OneTrust is seeking a Information Security GRC Analyst to support Information Security by performing governance, risk, and compliance activities. The role is within the OneTrust InfoSec GRC team.
Responsibilities:
- Conduct risk assessments to identify vulnerabilities and threats.
- Use the OneTrust platform to monitor, track, document and analyze risks.
- Serve as the technical Subject Matter Expert on the OneTrust ITSRM product.
- Prepare security findings reports and recommendations.
- Collaborate with Information Security to establish reporting process for risks and exceptions
- Perform security audits to ensure compliance.
- Assist in creating and maintaining security policies.
- Support customer audits and the overall ERM function.
Requirements:
- Deep understanding information security frameworks, risks and mitigation strategies
- Deep understanding of the technical aspects surrounding risks to the organization
- Understanding of applicable laws and regulations (GDPR, CCPA, PCI-DSS, SOC 2, ISO, FedRAMP)
- Working knowledge of security risk management and methodologies
- Understanding of sensitive data types and classifications
- Understanding of technology domains
- Bachelor’s degree or 5-8 years equivalent experience
OneTrust offers:
- Comprehensive healthcare coverage
- Flexible PTO
- Equity stock options
- Annual performance bonus opportunities
- Retirement account support
- Paid parental leave
- Career development opportunities
- Company-paid privacy certification exam fees
Apply
OneTrust
OneTrust is a company focused on enabling organizations to use data and AI responsibly. Its platform streamlines data collection with consent and preferences, automates governance with integrated risk management across various domains, and activates the responsible use of data by enforcing policies throughout its lifecycle. Serving over 14,000 customers globally and holding over 300 patents, OneTrust facilitates collaboration between data and risk teams to drive trusted innovation across industries.