Summary
The Analyst, IT Risk & Compliance will support their team members in ensuring the IT Controls are working as designed and Compliance is met. The incumbent will manage the IT SOX monitoring activities and respond to any request around control validation and improvements. They are also responsible for providing the assistance to internal and external stakeholders around IT controls and supporting IT audits.
Detailed Description
Performs tasks such as, but not limited to, the following :
- Data Privacy Assessment : Conducting thorough reviews of IT data collection, usage, and sharing practices across the
- organization to identify potential privacy risks.
- Compliance Monitoring : Monitoring adherence to privacy regulations like GDPR, CCPA, HIPAA, etc., by reviewing IT data processing activities and implementing necessary controls.
- Risk Management : Identifying, assessing, and mitigating data privacy risks through proactive measures and incident response planning.
- Vendor Management : Evaluating the IT privacy practices of third-party vendors that handle personal data and ensuring compliance with relevant privacy standards.
- IT Privacy Impact Assessments (PIAs) : Conducting IT PIAs to analyze the privacy implications of new projects, systems, or
- processes before implementation.
- Awareness Training : Providing training to employees on data privacy policies, IT best practices, and handling
- sensitive information responsibly.
Knowledge / Skills / Competencies
Good understanding of data privacy laws and regulations (GDPR, CCPA, HIPAA, etc.)Knowledge of data management practices (HR, Finance & Legal)Analytical skills to identify privacy risks and assess complianceExcellent communication and collaboration skills to work with cross-functional teamsAbility to prioritize tasks and manage complex projectsStrong project planning and project control skillsStrong communication skills, both written and verbalAbility to take initiative to achieve objectives.Ability to work effectively in a team environment.Good negotiation skillsAbility to analyze and understand business requirements and to design solution specifications.Process knowledge and experience with implementing systems changes, maintenance routines and application improvements.Proficient in Delivering Initiatives within the Operating ModelIntermediate level of understanding in Project ManagementIntermediate level of understanding in Architecture and Solution IntegrationProficient in Business PartneringTrains end user trainers, support and maintenance personnel.Proficient in IT SecurityProficient in Risk Mitigation and Business ControlsPhysical Demands
Duties of this position are performed in a normal office environment.Duties may require extended periods of sitting and sustained visual concentration on a computer monitor or on numbers and other detailed data. Repetitive manual movements (e.g., data entry, using a computer mouse, using a calculator, etc.) are frequently required.Typical Experience
1 to 3 Years; Up to 3 years of experience with IT general controls or / and security best practices. Also, recent graduates from University with programs like Computer science or IT security / IT controls. Working towards CISO certification. Available security courses around security and complianceTypical Education
Bachelor's Degree or consideration of an equivalent combination of education and experience.Educational Requirements may vary by GeographySkills Required
Data Privacy, It Architecture, Risk Mitigation