Talent.com
IT Risk & Compliance (ITRC) Analyst
IT Risk & Compliance (ITRC) AnalystATR International • San Francisco, California, US
IT Risk & Compliance (ITRC) Analyst

IT Risk & Compliance (ITRC) Analyst

ATR International • San Francisco, California, US
[job_card.30_days_ago]
[job_preview.job_type]
  • [job_card.full_time]
[job_card.job_description]

Job Description:

This role supports the ITRC goal to ensure risk inherent to technology systems and data is managed to a level within the Bank’s risk appetite The ITRC Analyst is responsible for monitoring, reporting, and executing risk management activities in areas such as technology deployments, vulnerability exposure assessments, third party access to non-public data, and information security used to protect against current or emerging threats to the Bank Additionally, this role partners with key stakeholders to ensure compliance with the IS and IT frameworks Primary Responsibilities: ·Conduct readiness assessments, including reviews of relevant documentation in advance of audits, 2LOD assessments, and external assessments. · Maintain the inventory of SOX IT General Controls (ITGC) and control tests in ServiceNow, updating as directed, and identifying opportunities for improvements in reporting and in using automation. · Liaison between control owner and internal auditors, and 2LOD assessors during audits and assessments, responsible for supporting control owners in the timely submission of artifacts · Ability to map key Information Security and Technology controls identified in policies, standards, and process documents to industry frameworks such as NIST CSF, NIST 800-53, CSA CCM, CIS v8.1, and regulatory requirements in FHFA Advisory Bulletins. · Ability to identify and document technology processes. · Manage the LogicGate Governance Library ensuring Information Security and Technology documents align with approval and publication requirements, relying equally on automated reminders as well as active engagement with document owners. · Maintain ITRC document archives in the ITRC shared repository. · Responsible for reporting status at a recurring cadence of open findings, observations, recommendations, and self-identified issues, and for submitting formal audit observation closure documentation. · As directed by the ITRC MD, document and report the progress and value of in-flight ITRC initiatives, identified risks, and planned initiatives. · Provide compliance review of requests for deviations from Information Security and Technology policies and standards, confirming compliance with Technology Exception requirements for components such as compensating controls, risk assessment, and documentation supporting exception request rationale. · Participate as a key stakeholder in the Architecture Assessment Review process, documenting meeting decisions, tracking deliverable commitments, and ensuring next steps are completed for proposed new technologies or changes in existing technologies. · Support ITRC team members as needed in conducting third-party security risk assessments for changes to existing third parties or proposed third party technologies.

Requirement:

Skills/Knowledge: · Required Core Competencies: Customer Focus, Decision Quality, Ensures Accountability, Drives Results, Drives Engagement, Collaborates, Values Differences, Communicates Effectively with all levels of staff and management, Instills Trust · 3 - 5 years of experience in technology risk or IT audit · Knowledge and experience with technology frameworks is required, e.g., CIS v8.1, CSA CCM, CoBIT, NIST, ITIL, et al. · Knowledge of Operational Risk Management and Technology Risk Management · Demonstrated ability to promote teamwork, act as a change agent, effectively remove obstacles, maintain high level of morale and motivation, and lead by example · Familiarity with SOX ITGC · Must be proficient with Microsoft Office (Word, Excel, PowerPoint) and Microsoft SharePoint. · Must have strong communication skills and be able to effectively communicate with all functional levels of the organization · Project management, planning, problem-solving and organizational skills required, preferably using Atlassian JIRA · Strong analytical, issue identification, prioritization, resolution, and report writing skills required. · Must be proactive and must be able to meet established deadlines. · Experience with a Governance, Risk and Compliance (GRC) tool is highly desirable, preferably ServiceNow and LogicGate. · Ability to learn use of the ProcessUnity/CyberGRX third party risk management platform Criteria: · 2 to 3 years experience supporting operational and technology risk management activities for Information Security and Technology

[job_alerts.create_a_job]

IT Risk Compliance ITRC Analyst • San Francisco, California, US

[internal_linking.similar_jobs]
IT Senior Analyst - Disaster Recovery

IT Senior Analyst - Disaster Recovery

University of California, San Francisco • San Francisco, CA, United States
[job_card.full_time]
IT Senior Analyst - Disaster Recovery.The Senior Analyst, Disaster Recovery is a pivotal role within the Information Technology department, reporting directly to the IT Disaster Recovery and Busine...[show_more]
[last_updated.last_updated_variable_days] • [promoted]
Senior Compliance Analyst

Senior Compliance Analyst

Russell Tobin • San Mateo, CA, United States
[job_card.full_time]
Location: San Francisco, CA (Onsite).Compliance Analyst within the Office of IT Hygiene plays a critical role in ensuring IT Hygiene practices and standards are consistently followed across the ent...[show_more]
[last_updated.last_updated_variable_days] • [promoted]
Risk Consulting - Risk Technology - Oracle GRC - Manager

Risk Consulting - Risk Technology - Oracle GRC - Manager

Ernst & Young Oman • San Francisco, CA, United States
[job_card.full_time]
Location: Boston, Chicago, Cincinnati, Dallas, Hoboken, Houston, Los Angeles, Miami, New York, San Francisco, San Jose, Seattle.At EY, we’re all in to shape your future with confidence.We’ll help y...[show_more]
[last_updated.last_updated_variable_days] • [promoted]
Head of IT SOX

Head of IT SOX

Anthropic • San Francisco, CA, United States
[job_card.full_time]
Anthropic’s mission is to create reliable, interpretable, and steerable AI systems.We want AI to be safe and beneficial for our users and for society as a whole.Our team is a quickly growing group ...[show_more]
[last_updated.last_updated_30] • [promoted]
Engagement Manager - Risk Infrastructure

Engagement Manager - Risk Infrastructure

Inizio Partners Corp • San Francisco, CA, United States
[job_card.full_time]
About the job Engagement Manager - Risk Infrastructure.As the Risk Infrastructure Engagement Manager, you will lead a critical project from onshore for strategy implementation in.This role requires...[show_more]
[last_updated.last_updated_30] • [promoted]
Strategic BSA Risk Advisor: KYC/AML Compliance Lead

Strategic BSA Risk Advisor: KYC/AML Compliance Lead

East West Bank • San Francisco, CA, United States
[job_card.full_time]
A premier financial institution is seeking a BSA Risk Advisor to ensure effective communication regarding financial crime risk controls.The ideal candidate will have over 7 years of compliance expe...[show_more]
[last_updated.last_updated_30] • [promoted]
IT Business Systems Reporting Analyst

IT Business Systems Reporting Analyst

University of California - San Francisco Campus and Health • San Francisco, California, United States
[job_card.full_time]
IT Business Systems Reporting Analyst.The Oracle Reporting Analyst is responsible for designing, developing, and maintaining reports and dashboards across Oracle Cloud ERP (and related systems) to ...[show_more]
[last_updated.last_updated_variable_days] • [promoted]
Senior GRC Security Lead — ISO/NIST, Risk & Audits

Senior GRC Security Lead — ISO/NIST, Risk & Audits

Lambda • San Francisco, CA, United States
[job_card.full_time]
A leading AI infrastructure company is seeking a Cybersecurity Risk Manager to enhance their compliance framework.Responsibilities include managing audits, communicating with stakeholders, and ensu...[show_more]
[last_updated.last_updated_30] • [promoted]
Information Security Risk Analyst

Information Security Risk Analyst

Compunnel, Inc. • San Francisco, CA, United States
[job_card.full_time]
We are seeking an experienced Information Security Risk Analyst to identify, assess, and communicate security risks across business processes and technologies.The ideal candidate will combine techn...[show_more]
[last_updated.last_updated_variable_days] • [promoted]
Governance, Risk & Compliance Lead

Governance, Risk & Compliance Lead

Perplexity • San Francisco, CA, United States
[job_card.full_time]
Perplexity is seeking a highly experienced Governance, Risk & Compliance Analyst to join our world-class team.You will help shape our compliance and risk management program.If you are a self-motiva...[show_more]
[last_updated.last_updated_variable_days] • [promoted]
Technology Risk Manager - IT Audit Leader

Technology Risk Manager - IT Audit Leader

Ernst & Young Advisory Services Sdn Bhd • San Francisco, CA, United States
[job_card.full_time]
A global professional services firm in San Francisco seeks a Manager for Assurance - Technology Risk.The role involves planning and performing IT-related audits and supervising audit teams, with a ...[show_more]
[last_updated.last_updated_30] • [promoted]
IT G&A Strategy Partner - Biotech Systems & Compliance

IT G&A Strategy Partner - Biotech Systems & Compliance

Kyverna Therapeutics • Emeryville, CA, United States
[job_card.full_time]
A clinical-stage biopharmaceutical company in Emeryville, CA is seeking an experienced IT G&A Business Partner to enhance and optimize enterprise systems across Finance and HR.This hybrid role requ...[show_more]
[last_updated.last_updated_variable_days] • [promoted]
IT Senior Analyst - Disaster Recovery

IT Senior Analyst - Disaster Recovery

University of California • San Francisco, CA, United States
[job_card.full_time]
IT Senior Analyst - Disaster Recovery.The Senior Analyst, Disaster Recovery is a pivotal role within the Information Technology department, reporting directly to the IT Disaster Recovery and Busine...[show_more]
[last_updated.last_updated_variable_days] • [promoted]
Senior Actuarial Analyst, Cyber Pricing & Risk

Senior Actuarial Analyst, Cyber Pricing & Risk

At-Bay • San Francisco, CA, United States
[job_card.full_time]
A leading insurance technology company in San Francisco is seeking a Senior Actuarial Analyst for its Pricing team.This role involves managing program profitability, enhancing pricing accuracy, and...[show_more]
[last_updated.last_updated_variable_days] • [promoted]
Governance, Risk & Compliance Lead

Governance, Risk & Compliance Lead

Pantera Capital • San Francisco, CA, United States
[job_card.full_time]
Perplexity is an AI-powered answer engine founded in December 2022 and growing rapidly as one of the world’s leading AI platforms.Perplexity has raised over $1B in venture investment from some of t...[show_more]
[last_updated.last_updated_30] • [promoted]
IT Senior Director: Cybersecurity & Compliance

IT Senior Director: Cybersecurity & Compliance

PacBio • Menlo Park, CA, United States
[job_card.full_time]
A leading life science technology firm is seeking a Senior Director, IT to lead the global IT organization.This role encompasses the development of secure and compliant technology solutions while p...[show_more]
[last_updated.last_updated_30] • [promoted]
Senior IT Auditor – Fintech Risk & Cyber Controls

Senior IT Auditor – Fintech Risk & Cyber Controls

Mercury • San Francisco, CA, United States
[job_card.full_time]
A leading fintech company in San Francisco is looking for an IT Auditor to assess cybersecurity and data security risks.In this role, you'll scope and plan audits, conduct process walkthroughs, and...[show_more]
[last_updated.last_updated_30] • [promoted]
Risk & Resilience Analyst: Quantify Risk, Shape Strategy

Risk & Resilience Analyst: Quantify Risk, Shape Strategy

McKinsey & Company • San Francisco, CA, United States
[job_card.full_time]
A global consulting firm in San Francisco is seeking a Business Analyst in Risk & Resilience.The role involves direct client interaction to address risk exposures and develop enterprise risk manage...[show_more]
[last_updated.last_updated_variable_days] • [promoted]