- Location
- Manila, NCR,PH, PH · Asturias, Central Visayas,PH, PH
- Type
- Full-time
- Department
- IT
- Experience
- 5+ years
- Education
- PhD
- Source
- Eightfold
Description
Meet the team:
The Governance, Risk & Compliance (GRC) team partners with business, technology, privacy, legal, and security stakeholders to strengthen the organization's cybersecurity and compliance posture. We help identify and manage cyber risk, support regulatory and industry compliance programs, drive audit readiness, and promote a culture of security across the enterprise.
Dexcom is seeking a Senior Cybersecurity Analyst to join the GRC Information Security team and support information security compliance, certification, audit, and risk management activities. The Senior Cybersecurity Analyst will coordinate with control owners, business stakeholders, auditors, and cybersecurity teams to prepare for audits, track findings, support risk treatment plans, and improve the consistency and effectiveness of GRC processes. This position will also contribute to security control assessment, testing, documentation, metrics, and continuous improvement efforts. And this role will manage and optimize the OneTrust GRC platform to support risk assessments, compliance workflows, evidence collection, control gap tracking, remediation activities, and reporting.
Where you come in:
- You will coordinate audit readiness, evidence collection, control owner preparation, audit workflow tracking, findings management, and remediation follow-up for internal and external audits.
- You will support security certification, compliance, and assessment activities by partnering with control owners, cybersecurity teams, business stakeholders, and auditors.
- You will conduct and support risk assessments using defined risk criteria, scoring methodologies, risk tolerance levels, and treatment tracking processes.
- You will track control gaps, audit findings, risks, remediation plans, and risk treatment activities through closure.
- You will support mapping of applicable regulatory, framework, and internal policy requirements to controls, assessments, evidence requests, and reporting within the GRC platform.
- You will perform control mapping, gap analysis, and compliance assessments against applicable frameworks, standards, regulations, and internal policy requirements.
- You will support control testing, evidence collection, and continuous monitoring activities to assess control effectiveness and identify remediation needs.
- You will generate and maintain reports, dashboards, metrics, and status updates that communicate audit status, remediation progress, control health, risk trends, and compliance indicators.
- You will validate GRC data quality and work with stakeholders to improve completeness, accuracy, and consistency of records, assessments, evidence, and reporting.
- You will configure, maintain, and support the OneTrust GRC platform to enable security risk assessments, compliance, audit, remediation, and reporting workflows.
- You will manage user access, permissions, templates, workflows, assessments, and reporting configurations in alignment with defined GRC and cybersecurity requirements.
- You will evaluate OneTrust features, releases, and configuration options and recommend practical improvements to usability, workflow efficiency, reporting, and stakeholder experience.
- You will identify opportunities to improve GRC processes, workflows, templates, documentation, reporting, and automation.
- You will support stakeholder enablement by developing guidance, job aids, and communications for OneTrust users, control owners, and GRC stakeholders.
- You will monitor changes in regulations, industry standards, and best practices and help translate applicable changes into GRC processes, assessments, and reporting.
What makes you successful:
- You possess a bachelor’s degree in information security, Information Systems, Computer Science, Business, or a related field, or equivalent practical experience.
- You bring 5+ years of experience in cybersecurity, information security, IT risk management, compliance, audit, or a related information technology function, or an equivalent combination of education and experience.
- Your experience configuring, administering, or supporting a GRC platform such as OneTrust, Archer, ServiceNow GRC, AuditBoard, LogicGate, or a similar tool.
- Your working knowledge of cybersecurity, risk, and compliance frameworks such as ISO 27001, NIST CSF, NIST 800-53, PCI DSS, SOC 2, HIPAA, or similar standards.
- Your experience supporting audit readiness, evidence collection, control testing, compliance assessments, issue tracking, and remediation activities.
- Your ability to support risk assessments, control gap analysis, risk treatment plans, and remediation tracking across business and technology stakeholders.
- Your ability to effectively work in cross-functional teams and collaborate with stakeholders from various departments.
- Your strong analytical skills, including the ability to analyze GRC data, identify trends, validate data quality, and develop useful metrics or reports.
- Your ability to plan, organize, and execute work related to GRC services.
- Your strong written and verbal communication skills, with the ability to translate cybersecurity risk, compliance, and audit concepts into clear business language.
- Your ability to partner with control owners, business stakeholders, auditors, and cybersecurity teams to resolve issues and drive audit, risk, and compliance activities to completion.
Nice to have qualifications
- OneTrust GRC experience or certification.
- Experience supporting cybersecurity, privacy, audit, or compliance activities in a regulated environment, such as medical device, healthcare, life sciences, financial services, or technology.
- Professional certification such as CISSP, CISA, CISM, CRISC, Security+, ISO 27001 Lead Implementer, or ISO 27001 Lead Auditor.
- Experience developing GRC dashboards, metrics, workflow automation, or reporting processes.
What you’ll get:
- A front row seat to life changing CGM technology. Learn about our brave #dexcomwarriors community.
- A full and comprehensive benefits program.
- Growth opportunities on a global scale.
- Access to career development through in-house learning programs and/or qualified tuition reimbursement.
- An exciting and innovative, industry-leading organization committed to our employees, customers, and the communities we serve.
Travel Required:
- 0-5%
Experience and Education Requirements:
- Typically requires a Bachelor’s degree in a technical discipline, and a minimum of 5-8 years related experience or Master’s degree and 2-5 years equivalent industry experience or a PhD and 0-2 years experience.
#LI-Hybrid