IT Risk and Compliance Analyst
2 dni temu
Greenberg Traurig (GT), a global law firm with locations across the world in 15 countries, has an exciting employment opportunity for you. We offer competitive compensation and an excellent benefits package, along with the opportunity to work within an innovative and collaborative environment.
Join our Technology department as a IT Risk and Compliance Analyst located in our Warsaw Center of Excellence office (remote).
Position Summary:
The IT Risk and Compliance Analyst will take a lead in the ongoing design, development, and management of the firm's third-party risk management program. The position will consist of developing, monitoring, and assessing risks regarding vendor and partner relationships.
Takes lead in the ongoing design, development, and management of the firms' Information Security Program. This position will consist of developing, monitoring, and enforcing information security practices and controls to ensure information and computing assets are kept secure from unauthorized access and inappropriate alteration.
Duties & Responsibilities:
Complete vendor risk assessments submitted by clients and prospective clients (RFP).
Respond to client Requests for Proposals (RFPs) and questionnaires related to security.
Perform information security due diligence on third party vendors to determine the effectiveness of their controls to protect the firm's data, identify any discrepancies and provide recommendations to management.
Assesses client needs against security concerns and resolves various risk issues.
Develop, implement, assign, and monitor third party vendor assessments.
Execute and document assessment activities following established processes and procedures.
Perform third party reviews to assess vendor information security posture and practices.
Keep abreast of regulatory and compliance related information to enhance the third-party due diligence program.
Collaborate with team members to provide subject matter expertise with respect to the Firm's third-party risk management program and to create and update documents and presentations that can be used to inform internal employees, external auditors or internal auditors about the Firm's third-party risk management program.
Contribute to the continuous improvement, including automation where possible, of all aspects of the third-party risk management program based on expert knowledge, industry best practices, business objectives and risk tolerance, keeping the program relevant and in alignment with the business objectives.
Lead third party risk threat notification to third party vendors by assessing vendor risk, impact and response to third (e.g., assessing Log4Shell vendor impact and response communications)
Track vendor mitigation progress of identified threats and risks
Develop, implement, monitor KPI, KRI for third party risk management program.
Develop and update third party risk management program policies, procedures, and best practices.
Actively participate in outside Third-Party Risk Management communities.
Work with the security team to develop, manage and maintain the Firm's Information Security Program, security awareness programs, insider threat programs, etc.
Identify Information Security & Business Continuity risks to senior management & make recommendations for corrective actions/mitigation of risks.
Works assess BCP/DR compliance status of third-party vendors and communicate their status/impact to the firm's BCP/DR team.
Skills & Competencies:
Proficiency with standard information gathering tools (e.g., DDQ, SIG, etc.)
Working knowledge of security exchanges (e.g. ProcessUnity, OneTrust, UpGuard, CyberGRX, Prevalent, Archer, LogicManager, etc.)
Understanding information security (IS) concepts, IT, information security awareness and third-party risk management processes, methodologies, and practices.
Experience working with compliance issues dealing with sensitive data preferred.
Demonstrate strong customer service skills to ensure a smooth data collection experience for both our customers and our internal business unit partners.
Must be available outside normal working hours to participate in emergency events such as security incidents, breaches, investigations, etc.
As a specialist on complex technical and business matters, work is highly independent. May assume a team leader role as needed.
Demonstrate strong customer service skills to ensure a smooth evidence collection experience for both clients and vendors.
Explain and articulate technical concepts to non-technical stakeholders and follow basic troubleshooting steps to work through issues.
Strong interpersonal skills, capable of interacting at all levels of the organization from analyst level to C-suite.
Demonstrate basic project management and documentation skills to manage multiple parallel work streams.
Work well under pressure with tight deadlines to deliver superior service to our clients and stakeholders.
Excellent written and verbal communication skills
Proficiency with Microsoft Office suite
Working knowledge of security exchanges (e.g. ProcessUnity, OneTrust, UpGuard, CyberGRX, Prevalent, Archer, LogicManager, etc.)
Qualifications & Prior Experience:
Bachelor's degree in information technology, Information Systems, Information Security, Business Administration, or Risk Management (or equivalent experience) or 3+ years of work experience in relevant information risk position in lieu of degree.
1-3 years of experience in implementing and/or supporting IT risk management processes.
1-3 years of experience in responding to vendor IT risk assessments
Experience working with IT audits, findings, and tracking and remediating to resolution.
Working knowledge of cloud technologies (any of these, Azure, AWS, Alibaba, GCP, IBM cloud) and software delivery models (SaaS, PaaS, IaaS).
Industry certifications preferred (e.g. TPRA, CTPRP, CTPRA, CEH, CISA, CISM) or will obtain
Proficiency with Windows-based software and Microsoft Office suite
Working knowledge of A.I. fundamentals (e.g. AI-900 certification)
Working knowledge of A.I. technologies (Gen AI), CoPilot, ChatGPT, etc.
Other
Be a Polish citizen living in Poland or a foreign national living in Poland with the right to work in Poland without a work permit.
-
IT Third Party Risk and Compliance Analyst
4 tygodni temu
Warsaw, Polska GT SERVICES sp. z o.o. Pełny etatIT Third Party Risk and Compliance Analyst Miejsce pracy: Warszawa Technologies we use Expected Information Security Standards About the project The IT Third Party Risk and Compliance Analyst will lead the design, development, and management of the firms' IT third party risk management program. The position will consist of gathering, analyzing, and...
-
Senior IT Compliance and Risk Officer
3 dni temu
Warsaw, Polska SIX Pełny etatAre you passionate about finance and modern technology? Do you have good organizational skills? Do you enjoy working together to achieve common objectives on time? If yes, this is the right place for you. You will be acting as the PCI DSS officer for SIX and as such, lead and coordinate internal and external activities to ensure compliance with the PCI DSS...
-
Cloud Email Security Analyst
6 dni temu
Warsaw Center of Excellence, Polska Greenberg Traurig Pełny etat 40 000 zł - 60 000 zł rocznieGreenberg Traurig (GT), a global law firm with locations across the world in 15 countries, has an exciting employment opportunity for you. We offer competitive compensation and an excellent benefits package, along with the opportunity to work within an innovative and collaborative environment. Join our Technology Team as a Cloud Email Security Analyst...
-
Risk Analyst
1 tydzień temu
London, England, United Kingdom / Warsaw, Mazowieckie, Poland capital Pełny etat 40 000 zł - 60 000 zł rocznieWe are a leading trading platform that is ambitiously expanding to the four corners of the globe. Our top-rated products have won prestigious industry awards for their cutting-edge technology and seamless client experience. We deliver only the best, so we are always in search of the best people to join our ever-growing talented team. We are a leading...
-
Senior Project Manager
1 dzień temu
Warsaw, Polska ERGO Technology & Services S.A. Pełny etatSenior Project Manager (IT Regulatory, Risk, Compliance and Security) Miejsce pracy: Warszawa Your responsibilities • leading the end-to-end delivery of global cybersecurity initiatives across heterogeneous, multi-vendor environments with a high degree of customization and complexity • driving the development of project charters that clearly define...
-
Technical Project Manager
1 tydzień temu
Warsaw, Polska ERGO Technology & Services S.A. Pełny etatTechnical Project Manager (IT Regulatory, Risk, Compliance, and Security) Miejsce pracy: Warszawa Your responsibilities • leading the end-to-end delivery of global cybersecurity initiatives across heterogeneous, multi-vendor environments with a high degree of customization and complexity • driving the development of project charters that clearly define...
-
Senior IT Risk and Control Officer
5 dni temu
Warsaw, Polska SIX Pełny etatAre you passionate about finance and modern technology? Do you have good organizational skills? If yes, this is the right place for you. You coordinate the IT Risk and controls out of a central team distributed between Switzerland, Spain and Poland, to ensure appropriate risk methodology and assessment and in-time remediation of deficiencies. You also help...
-
Senior Data Analyst Risk Management
3 dni temu
Warsaw, Polska Allegro Pełny etatThis is a critical and foundational role in launching and managing our new lending product for merchants. You will be essential in driving key business objectives: optimizing credit risk management , onboarding, building BI tools and minimizing the cost of risk. You will be responsible for building the core credit infrastructure from the ground up and...
-
System Analyst
3 dni temu
Warsaw, Polska Madiff Sp. z o.o. Pełny etatAt Madiff, we connect top IT talent with cutting-edge companies through remote Agile teams and nearshore outsourcing. With operations in Poland, Portugal, France, and the UK, we specialize in AI, DevOps, and Cybersecurity – supporting industries like Telecom, Banking, and Hi-Tech. Are you a passionate system analyst ready to contribute to the...
-
IT Systems Analyst
1 tydzień temu
Warsaw, Polska Lindt & Sprüngli Sp. z o.o. Pełny etatJoin Lindt & Sprüngli team and support a premium chocolate, global brand. We are looking for an experienced: IT Systems Analyst About the Role: We are looking for a D2C Systems Support Specialist to ensure stable data flow and smooth integration across our key Direct-to-Consumer systems (SAP, middleware, Salsify, Magento, Baselinker). You will support...