Employer Active
Job Alert
You will be updated with latest job alerts via emailJob Alert
You will be updated with latest job alerts via emailNot Disclosed
Salary Not Disclosed
1 Vacancy
Hello
GRC Analyst- Suffolk County NY
We have below job opening.
If you are interested and your experience match with job description.
Please send your updated
Job: GRC Analyst
Location: Suffolk county NY
Duration: Long Term contract
US Citizen only with Security Clearance
Experience 10 Years
Job Description-
At the direction of the CIO CTO CISO to perform the following activities:
1. When called upon participate in executive meetings.
2. Verify current Laws and Regulation (Federal State County) and all associated compliance requirements for Suffolk County.
3. Review and bolster existing IT Security policy standards and procedure development (aligned with industry frameworks (e.g. NIST) including but not limited to the following areas:
1. Enterprise Information and Information Technology Security Policies Standards and supporting procedures.
2. Incident Management Policy and supporting procedures/testing.
1. Cyber Incident Response Plan.
3. System and Application Configuration standards.
1. Server CIS Hardened Builds for Server OS
2. Endpoint CIS Hardened Builds for Endpoint OS
3. Application Secure Coding Standards
4. Disaster Recovery and Business Continuity Policy/Plans/Testing
1. Development of department business impact assessments risks contingencies RTO/RPO
5. Third Party Risk Management
1. Review existing vendor onboarding practices / offboarding practices to align with current industry standards.
2. Review existing security addendums
6. Personnel Security
1. Review existing Onboarding practices to align with current industry standards.
2. Review existing offboarding practices to align with current industry standards.
7. Security Awareness / Policy Acknowledgement.
1. Review existing practices to align with current industry standards.
4. Enhance current Risk Management and Risk Exception processes and supporting documentation.
Additional Information :
All your information will be kept confidential according to EEO guidelines.
Remote Work :
No
Employment Type :
Contract
Contract