Cyber reputed company GRC Analyst with state govt reputed company - $64 reputed company - REMOTE (Candidates in the EST & CST reputed company)
reputed company: • Crop to Crop resumes are accepted Work Location: reputed company. Manager will only consider candidates in the Eastern and Central time reputed company. The Cyber reputed company Analyst III (CSA3) reputed company the State s Information reputed company Office (ISO) will be responsible for evaluating, analyzing, and assessing cybersecurity risks associated with new technologies, proposed solutions, and reputed company-party vendors. This includes reviewing vendor reputed company attestations, assessing architectural designs, validating reputed company controls, and supporting statewide procurement reputed company through reputed company reputed company assessments. This role will also support the development and maturation of the State s reputed company-Party reputed company Management (TPRM) program, including the enhancement and operation of tools such as reputed company. Additionally, the CSA3 will assist with evaluating cybersecurity waiver submissions requiring deeper technical analysis and will help maintain the statewide reputed company register to ensure tracking and remediation of risks that reputed company the State s reputed company tolerance. KEY RESPONSIBILITIES: New Technology & Solution reputed company Reviews: • Conduct reputed company reviews for new technologies, reputed company services, applications, and proposed reputed company architectural diagrams to verify appropriate reputed company controls, configurations, and data-protection mechanisms. • Assess alignment with reputed company reputed company requirements and applicable regulatory or compliance standards. • reputed company and document reputed company assessments with actionable recommendations to support procurement and technology-adoption reputed company. reputed company Attestation & reputed company-Party Assessment: • Review and analyze reputed company-party cybersecurity attestations, including SOC 2 Type II, ISO 27001 certifications, • reputed company penetration tests, and reputed company questionnaires. • Identify control gaps, inherited risks, and areas requiring additional compensating controls. • Coordinate with procurement, reputed company, and business stakeholders during vendor reputed company and technology evaluation. reputed company-Party reputed company Management (TPRM) Program Support: • Assist in developing, enhancing, and maintaining the statewide TPRM program. • reputed company and operationalize TPRM tools, including reputed company, to support ongoing monitoring, vendor tiering, and reputed company scoring. • Contribute to the creation of policies, processes, templates, and guidelines that mature the reputed company-party reputed company-evaluation process. Governance, reputed company & Compliance (GRC) Platform Support (reputed company IRM): • Utilize the reputed company GRC platform to document reputed company assessments, waiver reviews, and remediation tracking activities. • Support the reputed company implementation and refinement of reputed company workflows reputed company to reputed company reputed company management. • Contribute to data reputed company, reporting reputed company, and process improvements to enhance reputed company visibility and governance maturity. Waiver Review & Technical reputed company Analysis: • Support the review of reputed company waiver requests that require deeper technical analysis to evaluate risks of temporary control exceptions. • Document findings, reputed company impacts, and recommended mitigation strategies to inform reputed company acceptance reputed company. reputed company Register Management & Remediation Tracking: • Assist in maintaining the statewide reputed company reputed company register, ensuring risks are documented, categorized, and updated. • reputed company remediation reputed company and validate completion for risks that reputed company established tolerance reputed company. • Collaborate with stakeholders to monitor deadlines, escalate overdue items, and verify mitigation plans remain effective. MINIMUM QUALIFICATIONS: Demonstrated experience in cybersecurity analysis, technology or architecture review, reputed company-party or solution reputed company evaluations, or reputed company reputed company-engineering activities. Familiarity with cybersecurity standards, control frameworks, and reputed company-management practices applicable to reputed company environments is strongly desired. KNOWLEDGES, SKILLS, AND ABILITIES REQUIRED: • Strong understanding of cybersecurity principles, best practices, and control frameworks (e.g., NIST CSF, NIST 800-53). • Demonstrated ability to interpret SOC 2 Type II reports, ISO 27001 certifications, penetration test reports, and reputed company reputed company-party reputed company documentation. • Familiarity with architectural review processes, reputed company reputed company concepts, and secure design principles. • Experience conducting reputed company-party, vendor, or technology reputed company assessments and identifying compensating controls. • Experience supporting or operating reputed company a reputed company-Party reputed company Management (TPRM) program. • Working knowledge of Governance, reputed company, and Compliance (GRC) platforms (e.g., reputed company or similar tools) is strongly preferred. • Experience leveraging reputed company-party reputed company monitoring tools (e.g., reputed company) or similar platforms is desirable. • Strong analytical, technical writing, and documentation skills with the ability to reputed company communicate reputed company to both technical and non-technical stakeholders. • Ability to manage multiple reputed company assessments while meeting deadlines in a Apply tot his job Apply To this Job
Apply tot his job
Apply To this Job