GRC Risk Analyst at Tanium conducting compliance assessments and developing risk management policies. Collaborating with stakeholders to ensure adherence to regulatory requirements and industry standards.
Responsibilities
Executes audits and risk assessments, communicates results of findings and makes recommendations for improvement through concise, high-quality reports
Ensures company management is knowledgeable of the risks of noncompliance to information security standards and regulatory requirements
Writes and revises policies, standards, procedures, guidelines and other documentation based on Tanium’s business needs
Participates in Information Security, Information Technology and Product Security projects driving the implementation of new process improvements and risk treatments
Works closely with Information Security, Information Technology, Product Security and System Owners to review and respond to security questionnaires and due diligence requests
Assists in the assessment and review of new vendors to ensure adequate levels of controls are in place to maintain compliance with security requirements
Prepares reports summarizing risk assessment findings and presents them to management
Recommends changes in business processes or policies to manage risks
Ensures compliance with regulatory requirements related to risk management
Monitors risks, proposing preventive measures and solutions to prevent future risks
Requirements
Bachelor's Degree in Computer Science, Engineering or equivalent experience
3-5 years in information technology / information security auditing, preferably within a software engineering environment
Technical knowledge of fundamental audit and risk concepts within the context of information technology and information security
Familiarity with one or more of the following frameworks: FedRAMP, StateRAMP, CMMC, ISO 27001:2013, SOC2, NIST Cyber Security Framework (CSF)
Experience writing audit findings, reports, policies, standards, procedures and guidelines
Comfortable performing technical interviews with technical personnel and business process reviews with non-technical personnel
Working knowledge of risk assessment methodologies, contingency planning approaches, data analysis techniques and improvement tools including root cause analysis, corrective action, preventative action, Plan-Do-Check-Act and the cost of quality
Working knowledge of improvement programs such as Total Quality Management, ISO 9001, Six Sigma, Theory of Constraints or Lean
Experience managing projects, implementing change and tracking their implementation progress
Excellent knowledge of risk analysis methodologies and tools
Alcohol Compliance Supervisor at Jiffy Lube Live ensuring responsible service of alcohol. Supervise event employees, uphold compliance with alcohol service guidelines and interact with guests for satisfaction.
Executive Director leading firm - wide Compliance Risk Assessment program for SMBC Group in financial services. Managing CRA process and collaborating with regulatory stakeholders.
Senior Product Environmental Compliance Specialist leading compliance initiatives in Stryker's Endoscopy division. Driving regulatory strategy and cross‑functional alignment in a hybrid role.
Payments RCA Professional at U.S. Bank focused on operational loss reporting and risk management compliance. Collaborating across teams to ensure timely and accurate reporting and process improvement.
Compliance Representative managing risk and compliance under U.S. Bank's financial services. Involves collaboration across various teams and addressing policy violations and customer complaints.
Corporate Compliance Analyst supporting the development of a global compliance program at Vantage Data Centers. Engaging in risk assessments, training, and compliance monitoring to drive process improvements.
Senior Executive/Executive in charge of compensation and compliance at Orfium, ensuring legal adherence and proper employee relations while managing benefits and compensation strategies.
Compliance Reporting Assistant supporting compliance activities and gaining hands - on experience in a dynamic international environment. Assist in preparing reports and dashboards while collaborating with various stakeholders.
Environmental Compliance Specialist managing compliance with environmental laws for natural gas projects in multi - state areas. Supervising consultants, preparing compliance reports, and conducting audits.
Compliance Analyst ensuring adherence to Federal Energy Regulatory Commission and ERCOT standards. Collaborating with various teams to manage compliance documentation and processes.