Epicareer Might not Working Properly
Learn More

Senior Analyst Data Governance Risk Mitigation

Salary undisclosed

Apply on


Original
Simplified

Job Title: Senior Analyst Data Governance Risk Mitigation

Location: Remote

Duration: Contractor (Six Months with the possibility of extension)

Role Definition: Senior Compliance Analyst

Reports to: Director of Risk & Compliance

Description:

The Senior Analyst Data Governance Risk Mitigation will manage data governance and protection risks using the Securiti.ai platform. The day-to-day aspects of the role will include performing data discovery scans, identifying data privacy and security risks, implementing controls, mitigating identified risks, documenting the artifacts and the evidence, and partnering with auditors, legal, IT, and business owners to ensure privacy and security compliance. The ideal candidate will have extensive experience in data governance, risk management, and regulatory compliance and a strong background in using data governance automation tools.

Duties and Responsibilities:

  • Lead the implementation and management of the Data Discovery and Governance program utilizing privacy and data governance best practices and tools.
  • Implement data governance strategies to ensure compliance with relevant regulations (GDPR, CCPA, PCI-DSS, SOX, etc.) and internal data protection policies.
  • Perform data discovery and classification of sensitive data across the company's data stores.
  • Monitor and analyze data access patterns, sensitive data flows, and anomalies to mitigate potential risks and ensure secure data handling practices.
  • Participate in managing the IT risk register by coordinating mitigation and exceptions for all identified privacy, security, and compliance risks.
  • Participate in creating and reviewing security policies, standards, and responsibility models that clearly outline the organization's security practices and responsibilities.
  • Support facilitation of PCI-DSS, SOX, and other internal or external audits and assessments.
  • Monitor national and international privacy and security law changes to determine the impact on NMG systems and processes.
  • Endorse and support a compliance culture whereby employees are encouraged to seek clarifications and support for the company's compliance initiatives.

Requirements:

  • Bachelor's degree in Information Security, Information Technology, Data Governance, Information Systems Management, Computer Science, Engineering, or related field(s).
  • 5+ years of experience in data governance, protection, and risk management, focusing on policy implementation and risk mitigation.
  • Hands-on experience using automated data governance platforms such as Securiti.ai, BigID, Varonis, OneTrust, and other tools.
  • Security and Compliance certifications include CISSP, CIPP/US, CISA, CISM, CGEIT, or CRISC. Candidates with CISSP and CIPP/US will be preferred.

Technical Knowledge:

  • The candidates MUST possess a solid working knowledge of:
    • Data privacy laws (GDPR & CCPA) and best practices.
    • Data discovery, classification, cataloging, and protection methodologies and tools such as Securiti.ai and OneTrust.
  • Control frameworks and control objectives (e.g., NIST Privacy Framework, NIST CSF, NIST RMF, PCI-DSS, SOX, COSO, and ISO 27001 etc.)
  • Operating systems, databases, and middleware components.
  • Conducting compliance and risk assessments.
  • Management of IT and security projects.
  • The candidates MUST possess familiarity and basic working knowledge of:
    • A broad range of IT and Information Security products and technologies, such as identity and access management, vulnerability management, encryption and key management, logging and monitoring, and application security.
    • IT asset management utilizing ServiceNow (or other) Configuration Management Databases (CMDB) and network asset discovery tools.
    • Cloud-based environments and technologies with associated auditing methodologies.
    • Office 365 tools (Word, Excel, SharePoint, Entra, OneDrive, Teams, and PowerPoint)

Work Environment Characteristics:

  • Self-motivated and results-oriented, including the ability to prioritize conflicting demands.
  • Exceptional organizational skills to balance work and lead projects.
  • Strong verbal and written skills.
  • Candidate must be outgoing and service-oriented.
  • The candidate must be able to build consensus, collaborate, and build strong relationships with various internal and external stakeholders (business, development, security, etc.).
  • Ability to adapt and apply information to new scenarios and technologies.
Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.
Report this job