8 часов назад
Security Compliance Analyst IV (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Security Compliance Analyst IV (Cybersecurity): Governing Generac’s enterprise information security compliance operations and ISMS across multiple regulatory and contractual frameworks with an accent on control mapping, evidence traceability, assessments, and remediation governance. Focus on coordinating audits and readiness reviews, managing exceptions and corrective actions, and improving compliance tooling, automation, and AI governance guardrails.
Location: Sussex, Wisconsin, USA
Company
develops solutions that protect homes, strengthen businesses, and support a resilient, efficient, and sustainable energy future.
What you will do
- Support the foundational operation and governance of the enterprise Information Security Management System.
- Govern compliance activities across ISO 27001, NIST CSF 2.0, NIST 800-171, TX-RAMP, and other applicable frameworks.
- Maintain the common Controls Framework and authoritative registers for controls, requirements, evidence, exceptions, corrective actions, and assessments.
- Facilitate compliance assessments, readiness reviews, surveillance activities, internal audits, external audits, and evidence validation.
- Govern exception and corrective-action workflows, monitor remediation effectiveness, and report systemic trends through KPIs and dashboards.
- Operate compliance tooling and support automation and AI-governance guardrails to improve scale, consistency, and auditability.
Requirements
- Bachelor’s degree or higher in Information Security, Cybersecurity, Information Technology, or a related field.
- 7–10 years of specialized experience in regulated environments, such as financial, federal, defense, FERC, or NERC-regulated sectors.
- Experience in security compliance, GRC operations, ISMS support, control assurance, or enterprise compliance programs.
- Experience supporting assessments or audit readiness across ISO 27001, SOC 2, NIST-based frameworks, or CMMC.
- Strong understanding of security controls, evidence quality, control mapping, remediation tracking, documentation, and workflow or register management.
- Understanding of AWS, Azure, and GCP compliance and shared-responsibility considerations, with the ability to coordinate across distributed business units.
Nice to have
- ISO 27001 Lead Implementer, ISO 27001 Lead Auditor, CISA, or another GRC-related certification.
- Experience with enterprise compliance tooling or GRC platforms.
- Experience supporting emerging regulations for connected products and digital systems, such as the EU Cyber Resilience Act.
Culture & Benefits
- Work in a cross-functional Enterprise IT Compliance & Governance team.
- Collaborate with business, technology, risk, legal, privacy, incident response, and audit stakeholders.
- Support a global enterprise environment with multiple business units and regions.
- Operate with an emphasis on integrity, accuracy, confidentiality, organization, and follow-through.
- is an equal opportunity employer.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
6 дней назад
Governance, Risk & Compliance (GRC) Analyst (Defense)
120 000 - 150 000$
5 дней назад
Security Compliance Analyst (Cybersecurity)
130 000 - 160 000$
3 часа назад
Security Compliance Analyst II (Healthcare)
70 100 - 126 200$
4 часа назад
Lead Security Compliance Analyst (Cybersecurity)
107 700 - 199 300$
6 дней назад
GRC Engineer (Cybersecurity)
1 день назад
Senior Security Analyst (GRC)
115 000 - 145 000$