Senior Analyst, Information Security Risk and CompliancePosted today$110K

The opportunity

Senior Manager, Security Risk and Compliance

What you'll do

  • Introduce innovative, differentiating capabilities that enhance our overall: GRC program and align risk strategies with business priorities, including collaborating with the team for operationalizing the common control framework approach to achieve our various compliance needs

  • Enhance internal processes, policies and programs by incorporating AI or: other automation to streamline compliance efforts while ensuring compliance requirements are maintained

  • Provide leadership to internal functions in the application, maintenance and: improvement of access management, change management and operational procedures and department specific processes for both current and future IT systems that come into scope

  • Establish credibility and maintain a strong working relationship with key: stakeholders across the business, internal and external auditors to understand their current and planned activities that impact ITGC SOX, FedRamp, and PCI

  • Partner with control owners and operators to validate the completeness and: accuracy of ITGC control execution, ensuring ITGC’s are designed, ChargePoint documentation and teams are audit-ready, and controls executed and monitored effectively

  • Build reporting to track and monitor overall GRC and other security project: status as needed for monthly and quarterly reporting to senior management

What they're looking for

  • Bachelor’s degree in General Business, Information Systems, Engineering,: Science or a related field and with a minimum of 5 years’ relevant experience
  • + years of internal controls and risk management experience including working: with ITGC SOX, SOC 1/2/3, or IT Internal Audit activities and programs to support compliance efforts
  • Good knowledge of Sarbanes-Oxley, NIST 800-53, Fedramp, ISO 27001, NIST CSF: and commonalities across frameworks and standards
  • Solution-oriented mindset and risk-based approach to identifying, evaluating: and addressing critical compliance risks, operational technology risks and the relevant business and governance processes
  • Experience working with and managing both internal and external auditors
  • Familiarity with SAAS-based applications, such as NetSuite, Workday,: Salesforce, Github, and infrastructure providers – AWS, Google Cloud from IT controls perspective and ability to understand in-house developed systems and CI/CD development processes
  • Good written and verbal communication skills with the ability to influence: broad range of stakeholders (Engineering, IT, Legal, Auditors, Product, Finance, etc.) and report policy and compliance results and risks
  • Excellent organizational skills