Talent.com
Esta oferta de trabajo no está disponible en tu país.
Information Security GRC Risk Analyst

Information Security GRC Risk Analyst

OneTrustmadrid, España
Hace más de 30 días
Descripción del trabajo

We are looking for a dynamic Information Security GRC Analyst to support Information Security by performing various governance, risk, and compliance activities as part of the OneTrust InfoSec GRC team.

Your Mission

The Security Risk Analyst is responsible for identifying, assessing, and mitigating risks related to the security of an organization's information systems and data. This role encompasses analyzing potential threats, developing strategies to protect against security breaches, and ensuring compliance with industry standards and regulations.

Key Responsibilities

  • Conduct thorough risk assessments to identify vulnerabilities and potential threats to the organization's information systems.
  • Work within the OneTrust platform on a daily basis to monitor, track, document, and analyze risks.
  • Be the technical Subject Matter Expert on the OneTrust ITSRM product (from implementation to maintenance).
  • Create repeatable metrics for OneTrust's risk posture.
  • Prepare detailed reports on security findings from risk assessments & audits that include recommendations for improvements.
  • Collaborate with Information Security to establish a reporting process for risks and exceptions.
  • Perform regular security audits to ensure compliance with internal policies and external regulations.
  • Assist in the creation and maintenance of security policies, procedures, and protocols.
  • Support customer audits as needed.
  • Support the overall ERM function.

You Are

  • A team player who can work well within the GRC team.
  • Critical Thinking : Ability to think critically and strategically about potential security threats and solutions.
  • Proactivity : Proactive approach to identifying and mitigating risks before they become issues.
  • Team Collaboration : Strong teamwork and collaboration skills to work effectively with cross-functional teams.
  • Adaptability : Ability to adapt to changing security landscapes and emerging threats.
  • Efficient : Facilitate and manage multiple questionnaires and due diligence activities simultaneously.
  • Organized : Maintain a high level of organization to manage multiple tasks and projects effectively.
  • A Trusted Advisor : Serve as a reliable advisor to stakeholders, providing expert guidance on security matters.
  • A Relationship Builder : Ability to listen, build rapport, and credibility as a partner vertically and horizontally.
  • A Technical Innovator : Possess the ability to become a technical SME in the OneTrust platform and create and manage your own assessments and workflows.
  • Value Driven : You are detail-oriented with an eye for quality.
  • Ability to execute given high-level direction.
  • Asks good questions and is always learning.
  • Your Experience Includes

  • Deep understanding of information security frameworks, risks, and mitigation strategies.
  • Deep understanding of the technical aspects surrounding risks to the organization.
  • Understanding of applicable laws and regulations, including but not limited to, GDPR, CCPA, PCI-DSS, SOC 2, ISO, and FedRAMP.
  • Working knowledge of security risk management methodologies and procedures.
  • Understanding of the different types of sensitive data, and the classifications of that data.
  • Understanding of technology domains including governance, risk management, security, privacy, information technology, and business continuity.
  • Bachelor’s degree; or 5-8 years of equivalent work experience.
  • J-18808-Ljbffr

    Crear una alerta de empleo para esta búsqueda

    Risk Analyst • madrid, España