyst, GRC (Fintech)
6 дней назад
Data Security Consultant (Cybersecurity)
130 000 - 150 000$
7 часов назад
Governance, Risk & Compliance (GRC) Analyst (Defense)
120 000 - 150 000$