Information Security Sr Anlyst
Job Summary
Object Technology Solutions Inc (OTSI) has an immediate opening for a Sr. Information Security Analyst - GRC
Sr. Information Security Analyst GRC (Cary NC- Onsite)
Other Location: Overland Park KS - Onsite
MAJOR RESPONSIBILITES:
Contract Risk Management
Proven experience reviewing client contract provisions related to data security breach reporting cyber resilience and compliance certifications and measuring compliance in IT and security architecture and operations.
Regulatory Compliance Risk Management
Support independent certification and audit by working with D&IT peer groups and lines of business to collect documentation and evidence of security policies and operations
Request and review documentation and evidence from control owners to certify and validate compliance to standards and industry-accepted best practice
Monitor regulatory and legal landscape at a global scale and across market sectors and maintain awareness of compliance requirements
IT Governance
Act as an informed voice in development of policy and ensure alignment with regulatory legal and contractual requirements
Assist establishment and enforcement of standards of practice documentation to be referenced by architecture and operations teams
Contribute process and subject matter expertise in governance forums and cross-functional committees
Cyber Risk Management
Support establishment collection and ongoing improvement of metrics to measure effectiveness of cyber risk management and provide data-driven insight to decision makers and control owners
Collaborate with peer D&IT groups to collect KPIs KRIs and drive efficiency through automation and other means
Supplier/Third Party Risk Management
Contribute subject matter expertise through third party risk assessment process
Identify and communicate risk of vendor engagements and mitigation actions to business owners and D&IT stakeholders
Assist review of client security requirements in contracts and aggregate relevant clauses to inform contractual risk
Miscellaneous:
Assist development of user training aligned with cyber threat landscape establish and implement metrics and propose enhancements
Support internal audit
Assist with security certification/attestations/audits to demonstrate control effectiveness to independent service auditors/assessors and C3PAOs
Assist in development of risk treatment plans and monitoring progress of actions.
Collaborate with members of the GRC team to ensure timely and quality deliverables to internal and external customers
Contribute subject matter expertise in review and response to internal and external sourced GRC related requests
SKILLS AND ABILITIES REQUIRED:
Bachelors degree in information systems Information Security or a related field
710 years of experience in GRC executing or auditing against standards frameworks and industry regulations
Demonstrated experience supporting GRC functions for global companies
Solid proficiency in risk assessment methodologies and frameworks
Proven ability to assess alignment of internal policy process control design and operations and cyber risk management with regulatory standards and frameworks
Strong collaboration with IT teams
Familiarity with industry standards and frameworks (e.g. NIST CSF and supporting SPs ISO 27001 AICPA SOC)
Working knowledge of cyber and privacy laws and regulations
Solid understanding of information security principles and concepts
Strong desire to create task and functional efficiencies through use of technology and tools especially GenAI
Preferred Qualifications
Strong analytical organizational and communication skills
Professional certifications such as CRISC CISSP or others
Experience with ServiceNow Risk Management platform
Knowledge of FAR DFARS CMMC
Experience with GRC platforms and risk management methodologies
Ability to work independently and collaboratively as required
Competencies
Attention to detail and critical thinking
Ethical judgment and integrity
Ability to manage multiple tasks and deadlines
Strong interpersonal and stakeholder engagement skills
About us
About us:
OTSI is a global technology partner providing enterprise IT consulting digital solutions and managed services. We help organizations modernize complex technology landscapes harness the power of data and build scalable AI-led ecosystems to accelerate innovation and business growth. With over 26 years of experience we consistently turn complex challenges into success stories through our strong technical capabilities and deep industry knowledge. Our global team of 1800 professionals spread across 6 countries delivers cutting-edge solutions for customers across Banking Financial Services Insurance Transportation & Logistics Energy & Utilities Healthcare & Life Sciences Government Hi-Tech Telecom & Media Manufacturing and more.
Our focused technology areas:
AI/ML (Agentic AI Solutions GenAI/LLMs Natural Language Processing Intelligent Processing Physical Intelligence)
Data & Analytics (Data Architecture Data Engineering Data Migration Data Modernization Big Data Analytics and BI)
Cloud (Cloud Computing Cloud Migration Cloud-Native Architecture Hybrid and Multi-Cloud)
Digital Engineering (Application Modernization Product Engineering Platform Engineering DevSecOps)
Quality Engineering (Manual Testing Nonfunctional testing Test Automation Digital Testing)
Enterprise Platforms (SAP Microsoft Oracle etc.)
Our focused industries and target segments:
Banking Financial Services & Insurance
Manufacturing Transportation & Logistics
Energy & Utilities
Telecom & Media
Healthcare & Lifesciences
Government & Public Sector (FED SLED & Partners)
Hi-Tech
Required Skills:
GRC NIST CSF CISSP