GRC Risk Analyst at Tanium conducting compliance assessments and developing risk management policies. Collaborating with stakeholders to ensure adherence to regulatory requirements and industry standards.
Responsibilities
Executes audits and risk assessments, communicates results of findings and makes recommendations for improvement through concise, high-quality reports
Ensures company management is knowledgeable of the risks of noncompliance to information security standards and regulatory requirements
Writes and revises policies, standards, procedures, guidelines and other documentation based on Tanium’s business needs
Participates in Information Security, Information Technology and Product Security projects driving the implementation of new process improvements and risk treatments
Works closely with Information Security, Information Technology, Product Security and System Owners to review and respond to security questionnaires and due diligence requests
Assists in the assessment and review of new vendors to ensure adequate levels of controls are in place to maintain compliance with security requirements
Prepares reports summarizing risk assessment findings and presents them to management
Recommends changes in business processes or policies to manage risks
Ensures compliance with regulatory requirements related to risk management
Monitors risks, proposing preventive measures and solutions to prevent future risks
Requirements
Bachelor's Degree in Computer Science, Engineering or equivalent experience
3-5 years in information technology / information security auditing, preferably within a software engineering environment
Technical knowledge of fundamental audit and risk concepts within the context of information technology and information security
Familiarity with one or more of the following frameworks: FedRAMP, StateRAMP, CMMC, ISO 27001:2013, SOC2, NIST Cyber Security Framework (CSF)
Experience writing audit findings, reports, policies, standards, procedures and guidelines
Comfortable performing technical interviews with technical personnel and business process reviews with non-technical personnel
Working knowledge of risk assessment methodologies, contingency planning approaches, data analysis techniques and improvement tools including root cause analysis, corrective action, preventative action, Plan-Do-Check-Act and the cost of quality
Working knowledge of improvement programs such as Total Quality Management, ISO 9001, Six Sigma, Theory of Constraints or Lean
Experience managing projects, implementing change and tracking their implementation progress
Excellent knowledge of risk analysis methodologies and tools
Manager Regulatory Affair at Capgemini Engineering coordinating activities for the US market. Preparing submissions to the FDA and collaborating with internal teams for regulatory compliance.
Engineer IT Compliance responsible for compliance activities in regulated IT systems. Building partnerships with IT functions and ensuring regulatory alignment in pharmaceutical industry.
Regulatory Affairs Associate for managing new drug registrations and preparing documentation in the India Market. Collaborating with stakeholders and supporting compliance in bulk drug registration.
Senior Tech Compliance Analyst at Syneos Health responsible for global Technology Disaster Recovery efforts, collaborating with various teams and service providers.
Chief Nuclear Officer serving as the nuclear safety authority for BaRupOn's SMR/MMR programs. Establishing safety frameworks and ensuring regulatory compliance within the organization.
International Trade Compliance Manager overseeing compliance with international trade regulations at Northrop Grumman. Leading a team and managing compliance initiatives across multiple locations in the US.
Compliance Manager leading Autodesk's Enterprise Compliance program. Ensuring compliance with SOX, PCI regulations and overseeing security controls across teams.
Compliance Student supporting compliance and risk management activities for individual insurance at iA Financial Group. Involves monitoring processes, collaborating with teams, and assisting with compliance tasks.
Nurse Licensure & Compliance Coordinator managing multi - state nurse licensure and compliance inquiries while ensuring a positive nurse experience. Advocating for nurses and maintaining regulatory adherence at the organization.
508 Compliance Specialist working with the Office of the Inspector General for the DoD. Responsible for ensuring electronic accessibility for compliance with Section 508 regulations.