DescriptionThe Global Cybersecurity Compliance Analystcandidates will be evaluated based on their ability to perform the duties listed below while demonstrating the skills and competencies necessary to be highly effective in the role. These skills and competencies include:
Responsibilities- Identify document and conduct compliance assessments and validate the effectiveness of cybersecurity controls across the organization
- Communicates assessment issues to team owners and custodians of information risk business partners or information governance teams and information security teams.
- Proactively manage and maintain UL customers requests (questionnaire) process by collaborating with relevant key stakeholders across the organization to complete/respond to cybersecurity related questions
- Partner with IT teams and other key stakeholders (e.g. Legal) advising both on applicable control requirements and potential solutions to address compliance issues
- Identify control deficiencies and maintain records of deficiency details including management response documentation and exposure check evidence
- Stay abreast of and proactively informed on developing relevant legislative statutory contractual regulatory concerns and evolving compliance control solutions
- Assists with the evaluation of the effectiveness of the information security program by developing monitoring gathering and analyzing information security and compliance metrics for management.
- Assist with developing and maintain compliance and risk monitoring mechanisms such as Key Risk Indicators (KRI) reports on status of risk assessment control effectiveness issues remediation and internal audit findings
- Understands and applies relevant regulatory and legal compliance requirements
QualificationsA successful Global Cybersecurity Compliance Analyst candidate will have the expertise and skills described below.
Education Training and Previous Experience
Candidates will be evaluated primarily on their ability to demonstrate the competencies required to be successful in the role as described above. For reference the typical work experience and educational background of candidates in this role are as follows:
- BS or MA in Business Computer Science Information Security or a related field
- 2 years of work experience in information security especially in an information cybersecurity risk role
- 2 years of experience in managing risk and compliance issues or similar experience managing applications projects or systems that require identification evaluation and remediation if risk
- Technical background or demonstrable understanding of a range of operational and IT risks and operations
- Strong business background; experience gathering and interpreting risks and associated impacts in the context of financial and operational concerns
- Strong understanding of compliance and riskrelated issues through demonstrated experience managing information security or regulatory compliance programs and audits
- 4 years of experience with regulatory compliance and information security management frameworks (e.g. International Organization for Standardization IS0 27000 COBIT National Institute of Standards and Technology NIST 800
Desired but not required:
- Certified Information Systems Security Professional (CISSP) Certified Information Security Manager (CISM) and/or Certified Information Systems Auditor (CISA)
Knowledge and Skills
- Detailed understanding of cybersecurity controls and the ability to characterize the spirit of the control to our business partners/control owners.
- An ability to apply original and innovative thinking to produce new ideas. Sound understanding of different factors that make up risk (e.g. assets vulnerabilities controls threats etc. and their relationships to one another to inform risk decisions
- Communicate control deficiencies outside the cybersecurity program in a way that consistently drives understanding objectives factbased decisions that optimize the tradeoff between risk mitigation and business performance.
- An understanding of organizational mission values goals and consistent application of this knowledge.
- An ability to work on several tasks simultaneously and pay attention to sources of information from inside and outside ones network within an organization.
- An ability to apply original and innovative thinking to produce new ideas. Sound understanding of different factors that make up risk and their relationships to one another to inform risk decisions
- An understanding of business needs and commitment to delivering highquality prompt and efficient service to the business.
- An ability to effectively influence others to modify their opinions plans or behaviors.
- Excellent prioritization capabilities with an aptitude for breaking down work into manageable parts effectively assessing the priority and time required to complete each part.
- Strong decisionmaking capabilities with a proven ability to weigh the relative costs and benefits of potential actions and identify the most appropriate one.
- Strong problemsolving and troubleshooting skills.
Personal Characteristics (Optional)
- Can interface with and gain the respect of stakeholders at all levels and roles in the company.
- Is a confident energetic selfstarter with strong interpersonal skills.
- Has good judgment and a sense of urgency and has demonstrated commitment to high standards of ethics regulatory compliance customer service and business integrity.
- Instinctive and creative.
- Selfmotivated and possessing a high sense of urgency and personal integrity.
- Highest ethical standards and values.
Total Rewards: We understand compensation is an important factor as you consider the next step in your career. The estimatedsalary range for this position is $80000 to $100000 and is based on multiple factors including jobrelated knowledge/skills experience geographical location as well as other factors.This position is eligible for annual bonus compensation with a target payout of 10 of the base salary. This position also provides health benefits such as medical dental and vision; wellness benefits such as mental and financial health; and retirement savings 401K) commensurate with the standard rewards offered in each individual location or country. We also provide fulltime employees with paid time off including vacation 15 days) holiday including floating holidays 12 days) and sick time off 72 hours).
#LISG2
#LIHybrid
Required Experience:
Exec