Role: GRC ( Governance Risk and Compliance) Specialist
Location Required: San Mateo. CA (Onsite)
Type: W2/Fulltime
Job Description:
- Minimum 8 years experience in Information Security Technology and minimum 4 years in Risk & Compliance
- Establish and execute IT compliance program in collaboration with multiple internal and external stakeholders assess existing controls and identify new controls that need to be designed and implemented.
- Assist control owners and executives to remediate control weaknesses and address audit action plans for their groups and prepare for future audits.
- Monitor IT compliance posture relevant to each group and report monthly and quarterly (to various governance bodies)
- Basic Knowledge on security models such as ITIL ISO27002SOX PCI DSS and Cobit 5 Deliver Managed Security Services in compliance with PCI DSS and framework compliance to COBIT 5
- Run compliance scans and deep dive into compliance findings
- Understand unified control catalog develop control guidance and deliver training to control owners.
- Support groups and enterprise initiatives with IT compliance requirements
- Participate in formal security risk analysis and technical assessment programs for various cybersecurity compliance initiatives and processes
- Oversee security policies standards guidelines and baselines
- Ensure policies are reviewed and updated regularly
- Assist Client to define Security requirements based upon Business needs and their Information Security Policy
- Ensure and enforce security controls in the area of Networks and Applications to drive policy compliance and risk mitigation.
- Controlling and managing access rights to the information system and assets that manage these information repositories
- Securityrelated Incident handling and registration
- Provide Evaluation which includes supporting internal audits and evaluating Security Incidents
- Perform evidence gathering to validate compliance as requested and report audit results to appropriate oversight bodies