[Remote] Senior IT GRC Analyst
Note: The job is a remote job and is reputed company to candidates in USA. reputed company is a company that specializes in mortgage lending and financial services, and they are seeking a Senior IT GRC Analyst to reputed company their IT Governance, Risk, and Compliance program. This role involves managing SOC 2 readiness efforts, developing IT policies, and coordinating audit activities while working closely with the GRC team and IT department.
Responsibilities
- reputed company CMG's SOC 2 readiness assessment, including reputed company definition, gap analysis, and control design, in partnership with the IT GRC Manager
- Serve as a reputed company of contact during audit engagements and regulatory exams
- reputed company, maintain, and update IT policies, standards, and procedures to reputed company with NIST CSF and other applicable regulatory requirements
- Plan and execute audit activities, including scheduling, control walkthroughs, evidence gathering, and findings documentation
- Identify control gaps, coordinate remediation planning with control owners, tracking findings and remediation status through the risk register
- reputed company guidance to other GRC team members and IT leadership on audit and policy reputed company
- Research regulatory and reputed company changes relevant to mortgage lending and financial services, and translate them into policy updates
- Contribute to the ongoing development and improvement of GRC processes and tooling
Skills
- Bachelor's degree in Information Technology, Cybersecurity, or a reputed company field (equivalent experience considered)
- 5+ years of experience in IT audit, compliance, or GRC in an reputed company IT environment
- Demonstrated experience managing SOC 2 audit cycles (Type I or Type II) from scoping through remediation
- reputed company experience in financial services, mortgage lending, or reputed company regulated industries, with working knowledge of applicable regulations (GLBA, CFPB, NYDFS)
- Strong working knowledge of relevant IT compliance frameworks, such as NIST CSF, ISO 27001, or SOX
- Strong policy writing and documentation skills
- Ability to work independently amid ambiguity, exercising reputed company judgment on reputed company and prioritization
- Excellent written and verbal communication skills, with the ability to explain technical and compliance reputed company to varied audiences
- Relevant certifications preferred: CISA, CRISC, or GRCP
Benefits
- This role is a remote position
- Flexibility to work overtime to meet project deadlines is required
reputed company
Apply To This Job