Job Description
This is a full time job onsite in Woodbridge NJ. Only accepting local candidates and must be a green card or US citizen.
Job Description :
The GRC Analyst will collaborate with process owners, internal auditors, external auditors, and other stakeholders to assist in reviewing, monitoring, and resolving findings. This includes helping the team manage SOX and GLBA Compliance programs.
The GRC Analyst will support the implementation of internal and external assessments, assist with compliance audits, and ensure compliance with existing and emerging regulations and standards including GLBA, SOX, and other GRC activities.
KEY RESPONSIBILITIES
- Gather relevant evidence to support annual testing for internal and external audits. Maintain and monitor a central repository for audit evidence. Ensure timely and accurate response to internal and external audit requests.
- Provide training and guidance to employees and other stakeholders on cybersecurity best practices and awareness including but not limited to :
- New Hire Training,
- Monthly cybersecurity newsletters and phishing campaigns,
- Administration of the Cybersecurity Compliance training program
- Gather relevant evidence and documentation to support risk assessments using various frameworks to identify control ratings, strengths, potential gaps and action plans.
- Leverage the Bank’s GRC platform to document and manage security exceptions, violations, incidents, and other risk concerns to closure.
- Maintain up-to-date documentation of procedures and methods that serve to broaden team knowledge and industry expertise.
- Assist GRC Manager with maintaining security standards, policies, and practices on an annual basis to make sure they reflect the current environment
- Collaborate with business lines to help satisfy new and existing regulatory obligations.
MINIMUM SKILLS REQUIRED
1-3 years’ experience in cybersecurity with exposure with various security frameworks. Understanding of cybersecurity governance frameworks, Sarbanes Oxley (SOX) compliance requirements and IT General Controls (ITGC)Information Security Governance experience or related trainingDetail oriented with good organizational skillsEffective written and verbal communication skillsIntermediate proficiency with Microsoft Office