GRC Analyst
Granify
This job is no longer accepting applications
See open jobs at Granify.See open jobs similar to "GRC Analyst" Work In Tech.What you will be doing:
- Compliance- Interact with stakeholders as follows:
- Interview them to learn how their processes work.
- Request supporting evidence for processes
- Analyze information from interactions with stakeholders to determine the following:
- If internally-defined controls align with ISO 27001 requirements.
- If internally-defined controls are operating effectively
- Document the interview process, outcome, and related evidence.
- Communicate detected non-conformities, opportunities for improvement, and recommended corrective actions to stakeholders.
- Track progress for corrective actions.
- Calculate and provide program metrics (number of controls tested; test results; and corrective action status) to senior leadership.
- Risk Management
- Help manage the connection between internal audit and risk management:
- Collate non-conformity reports and analyze how non-conformities impact the risk rank of the domain they are included in.
- Calculate and communicate calculated risk rank based on the analysis performed.
- Update risk rank when internal audit corrective actions are completed and result in non-conformities being resolved.
- In addition to helping manage the connection between internal audit and risk management, help perform risk analysis for new systems, software, and/or identified vulnerabilities
- Develop and document risk treatment recommendations.
- Communicate risk treatment recommendations to stakeholders.
- Track risk treatment progress and collate metrics.
- Communicate risk treatment metrics to senior leadership.
- Governance
- Organize documentation reviews, taking ownership of communicating review requests to appropriate stakeholders and tracking their review progress.
- Collate review feedback and apply it to related documentation.
- Prepare documentation for final publishing.
- Work with appropriate business units to help communicate policy updates to Bazaarvoice team members.
- Work with stakeholders to support them in developing ISMS documentation they own
- Provide guidance to stakeholders regarding documentation they must develop in support of ISMS policies (standards, processes, plans).
- Track the completion status of stakeholder’s documentation.
- Help stakeholders finalize and publish their documentation.
- Ensure stakeholder documentation is represented in ISMS documentation set.
This job is no longer accepting applications
See open jobs at Granify.See open jobs similar to "GRC Analyst" Work In Tech.