IT Risk and Compliance Analyst

3 dni temu


Warszawa, Mazovia, Polska Greenberg Traurig Pełny etat

Greenberg Traurig (GT), a global law firm with locations across the world in 15 countries, has an exciting employment opportunity for you. We offer competitive compensation and an excellent benefits package, along with the opportunity to work within an innovative and collaborative environment.

Join our Technology departmentas a IT Risk and Compliance Analyst located in our Warsaw Center of Excellence office (remote).

Position Summary:

The IT Risk and Compliance Analyst will take a lead in the ongoing design, development, and management of the firm's third-party risk management program. The position will consist of developing, monitoring, and assessing risks regarding vendor and partner relationships.

Takes lead in the ongoing design, development, and management of the firms' Information Security Program. This position will consist of developing, monitoring, and enforcing information security practices and controls to ensure information and computing assets are kept secure from unauthorized access and inappropriate alteration.

Duties & Responsibilities:

  • Complete vendor risk assessments submitted by clients and prospective clients (RFP).
  • Respond to client Requests for Proposals (RFPs) and questionnaires related to security.
  • Perform information security due diligence on third party vendors to determine the effectiveness of their controls to protect the firm's data, identify any discrepancies and provide recommendations to management.
  • Assesses client needs against security concerns and resolves various risk issues.
  • Develop, implement, assign, and monitor third party vendor assessments.
  • Execute and document assessment activities following established processes and procedures.
  • Perform third party reviews to assess vendor information security posture and practices.
  • Keep abreast of regulatory and compliance related information to enhance the third-party due diligence program.
  • Collaborate with team members to provide subject matter expertise with respect to the Firm's third-party risk management program and to create and update documents and presentations that can be used to inform internal employees, external auditors or internal auditors about the Firm's third-party risk management program.
  • Contribute to the continuous improvement, including automation where possible, of all aspects of the third-party risk management program based on expert knowledge, industry best practices, business objectives and risk tolerance, keeping the program relevant and in alignment with the business objectives.
  • Lead third party risk threat notification to third party vendors by assessing vendor risk, impact and response to third (e.g., assessing Log4Shell vendor impact and response communications)
  • Track vendor mitigation progress of identified threats and risks
  • Develop, implement, monitor KPI, KRI for third party risk management program.
  • Develop and update third party risk management program policies, procedures, and best practices.
  • Actively participate in outside Third-Party Risk Management communities.
  • Work with the security team to develop, manage and maintain the Firm's Information Security Program, security awareness programs, insider threat programs, etc.
  • Identify Information Security & Business Continuity risks to senior management & make recommendations for corrective actions/mitigation of risks.
  • Works assess BCP/DR compliance status of third-party vendors and communicate their status/impact to the firm's BCP/DR team.

Skills & Competencies:

  • Proficiency with standard information gathering tools (e.g., DDQ, SIG, etc.)
  • Working knowledge of security exchanges (e.g. ProcessUnity, OneTrust, UpGuard, CyberGRX, Prevalent, Archer, LogicManager, etc.)
  • Understanding information security (IS) concepts, IT, information security awareness and third-party risk management processes, methodologies, and practices.
  • Experience working with compliance issues dealing with sensitive data preferred.
  • Demonstrate strong customer service skills to ensure a smooth data collection experience for both our customers and our internal business unit partners.
  • Must be available outside normal working hours to participate in emergency events such as security incidents, breaches, investigations, etc.
  • As a specialist on complex technical and business matters, work is highly independent. May assume a team leader role as needed.
  • Demonstrate strong customer service skills to ensure a smooth evidence collection experience for both clients and vendors.
  • Explain and articulate technical concepts to non-technical stakeholders and follow basic troubleshooting steps to work through issues.
  • Strong interpersonal skills, capable of interacting at all levels of the organization from analyst level to C-suite.
  • Demonstrate basic project management and documentation skills to manage multiple parallel work streams.
  • Work well under pressure with tight deadlines to deliver superior service to our clients and stakeholders.
  • Excellent written and verbal communication skills
  • Proficiency with Microsoft Office suite
  • Working knowledge of security exchanges (e.g. ProcessUnity, OneTrust, UpGuard, CyberGRX, Prevalent, Archer, LogicManager, etc.)

Qualifications & Prior Experience:

  • Bachelor's degree in information technology, Information Systems, Information Security, Business Administration, or Risk Management (or equivalent experience) or 3+ years of work experience in relevant information risk position in lieu of degree.
  • 1-3 years of experience in implementing and/or supporting IT risk management processes.
  • 1-3 years of experience in responding to vendor IT risk assessments
  • Experience working with IT audits, findings, and tracking and remediating to resolution.
  • Working knowledge of cloud technologies (any of these, Azure, AWS, Alibaba, GCP, IBM cloud) and software delivery models (SaaS, PaaS, IaaS).
  • Industry certifications preferred (e.g. TPRA, CTPRP, CTPRA, CEH, CISA, CISM) or will obtain
  • Proficiency with Windows-based software and Microsoft Office suite
  • Working knowledge of A.I. fundamentals (e.g. AI-900 certification)
  • Working knowledge of A.I. technologies (Gen AI), CoPilot, ChatGPT, etc.

Other

  • Be a Polish citizen living in Poland or a foreign national living in Poland with the right to work in Poland without a work permit.


  • Warszawa, Mazovia, Polska TMF Group Pełny etat

    General InformationJob ID32250LocationAsker, Norway, Copenhagen, Denmark, Frankfurt, Germany, Helsinki, Finland, Stockholm, Sweden, Warsaw, PolandWork TypesFull TimeCategoriesInternal LegalWe never ask for payment as part of our selection process, and we always contact candidates via our corporate accounts and platforms. If you are approached for payment,...

  • Risk Analyst

    2 tygodni temu


    Warszawa, Mazovia, Polska capital Pełny etat 60 000 zł - 120 000 zł rocznie

    We are a leading trading platform that is ambitiously expanding to the four corners of the globe. Our top-rated products have won prestigious industry awards for their cutting-edge technology and seamless client experience. We deliver only the best, so we are always in search of the best people to join our ever-growing talented team.We are a leading trading...

  • Risk & Compliance Lead

    1 tydzień temu


    Warszawa, Mazovia, Polska ICON plc Pełny etat 60 000 zł - 120 000 zł rocznie

    Risk & Compliance LeadICON plc is a world-leading healthcare intelligence and clinical research organization. We're proud to foster an inclusive environment driving innovation and excellence, and we welcome you to join us on our mission to shape the future of clinical developmentWe are currently seeking a Risk & Compliance Lead to join our diverse and...

  • Operational Risk Analyst

    1 tydzień temu


    Warszawa, Mazovia, Polska CMC Markets Pełny etat 40 000 € - 80 000 € rocznie

    ROLE AND RESPONSIBILITIESThe main role and responsibilities of the Operational Risk Analyst will be to assist the Head of Operational Risk and the Operational Risk Function to implement and embed CMC Markets' Operational Risk Management policy, framework, systems and processes across the organisation.  The Operational Risk Analyst will play a pivotal role...

  • Operational Risk Analyst

    2 tygodni temu


    Warszawa, Mazovia, Polska CMC Markets Pełny etat 60 000 € - 100 000 € rocznie

    The main role and responsibilities of the Operational Risk Analyst will be to assist the Head of Operational Risk and the Operational Risk Function to implement and embed CMC Markets' Operational Risk Management policy, framework, systems and processes across the organisation.The Operational Risk Analyst will play a pivotal role within the function by...

  • Operational Risk Analyst

    1 tydzień temu


    Warszawa, Mazovia, Polska CMC Markets Pełny etat 45 000 zł - 75 000 zł rocznie

    ROLE AND RESPONSIBILITIESThe main role and responsibilities of the Operational Risk Analyst will be to assist the Head of Operational Risk and the Operational Risk Function to implement and embed CMC Markets' Operational Risk Management policy, framework, systems and processes across the organisation.  The Operational Risk Analyst will play a pivotal role...

  • ICT Risk Analyst

    2 tygodni temu


    Warszawa, Mazovia, Polska Colibrix One Pełny etat 40 000 zł - 80 000 zł rocznie

    Join Colibrix One – Innovating the Future of PaymentsAt Colibrix One*, we're building advanced, AI-powered payment technologies that support Payment Service Providers (PSPs), Electronic Money Institutions (EMIs), and neobanks across the EU and the UK. As a fully licensed EMI (FCA reference number and a Principal Member of Mastercard, we offer real-world...


  • Warszawa, Mazovia, Polska Risk Pełny etat

    Company DescriptionAt RISK, we are the mavericks of the gaming and wagering industry, where taking bold chances is our core philosophy. In an arena where digital entertainment and betting merge, we're the trailblazers venturing into the unexplored.Our mission is to forge ahead with pioneering solutions that challenge the status quo. Our vision? To outpace...


  • Warszawa, Mazovia, Polska RISK Pełny etat

    Company Description At RISK, we are the mavericks of the gaming and wagering industry, where taking bold chances is our core philosophy. In an arena where digital entertainment and betting merge, we're the trailblazers venturing into the unexplored.Our mission is to forge ahead with pioneering solutions that challenge the status quo. Our vision? To outpace...

  • Risk Analyst

    2 tygodni temu


    Warszawa, Mazovia, Polska Sii Poland Pełny etat 40 000 zł - 60 000 zł rocznie

    Are you passionate about numbers, analysis, and understanding how financial risks shape investment decisions? We are looking for a Risk Analyst to join our risk management team. This is a great opportunity to gain experience in monitoring market, credit, and operational risks while learning from experienced professionals in the asset management industry.If...