GRC Analyst Job at Suzy, Remote

dGRPYVpFUlEzd2NacE93bDdBcFRDOTBqSHc9PQ==
  • Suzy
  • Remote

Job Description

Suzy puts the voice of the consumer at your fingertips. Whether you're a novice or an expert researcher, our platform brings advanced tools together with the highest quality audience to deliver insights in minutes. Some of the biggest brands in the world use Suzy to deliver breakthrough products and experiences backed by data-driven decisions. Learn more at

The Governance, Risk, Compliance (GRC) Analyst will manage policies, procedures, and standards to govern the protection of corporate information systems, networks, data, and 3rd party services. The analyst will stay up to date on the latest cybersecurity intelligence while managing privacy workflows to ensure the company meets regulatory compliance.

Responsibilities
  • Third Party Risk Management
    • Provide oversight, coordination, and deliver the activities supporting successful risk management activities around third parties
    • Perform risk analysis for systems, processes, third-party tools/applications, and configurations
    • Perform Third Party Risk Management (TPRM) functions and analyze SOC-2 and other reporting from vendors
    • Respond to initial and annual security questionnaires from customers.
  • Controls and Risk Management
    • Manage company's Risk Register
    • Perform periodic risk assessments
    • Document the results and develop a plan of action and milestones for mitigating identified risk
    • Gather data for metric reporting for company's Information Security and Privacy Council.
  • Audits
    • Coordinate multiple large-scale audit projects and programs simultaneously
    • Help implement Governance, Risk and Control tool
    • Document business ownership and responsibilities of security controls using the company's GRC tool
    • Schedule and perform regular assessments (internal and external) to test the effectiveness of controls
    • Manage remediation efforts for the identified gaps including assessment of new or enhanced implemented controls
    • Coordinate, track, and verify remediation of audit findings.
  • Asset Management
    • Maintain Suzy's information asset inventory with accurate and updated information
    • Identify and rank the value, sensitivity, and criticality of the operations and assets that could be affected should a threat materialize.
Basic Qualifications
  • Creative problem solver and desire to learn
  • Willing to #getyourhandsdirty and work across cross-functional teams
  • Bachelor's degree or equivalent work experience (Information Technology, Engineering, Cybersecurity, Audit, Risk, Compliance, or a related technical field)
  • Familiarity with industry security frameworks, including SCF, ISO, SOC, and NIST
  • Audit, compliance, and/or risk management experience
  • Experience in Project Management Methodologies
  • Experience testing or auditing technical controls.
Preferred Qualifications
  • Certified Information Security Auditor/Manager (CISA/M) designation or CISSP, CRISC, CISA, CIPT, CIPP
  • Direct participation in ISO/SOC audits
  • Understanding of Enterprise Risk Management and Strategy frameworks
  • Providing consultative information security or risk management services to a broad range of companies
  • Experience proposing enterprise level solutions to mitigate risk
  • Experience creating and managing corporate security policies
  • Microsoft cloud technical certifications.
Benefits:
  • We take care of our employees and their families. We have generous health dental and vision benefits, and our 401K plan vests immediately
  • A friendly, fun, and collaborative work environment that allows for frequent exposure to executives
  • The opportunity to make an immediate impact as a part of a fast-growing company
  • The target base compensation for this role is $125,000 - $135,000.
Suzy is an equal opportunity employer. We are a welcoming place for everyone, and we do our best to ensure all people feel supported and connected at work. Suzy is committed to protecting its customers, employees, partners, and the company as a whole, from damaging acts that are intentional or unintentional. Effective security is a team effort involving the participation and support of every user who interacts with company information/data and systems. It is the responsibility of each individual to help protect company information assets. #LI-Remote #LI-LH1 Click Here to view our Applicant Privacy Notice Who to contact: Apply Online IMPORTANT - PLEASE INCLUDE YOUR NAME AND EITHER YOUR RETURN E-MAIL ADDRESS OR TELEPHONE NUMBER IN THE MESSAGE . Please say that you found the vacancy on MrWeb! Thanks for your interest.

Job Tags

Work experience placement, Immediate start, Remote work,

Similar Jobs

Wayne Brothers Construction

HAULING DISPATCH & OPERATIONS MANAGER Job at Wayne Brothers Construction

 ...Position Description POSITION SUMMARY The Hauling Dispatch & Operations Manager will oversee all aspects of dispatching and day-to-...  ...ClassATruckandTrailerCommercialDriversLicense(CDL) Flagcarcertification OSHA10-hourcertification Materialhandler... 

Alsglobal

Courier Job at Alsglobal

 ...testing and data-driven insights to build a healthier future.**Courier****Imagine your future with us!** At ALS, we encourage you to...  ...-art technologies and innovative methodologies, our dedicated international teams deliver the highest-quality testing services and personalized... 

Marvin

Retail and Event Representative Job at Marvin

 ...helping people live healthier, happier lives through thoughtful design, exceptional craftsmanship, and a deep understanding of how people...  ...: Represent Marvin at retail stores, trade shows, and local events Engage with shoppers and spark interest in our premium window... 

HealthTrust Workforce Solution External

Travel Cardiac Cath Lab RN Job at HealthTrust Workforce Solution External

Job Description HealthTrust Workforce Solution External is seeking a travel nurse RN Cardiac Cath Lab for a travel nursing job in Rogers, Arkansas. Job Description & Requirements ~ Specialty: Cardiac Cath Lab ~ Discipline: RN ~ Duration: 13 weeks ~40 hours...

Lowe's

Full Time - Sales Specialist - Cabinets - Day Job at Lowe's

 ...Gain extra savings with a **10% Associate Discount.**+ Learn new trade skills with our **Track to the Trades program.**For information...  ...our benefit programs and eligibility, please visit .**Your Day at Lowe's**Sales Specialists at Lowe's are very active, moving...