Security Risk Analyst
Job Summary
You may know McCormick as a leader in herbs spices seasonings and condiments and were only getting started. At McCormick were always looking for new people to bring their unique flavor to our team.
McCormick employees all 14000 of us across the world are what makes this company a great place to work.
We are looking to hire an Security Risk Analyst immediately in a Hybrid (50/50) capacity.
What We Bring To The Table:
The best people deserve the best addition to the benefits youd expect from a global leader (401k health insurance paid time off etc.) we also offer:
Competitive compensation
Career growth opportunities
Flexibility and Support for Diverse Life Stages and Choices
Wellbeing programs including
Position Overview:
The Security Risk Analyst is a key member of the Cybersecurity Governance Risk and Compliance team and will report to the Senior Manager Cybersecurity Governance Risk & Compliance. This position will be responsible for assessing security risk establishing security standards and ensuring compliance against those standards across all disciplines of the information security domain that support McCormicks global brands and subsidiaries. The ideal candidate has a strong work ethic along with strong organizational project management and problem-solving skills. Additional key qualities include the ability to work with others to drive results. This position requires excellent verbal and written communication skills spanning across all levels of management. Candidates must thrive in a demanding fast-paced work environment that is energetic driven and team-oriented. This role will also work with SMEs across the organization to mature/design security controls & mitigate risk.
Key Responsibilities:
- Intake and analysis of identified risks from a variety of sources including audits compliance checks automated vulnerability systems and other internally or externally reported risks. Process risk acceptance requests and provide necessary information and analysis to allow business leaders to determine which risks are appropriate
- Complete analyses and reports and work with the Senior Manager Cybersecurity GRC to develop a comprehensive view of risk across the company.
- Review and track action plans developed by risk owners and ensure plans are completed appropriately.
- Process policy exception requests as needed or ad-hoc risk analysis as assigned as well as execute a detailed audit plan and identify risk areas develop action plans and monitor completion.
- Draft clear concise audit reports that communicate key insights and observations to functional/business personnel and executive leadership.
- Demonstrate effective teaming skills with the ability to work independently as needed; leading initiation execution and completion to finalization and reporting for key work tasks.
Desired Candidate Profile:
- Bachelors degree in Information Technology Information Systems Risk Management Accounting or similar.
- 6 years of experience related to internal/external audit information technology or internal controls.
- Internal/External Audit Sarbanes-Oxley or other internal control (IT or operational) project experiences.
McCormick & Company is an equal opportunity/affirmative action employer. All qualified applicants will receive consideration for employment without regard to sex gender identity sexual orientation race color religion national origin disability protected veteran status age or any other characteristic protected by law.
As a general policy McCormick does not offer employment visa sponsorships upon hire or in the future.
Required Experience:
IC
About Company
McCormick spices and products have been kitchen must-haves since 1889. Learn about seasoning and cuisine while discovering tons of delicious recipes today.