Role OverviewThe Analyst will serve in an Asset Based Testing role that will help plan, scope, execute, and report testing of IT and Information Security controls. The Analyst will be responsible for all phases of the assessment and communications with business partners and other stakeholders. They will work in an Agile environment.
What You Will Do
Planning and scoping of Asset Based Assessments, including development of communications, risk and control matrices, scope documents, and other supporting information. Perform walk-throughs with business partners to identify actual versus expected controls. Create test strategies to test actual controls.
Why It Might Be a Fit
Experience in control testing, including experience in one or more of the three lines of defense (Audit, ERM, First Line areas). Knowledge of applicable federal and state laws, rules, and regulations, including FFIEC, NIST, and ISO.
Requirements
- Experience in control testing, including experience in one or more of the three lines of defense (Audit, ERM, First Line areas)
- Experience in audit and information security risk assessments
- Knowledge of applicable federal and state laws, rules, and regulations, including FFIEC, NIST, and ISO
- Knowledge of NCUA, FFIEC, GLBA, NIST (including the Cybersecurity Framework and 800 Series), ISO 27001/27002, SANS/CIS 20, PCI DSS, and other information security requirements and frameworks
- CISSP, CISA, CCSP, CRISC, or other Information Security certification
- Ability to present findings and conclusions clearly and concisely
- Ability to build effective relationships through rapport, trust, diplomacy, and tact
- Strong word processing and spreadsheet software skills
Benefits
- Comprehensive Medical, Dental, and Vision Insurance
- Employer-Paid Life Insurance
- Employer-Paid Short-Term and Long-Term Disability Insurance
- 401(k)
- Paid Time Off (PTO) that includes Vacation Leave, Sick Leave, and 11 Paid Holidays
- Educational Assistance
]]>