Sobre esta vaga de Senior Information Security Analyst na Great Gray Group
The Role
Great Gray is looking to add a Senior Information Security Analyst on our Information Security Team. The role will support IT governance, risk assessment, and security compliance functions and will be involved in monitoring and maintaining elements of overall IT governance, enterprise risk management, and compliance with regulations and control frameworks such as SOC2, CIS18, and NIST CSF. The analyst will focus on facilitating the review, development, implementation, and documentation supporting the ISMS policies, processes, procedures, and practices.
Location
This position will work from our Boston, MA or Wilmington, DE offices. Great Gray currently supports a hybrid work model with 4 days onsite, and 1 day remote.
Visa sponsorship or transfer of an existing visa is not available for this position. Applicants must be authorized to work directly for any employer in the United States without visa sponsorship or transfer.
Responsibilities
- IT governance & oversight, risk assessment, and security awareness.
- Internal auditing & evidence collection for IT controls compliance (PCI, SOX) and cybersecurity ISMS frameworks (SOC2)
- Vendor Risk Management assessment, onboarding, and reviews.
- Business Impact Analysis (BIA), and Sensitive Data Reviews (SDR).
- User Rights Management (URM) and Privileged Access Management (PAM) reviews for critical applications.
- Provide support in the assessment, design, and implementation of technical control requirements.
- Identify and recommend changes to improve efficiency and the effectiveness of key technical controls and processes.
- Work with control owners and system administrators to ensure quality, consistency, and operability of new and existing controls.
- Support the review of IT systems and tools to ensure the inclusion of appropriate controls and processes.
- Review test findings, support the remediation of IT control gaps, and escalate potential issues to management, where necessary.
- Validate and update IT documentation as needed to ensure processes, policies and controls are accurate.
- Complete other related duties as assigned
Qualifications & Experience
- Bachelor’s degree in Computer Science, Cybersecurity, Information Technology, or a related field.
- 5+ years of audit, compliance, or technical experience.
- Excellent knowledge of IT security control trends as well as auditing & compliance best practices.
- Effective communication skills (written and verbal) to properly articulate complicated IT controls and compliance issues to leadership and partners.
- Positive attitude and a strong commitment to delivering quality work.
- Relevant training and/or industry certifications in auditing, compliance, or IT security.
- Ability to thrive in a fast-paced, dynamic environment and manage multiple priorities effectively.
- Comfortable navigating ambiguity.
- Entrepreneurial mindset to bring best practice ideas to the team.
- Your standards reflect our core values: Growth Mindset, Disciplined Curiosity, Grit, Results Ownership, Collaboration.
Base Pay Range*
$95,000-$140,000
*This base pay range is subject to change and may be modified in the future.
The pay range displayed above is the base pay compensation range that Great Gray expects to pay for this position at the time of this posting. Individual compensation within this range, or that may warrant a provision for pay beyond this range, depends on multiple factors, including, but not limited to, candidate’s prior education and relevant work experience and training as well as position location and local market demands. Our pay-for-performance culture also includes participation in an annual incentive bonus plan for this position which is not included in the ‘Base Pay Range’ noted above.