Cybersecurity Senior IT Analyst Risk and Controls
Cleveland, TN - USA
Job Summary
The Cybersecurity GRC (Governance Risk and Compliance) Risk Sr. Analyst is responsible for developing maintaining and enhancing the organizations risk management and compliance framework. This role oversees policy governance processes manages control frameworks and ensures effective control mapping across regulatory industry and internal requirements. The Sr. Analyst partners with business technology cybersecurity audit legal and compliance teams to strengthen governance practices reduce risk exposure expand risk treatment tracking and support regulatory compliance initiatives.
Responsibilities
- Obtain a thorough understanding of our business processes applications standard programs and reports as they related to privacy and data security.
- Analyze complex business processes or issues and quickly understand the business issues and related privacy and data challenges.
- Lead/Review/Perform risk assessments of new/existing technologies data processing policy exceptions and non-compliant 3rd Party Vendors.
- Identify process improvement opportunities; define improvement requirements; conduct detailed analysis; act as a liaison between the business and development resources; and support the communication/training efforts related to process changes.
- Work with the business to develop and monitor risk mitigation efforts. Ensure identified issues are tracked reported and resolved in a timely manner.
- Communicate effectively with data owners to identify needs and evaluate business solutions.
- Work frequently with key business personnel across all divisions domestically and globally.
- Exhibit personal ownership and accountability for continuous improvement.
- Deliver informative well-organized presentations. Understand how to communicate difficult/sensitive information tactfully.
- Lead in the development and implementation of cybersecurity policy standards and procedures in alignment with our framework best practices and organizational objectives.
- Work with IT and security teams to enforce cybersecurity policies and procedures.
- Regularly review and update existing cybersecurity policy standards and procedures to reflect changes in technology emerging threats and evolving business needs.
- Identify critical issues with ease. Exhibit confidence and an extensive knowledge of emerging privacy laws and best practices when solving business problems.
- Push creative thinking beyond the boundaries of existing company practices and mindsets.
- Facilitate effective team interaction. Acknowledges and appreciates each team members contributions.
- Seek and participate in development opportunities beyond training required by us.
- Complete special projects as requested
This is a remote position.
This position is not eligible for sponsorship for work authorization now or in the future including conversion to H1-B visa. Must be legally authorized to work in the country of employment without needing sponsorship for employment work visa status now or in the future.
Job duties include contact with other employees and access confidential and proprietary information and/or other items of value and such access may be supervised or unsupervised. TheCompany therefore has determined that a review of criminal history is necessary to protect the business and its operations and reputation and is necessary to protect the safety of the Companys staff employees and business relationships.
Qualifications
Education & Experience
Required:
- Bachelors Degree (or foreign equivalent) or in lieu of a degree at least 12 years in experience in the field of Information Technology or Business (work experience or a combination of education and work experience in the field of Information Technology or Business).
- 5 years in IT and/or Business.
- Experience assessing and evaluating business risk.
- Skill set includes leadership problem solving critical thinking decision-making organizational skills excellent communication (oral and written) capability to work independently.
- Intermediate knowledge of Microsoft Office tools.
- Prior experience working on teams and motivating others in a team-orientated collaborative environment across cultures.
- Business knowledge includes a working knowledge of SW structure business processes operations and goals preferred.
- Excellent writing and communication skills with the ability to translate technical concepts into clean and concise policy and standards.
- Support internal and external audits regulatory examinations compliance assessments evidence collection issue remediation and corrective action tracking.
- Strong analytical and problem-solving skills.
- Must be eighteen years or older
- Must be legally authorized to work in the United States without company sponsorship
PREFERRED REQUIREMENTS
- Experience with internal control frameworks for information technology information security IT governance frameworks and conducting and analyzing IT risk assessments.
- Demonstrate knowledge and aptitude for methods for scoring calculating and quantifying risk.
- Ability to interface with top management and effectively articulate ideas through verbal and written communications.
- Experience with MS Excel and IT GRC systems such as ServiceNow GRC
- Preferred certifications: CISSP CISA CRISC CISM CGRC or related certifications
- Knowledge of the following NIST frameworks:
- Cyber Security Framework (CSF)
- Privacy Framework (PF)
- Artificial Intelligence Risk Management (AI)
- SW experience preferred
Required Experience:
Senior IC
About Company
At Sherwin-Williams, our purpose is to inspire and improve the world by coloring and protecting what matters. Our paints, coatings and innovative solutions make the places and spaces in our world brighter and stronger. Your skills, talent and passion make it possible to live this purp ... View more