Title:IT AUDITING (Governance and Compliance) Auditing Is Key
Location: Hybrid (Deerfield Beach, FL)
Duration: 12 months +
Sr.Governance and Compliance Analyst The Governance and Compliance Sr. Analyst will report to the Governance, Riskand Compliance Manager and support the Information Security department toprovide the highest quality assurance program to our customers. TheGovernance and Compliance Sr. Analyst will perform a critical role in providingIT governance and compliance as a service, including assessments, complianceprogram management and assurance, and control framework maturity evaluations.The Governance and Compliance Sr. Analyst will manage, measure, operationalizeand communicate a myriad of compliance initiatives across the enterprise,including but not limited to SOC 1 Type 2, MAR, NY DFS 500, CCPA, HIPAA.Collaboration with business areas within JM Family will be a key successcriterion for this individual.
Responsibilities
- Facilitate IT audits and assessments,including remediation of any findings noted
- Ensure compliance with regulatoryrequirements (e.g., SOC 1 Type 2, MAR, NY DFS 500, CCPA) and internalcontrols, with proactive validation of controls.
- Review regulatory and compliance mattersrelated to information technology, as the shared-service provider for allbusiness units, and perform necessary gap analysis
- Implement and maintain an informationtechnology, including security and privacy, controls framework
- Develop and maintain IT policies,standards, and procedures
- Act as an advocate for informationsecurity practices
- Execute program tasks related to theevaluation of security control framework maturity, such as stakeholderinterviews, documentation reviews, and maturity quantification.
- Engage control owners (of varyinginformation security acumen and expertise) and key stakeholders across theenterprise to collect and test evidence and assess compliance to variousrequirements (external regulatory and contractual, as well as internal controls)
- Maintain and foster relationships andtrust with key partners throughout the company
- Maintain compliance and risk managementinitiatives in a GRC platform
- Understand contractual elements with thirdparties and intelligently speak on the security requirements of a contractfrom an information security point of view
- Maintain reliable, up-to-date informationfrom the government and across the industry regarding the identificationof new security standards and governance
- Establish governance around disasterrecovery function and collaborate with key business and IT leaders todevelop security and disaster recovery standards and action plans
- As directed, conduct periodic internalassessments for security risk and compliance
- Perform other essential duties as assigned
- Project management skills formanaging multiple complex activities
- Knowledge ofcontrolsframeworks and applicable regulatory compliance mandates(e.g.,NIST, CIS CSC, COBIT, CCPA, HIPAA, GLBA, SOC 1 Type 2, MAR)
- Conduct research to keepabreast of the latest security issues, third-party vendors, andapplications as needed
Qualifications / Requirements
- Working knowledge of governanceand compliance, including policy, process, governance, controlsframeworks, and regulatory environments
- Knowledge to evaluate, buildand optimize security program elements as assigned (e.g., logical accesscontrol, application security, vendor risk management, network security,privacy)
- Experience in working withauditors
- Strong organizational skillswith ability to thrive in a sense-of-urgency environment, leveraging bestpractices, and approaching any problem as a team-player with a can-doattitude
- Strong written and verbalcommunication skills and ability to interface with all levels of businessand executive leadership
- Excellent analytical, problemsolving, and decision-making skills, applied with a solution-focusedattitude
- Strong self-directed workhabits, exhibiting initiative, drive, creativity, maturity, self-assuranceand professionalism
License/Certificate (anyof the following a plus):
CISSP,CISA, CISM, CIPP, GIAC
Skill set
Working knowledge of governance and compliance, including policy, process, governance, controls frameworks, and regulatory environmentsKnowledge to evaluate, build and optimize security program elements as assigned (e.g., logical access control, application security, vendor risk management, network security, privacy)Experience in working with auditors