Hiring.Camp

Governance, Risk and Compliance Analyst III

Uwcu

·

Yesterday

Salary
$127k+
Location
Madison, WI, US
Type
Full-time
Department
IT
Experience
6+ years
Closing date
Today
Source
iCIMS

Description

Overview

The Information Security Governance Risk and Compliance (GRC) Analyst is responsible for ensuring the confidentiality, integrity, and availability of University of Wisconsin Credit Union (UWCU) information by working with a team of GRC analysts who continually assess UWCU's information security posture. This role regularly reviews information security policies, standards, and procedures to ensure UWCU is aligned with industry best practices including applicable laws and regulations. Additionally, this role conducts third-party risk evaluations and assessments to minimize cybersecurity risk exposure and impacts on the business. The individual in this role supports legal, audit, accounting and loss prevention departments in assessing compliance and works to develop, implement, and maintain a comprehensive information security compliance program that encompasses all aspects of the organization’s information management life cycle. By safeguarding UWCU’s information, you will have the opportunity to make a positive impact on our organization and our members.

Responsibilities

Compliance

  • Recommend procedures to ensure compliance with relevant laws, regulations, and industry standards.
  • Ensure technical controls are effective by coordinating reviews with technical engineers and analysts.
  • Continually research and stay up to date on emerging compliance issues.
  • Coordinate with stakeholders to ensure policies and standards are communicated effectively, supporting training and awareness initiatives.
  • Support audits to assess the effectiveness of security controls and identify compliance gaps, in accordance with legal and regulatory requirements.
  • Work with regulatory examiners and auditors as necessary.
  • Maintain documentation for internal audits, external audits, and independent third-party assessments.
  • Train and educate employees on cybersecurity compliance requirements.

 

Governance

  • Ensure ethics, transparency and accountability in the practice of information security governance.
  • Support the policy and standard lifecycle, including creation, review, revision, approval, communication, and retirement.
  • Develop and implement robust information security policies and standards that align with industry best practices, security frameworks, and regulatory requirements.
  • Conduct policy and standard reviews, ensuring to address emerging threats or changes in the regulatory landscape.
  • Coordinate review of policies and procedures with technology engineers ensuring practicality for implementation.
  • Identify and resolve conflicting policies.
  • Facilitate Information Security Steering Committee (ISSC) meetings, providing insight into the implementation and effectiveness of information security governance.
  • Integrate security measures into business processes to ensure that security is considered in all organizational activities.
  • Collaborate with cross-functional teams to address security issues and implement corrective measures.

 

Risk

  • Support the Information Security Risk Management Program, planning and coordinating the execution of risk assessments, monitoring emerging risks, and maintaining the risk register.
  • Conduct and coordinate regular risk assessments to identify vulnerabilities and potential threats.
  • Implement risk mitigation strategies and controls to manage identified risks effectively.
  • Support the identification and ranking of third-party cybersecurity risks and impacts.
  • Implement communication and escalation plans for third-party cybersecurity risk management activities within the enterprise.
  • Evaluate third-party cybersecurity risks as defined in contracts and in accordance with existing risk management programs and policies.
  • Develop, monitor, and execute third-party remediation actions, mitigation, and contingency plans when cybersecurity risks or events are identified.
  • Evaluate external party compliance with regulatory requirements.
  • Support the security onboarding process for new vendors.
  • Gather third-party cybersecurity risk assessment data and prepare assessments for critical third parties, to be published and communicated to stakeholders.
  • Track identified cybersecurity risks and events.
  • Support communication plans to report identified cybersecurity risk requirements and violations to internal stakeholders, end users, and responsible third parties, supporting the response and resolution of these issues.
  • Guide third parties and business partnears to ensure compliance with cybersecurity risk management policies.
  • Support a monitoring system for third-party cybersecurity risk management.
  • Review Enterprise Risk Management products, to ensure enterprise risks are evaluated for information security impacts.

 

Security Planning and Training

  • Foster a culture of security awareness within the organization.
  • Support the implementation of the Security and Awareness Training Program, including New Employee Orientation, New Leader Onboarding, and additional programs as needed to implement information security best practices and policies.
  • Evaluate the success of the program, recommending necessary changes to address deficiencies.
  • Assess the effectiveness of policies, standards, and procedures during exercises and testing.

 

Qualifications

Education & Experience:

  • Bachelor’s Degree Computer science or similar technology related field, or equivalent relevant work experience required (Master’s Degree preferred).
  • 6-7 years of experience in one or more of the following roles required:  NCUA or Financial Auditing Chief Compliance Officer, Cybersecurity GRC Manager, Cybersecurity Compliance and Risk Manager, GRC Manager, Data Protection Officer, IT Security Officer, Information Security Auditor, GRC Analyst, Information Security Analyst, or Cybersecurity Analyst.
  • CISSP, CRISC, CISA, CGEITR or equivalent. Technical certifications such as GSEC Sec+, or equivalent preferred.

 

Skills:

  • Deep understanding of security controls and alignment to key regulations.
  • Strong knowledge of IT hardware, software, environmental controls, networks, resiliency, virtualization and cloud computing.
  • Experience with risk assessment and security audits.
  • Solid understanding of security frameworks such as CIS Critical Controls, NIST, and COBIT. Effective communication within the team and across the department.
  • Excellent verbal and written communication skills, with the ability to adjust messages to the correct technical level of the target audience.
  • Understanding of organizational mission, values, and goals, and consistent application of this knowledge.
  • Strong problem-solving and troubleshooting skills.
  • Talent and passion for technology; creativity and resourcefulness in solving problems.

Working at UW Credit Union

Why work for UW Credit Union?

 

Join one of Wisconsin’s premier financial institutions, a National Top Workplace and multi-year recipient of Madison Magazine’s Best Places to Work, Wisconsin State Journal’s Top Workplaces, and Milwaukee Journal Sentinel’s Top Workplaces to receive:

 

  • 21.5 days of annual time off (accrued per pay period)
  • 2 weeks paid caregiver leave
  • 2.5 weeks paid new child parental leave
  • 2 days paid volunteer time
  • 10 paid holidays (including your birthday!)
  • 401k company match of up to 5%, plus approximately 4% discretionary match
  • Variable bonus reward
  • Competitive Medical, Dental, and Vision plans, including domestic partner eligibility
  • Employee Assistance Program
  • And more!

 

All employees must possess valid work authorization to work for UWCU on the date of hire.  UWCU does not provide immigration sponsorship or support for employment authorization to include, but not limited to, sponsorship or support for H-1B, F-1 OPT, TN, or other visa category. 

Skills

CybersecurityRisk ManagementComplianceLoss PreventionCISSP

Similar Jobs

30

Manager - Governance, Risk and Compliance

Scyne Advisory·Melbourne, Victoria·Hybrid

Today

Specialist I, Governance, Risk and Compliance

Cnx·PHL Quezon City - EXXA Tower, 8th Floor

2d ago

Operational Risk Governance and Transformation Analyst

Truist·Charlotte NC - 214 North Tryon Street, US +1·Remote, Onsite

2d ago

Chief Corporate Services Office; Risk and Governance Initiatives, AVP

Mufgub·Watermark - 410 North Scottsdale Road, US

2d ago

Governance, Risk, and Compliance (GRC) Specialist

Logicalis·Mapletree Business City, SG

2d ago

Sr Manager, Governance, Risk and Compliance

Lennar·Irving TX, US

3d ago

Model Risk Governance and Review Associate for Corporate Aligned - Model Risk Program Associate

JPMorgan Chase·Jersey City, NJ

3d ago

Model Risk Governance and Review Associate for Corporate Aligned - Model Risk Program Associate

JP Morgan Chase·Jersey City, NJ

3d ago

Cybersecurity Governance, Risk and Compliance

Vitol·London, England

3d ago

Risk & Prevention Singapore, AVP - Risk Governance and Conduct

Ocbc·SGP-Head Office, Singapore

4d ago

Director, IT Governance, Risk and Compliance

Prologis·Denver Office, US

4d ago

Governance Risk and Compliance I Analyst II

Vertiv·Mandaluyong City, Philippines

1w ago

Governance, Risk, and Compliance Certifications Engineer

Nvidia·Remote, WA·Remote

1w ago

Governance, Risk, and Compliance Certifications Engineer

Nvidia·WA, US·Remote

1w ago

Governance, Risk, and Compliance (GRC) Data Analyst | Technology Services

Denver means seeing yourself working·Webb Building Floor 03, US·Hybrid, Onsite

1w ago

Information Security Risk and Governance Specialist, Consultant

Blue Shield of California·Oakland, CA

1w ago

FY 27 - Intern - Assurance - GRC (Governance, Risk, and Compliance) Centralized team

Pwc·Jakarta - Gd. WTC 3, Indonesia

1w ago

Security Associate Manager – Governance, Risk and Compliance - Internal Corporate Function

BIP·Milano, Lombardia

1w ago

Director Governance Risk and Compliance

surescripts·US

1w ago

Information Security Governance, Risk and Compliance Analyst II

Saintlukes·System Offices, MO·Remote

1w ago

Supply Chain Governance, Risk and Compliance Analyst, Supply Chain Management Unit, P-2 Copenhagen (209433)

United Nations Development Programme (UNDP)·Copenhagen, DK

1w ago

Governance, Risk and Compliance Specialist, Supply Chain Management Unit, P-4, Copenhagen (209474)

United Nations Development Programme (UNDP)·Copenhagen, DK

1w ago

Head of IT Governance, Risk, and Compliance (GRC)

"LabConnect, LLC"·Remote - US, 2304 Silverdale Drive·Remote

1w ago

Enterprise Governance Risk and Compliance Analyst

RBFCU Randolph·ASC - San Antonio, US

2w ago

Governance, Risk, and Compliance Analyst

Pike Engineering·SC, US

2w ago

Governance, Risk, and Compliance Senior Associate or Supervisor (IT)

Weaver·DALLAS, TX +3

2w ago

Lead Analyst, Information Security (Risk and Governance)

Rxo·USNC-Charlot15, US·Onsite

2w ago

Senior Manager in Governance Risk and Compliance

Prometeia·Milano - Brera, Italy +3

2w ago

Governance, Risk and Compliance Analyst

Mission Australia·Sydney Office, Australia

2w ago

Enterprise Risk Management (ERM) - Policy and Governance Risk Analyst V

Keybank·127 Public Square, OH

2w ago
Governance, Risk and Compliance Analyst III at Uwcu • $127k+ | Hiring.Camp