Information Security Governance Analyst

A Society Group, Inc.
Foster City, CA, US
$120K-$140K a year
Full-time
Quick Apply

Join one of the most exciting startups in the automotive industry!

We are seeking a highly skilled Information Security Governance Compliance Analyst who will be responsible for ensuring that the organization adheres to established information security governance, risk management, and compliance (GRC) frameworks.

This role involves conducting internal compliance assessments, risk assessments, and ensuring adherence to policies and standards.

The analyst will work closely with various departments to ensure compliance with frameworks such as NIST 800-53, ISO 27001, ISO 21434, and other relevant standards.

In this role you will be engaged in the following areas :

Compliance Activities :

  • Develop and implement security management systems to track objectives and controls.
  • Plan and lead organization-wide security audits to ensure compliance with relevant policies, standards, and frameworks (e.

g. NIST 800-53, ISO 27001, etc.).

  • Coordinate internal and external audits with IT, Product Security, and other departments / teams.
  • Prepare, review, and maintain compliance documentation.
  • Risk Assessments :
  • Conduct risk exposure assessments to identify potential threats and vulnerabilities.
  • Perform comparative risk assessments to evaluate different solutions and their impact on security.
  • Prioritize risks based on their potential impact and likelihood, determining security ROI for prioritization considerations.
  • Develop and implement remediation plans for identified risks.
  • Policy and Standards Management :
  • Ensure compliance activities align with existing policies, standards, frameworks, and industry regulations.
  • Identify and address shortcomings in platform security and compliance processes.
  • Develop and maintain the control framework, ensuring it is up-to-date and effective.
  • Collaboration and Communication :
  • Serve as a liaison between IT and internal auditing teams.
  • Work with various departments to ensure compliance with internal and external requirements.

Requirements

Qualifications

  • Experience :
  • 6+ years of experience in conducting security control assessments or audits.
  • 6+ years experience with information security standards and privacy laws (e.g., ISO 27001, NIST, GDPR, CCPA, CPRA, etc.).
  • Skills / Knowledge / Abilities :
  • LLMs (Large Language Models), AI (artificial intelligence), ML (machine learning)
  • Strong knowledge of GRC frameworks and tools.
  • Proficiency in risk assessment methodologies and tools.
  • Conceptual understanding of the following technologies :
  • Understanding of security management tools (e.g., vulnerability scanners, file integrity monitoring, configuration monitoring, etc.

and perimeter technologies (e.g., router, firewalls, web proxies and intrusion prevention, etc.).

  • Excellent analytical and critical thinking skills.
  • Strong written and verbal communication skills.
  • Ability to work collaboratively in a dynamic, fast-paced environment.
  • Experience in automotive, aerospace, industrial control systems (ICS / SCADA), or high-assurance environments is beneficial, but not required.
  • Education :
  • Bachelor’s degree in Computer Science, Information Systems, Business, or a related field, or equivalent relevant experience.
  • Certifications (beneficial) :
  • Professional certifications such as CISA, CISM, CRISC, CISSP.

Benefits

  • Daily free breakfasts and lunches
  • Health Care Plan (Medical, Dental & Vision)
  • Life Insurance (Basic, Voluntary & AD&D)
  • Paid Time Off (Vacation, Sick & Public Holidays)
  • Training & Development
  • Retirement Plan (401k, IRA)
  • 5 days ago
Related jobs
Promoted
LanceSoft Inc
Foster City, California

We are seeking a highly skilled Information Security Governance Third-Party Risk Analyst who will assess third-party risk as part of vendor evaluations. Additionally, the analyst will conduct periodic assessments based on the sensitivity of the vendor, data in scope, or prior security incidents. Thi...

Promoted
Ursus, Inc.
Foster City, California

We are seeking an highly skilled Information Security Governance Compliance Analyst who will be responsible for ensuring that the organization adheres to established information security governance, risk management, and compliance (GRC) frameworks. Job Title: Information Security Governance Complian...

Promoted
A Society Group, Inc.
Foster City, California

We are seeking a highly skilled Information Security Governance Compliance Analyst who will be responsible for ensuring that the organization adheres to established information security governance, risk management, and compliance (GRC) frameworks. The analyst will work closely with various departmen...

Promoted
Considine Search
CA, United States

Reporting to the Information Security Director, the Information Security Analyst works within a diverse and exciting team of 6 additional skilled cybersecurity professionals. The Information Security Analyst is a wide-ranging, hands-on role encompassing the design, implementation, and maintenance of...

Promoted
Two Point Consulting
CA, United States

Premier international law firm seeks an Information Governance Analyst. ...

Promoted
Thesagegroup
Redwood City, California

Security Governance Risk & Compliance Analyst. The Sage Group’s Client, the world's largest food delivery service, is seeking a Security Governance Risk & Compliance Analyst. Perform intake and periodic security risk and business impact assessments for vendors. Work with strategic sourcing t...

Snowflake
San Mateo, California

This role will be responsible for managing the cybersecurity risks (identifying, assessing, managing, monitoring and communicating cybersecurity risks) and security policies (facilitate development, maintenance, and evolution of the security policy framework, and work with all security teams to impl...

A Society Group, Inc.
Foster City, California

We are seeking a highly skilled Information Security Governance Compliance Analyst who will be responsible for ensuring that the organization adheres to established information security governance, risk management, and compliance (GRC) frameworks. The analyst will work closely with various departmen...

Tevora
California, CA, USA

Knowledge and understanding of security engineering, system and network security, authentication and security protocols, cryptography, mobile, and web application security. Information Security Analyst (Penetration Testing). The right candidate will have technical proficiency, experience in Penetrat...

N. Harris Computer Corporation - USA
Remote, CA
Remote

As the Information Security Governance Specialist, you will utilize your wide area of expertise in risk management, cybersecurity, vulnerability management, information security governance, incident management, security frameworks and other areas to provide security compliance oversight for the Harr...