GRC Consultant-68498
Dallas, TX - USA
Job Summary
Function
Cloud & Data EngineeringWere Hitachi Digital Services a global digital solutions and transformation business with a bold vision of our worlds potential. Were people-centric and here to power good. Every day we future-proof urban spaces conserve natural resources protect rainforests and save lives. This is a world where innovation technology and deep expertise come together to take our company and customers from whats now to whats next. We make it happen through the power of acceleration.
Imagine the sheer breadth of talent it takes to bring a better tomorrow closer to today. We dont expect you to fit every requirement your life experience character perspective and passion for achieving great things in the world are equally as important to us.
Title: Senior GRC Analyst
Location: Dallas TX (Onsite)
Experience: 57 years
Meet Our Team
Join our Information Security Governance Risk and Compliance (GRC) team where we partner with Security Engineering IT Legal Privacy Internal Audit and business teams to strengthen the organizations security and compliance posture.
Our team is responsible for establishing effective security governance identifying and managing technology risks maintaining alignment with industry and regulatory frameworks and supporting internal and external audits.
In this role you will help embed security and risk management into day-to-day business operations while improving control monitoring evidence collection GRC processes and compliance automation.
What Youll Be Doing
- Governance: Maintain and update information security policies standards procedures and security-control documentation.
- Track policy exceptions and support remediation and governance processes.
- Translate regulatory security and compliance requirements into operational controls.
- Define track and report security metrics and KPIs to support leadership visibility and decision-making.
- Risk Management
- Conduct security risk assessments across applications systems infrastructure business processes and vendors.
- Maintain the enterprise risk register and track identified risks remediation plans owners due dates and residual risk.
- Perform third-party/vendor security risk assessments and due diligence.
- Support business impact analysis and risk-treatment decisions.
- Partner with stakeholders to identify control gaps and drive remediation activities.
- Compliance & Audit
- Map and assess controls against security and compliance frameworks including:
- ISO 27001
- SOC 2
- NIST CSF / NIST 800-53
- PCI-DSS
- GDPR HIPAA and other applicable privacy/regulatory requirements
- Coordinate internal and external audits from evidence gathering through findings closure.
- Manage audit evidence requests control testing findings and remediation tracking.
- Support continuous control monitoring and evidence-collection initiatives.
- Support security certification and attestation programs.
- Collaboration & GRC Operations
- Partner with Security Engineering Cloud Infrastructure IAM IT Legal and business teams to validate control implementation.
- Support security awareness policy adoption and governance initiatives.
- Help mature GRC processes and platforms.
- Identify opportunities to automate manual compliance control monitoring and evidence-collection activities.
- Support emerging governance areas including cloud security and AI governance.
What Youll Bring to the Team:
- 57 years of experience in GRC Information Security IT Risk IT Audit Cybersecurity Compliance or related areas.
- Hands-on experience conducting security and technology risk assessments.
- Strong experience supporting internal and/or external audits end to end.
- Working knowledge of at least two major security frameworks such as ISO 27001 SOC 2 NIST CSF/800-53 or PCI-DSS.
- Experience with control mapping control testing evidence collection and remediation tracking.
- Experience maintaining risk registers and managing risk-remediation activities.
- Familiarity with third-party/vendor risk management.
- Understanding of security controls across cloud environments such as AWS Azure or GCP as well as identity and infrastructure.
- Strong documentation communication analytical and stakeholder-management skills.
- Bachelors degree in a related field or equivalent professional experience.
- Preferred Qualifications
- CISA CRISC CISSP ISO 27001 Lead Implementer/Auditor or CompTIA Security certification.
- Hands-on experience with GRC platforms such as ServiceNow GRC/IRM Archer OneTrust Vanta or Drata.
- Experience with cloud compliance and continuous-control-monitoring tools.
- Exposure to compliance automation.
- Awareness of AI governance AI risk management or emerging technology governance.
Key Skills:
Risk Assessment GRC Information Security IT Risk Control Mapping Control Testing Audit Management ISO 27001 SOC 2 NIST PCI-DSS Risk Register Policy Development Vendor Risk Management Cloud Security Compliance Monitoring Remediation Tracking GRC Tools
#LI-RS2
Were a global team of innovators. Together we harness engineering excellence and passion to co-create meaningful solutions to complex challenges. We turn organizations into data-driven leaders that can make a positive impact on their industries and society. If you believe that innovation can bring a better tomorrow closer to today this is the place for you.
Hitachi is a global company operating across a wide range of industries and regions. One of the things that sets Hitachi apart is the diversity of our business and people which drives our innovation and growth.
We are committed to building an inclusive culture based on mutual respect and merit-based systems. We believe that when people feel valued heard and safe to express themselves they do their best work.
We help take care of your today and tomorrow with industry-leading benefits support and services that look after your holistic health and wellbeing. Were also champions of life balance and offer flexible arrangements that work for you (role and location dependent). Were always looking for new ways of working that bring out our best which leads to unexpected ideas. So here youll experience a sense of belonging and discover autonomy freedom and ownership as you work alongside talented people you enjoy sharing knowledge with.
Were proud to say were an equal opportunity employer and welcome all applicants for employment without attention to race colour religion sex sexual orientation gender identity national origin veteran age disability status or any other protected characteristic. Should you need reasonable accommodations during the recruitment process please let us know so that we can do our best to set you up for success.
Required Experience:
Contract
About Company
Discover how Hitachi Rail is connecting the future of mobility through integrated rail solutions, across rolling stock, signalling, digital technology and more.