Job added in hotlist
Applied job
Contract job
90-day-old-job
part-time-job
Recruiter job
Employer job
Expanded search
Apply online not available
View more jobs in Atlanta, GA
View more jobs in Georgia

Job Details

IT Third Party Risk and Compliance Analyst

Company name
Greenberg Traurig, L.L.P

Location
Atlanta, GA, United States

Employment Type
Full-Time

Industry
Compliance, It

Posted on
Aug 25, 2022

Apply for this job






Profile

Description

Greenberg Traurig (GT), a global law firm, has an exciting full-time employment opportunity for an IT Third Party and Compliance Analyst in the Technology Department of various office locations. We offer competitive compensation and an excellent benefits package.

Position Summary:

The IT Third Party Risk and Compliance Analyst will lead the design, development, and management of the firms’ IT third party risk management program. The position will consist of gathering, analyzing, and interpreting security control evidence from third parties. Candidate should be available outside normal working hours to participate in emergency events such as security incidents, breaches, investigations, etc.

Duties & Responsibilities:

Uses SIG questionnaire, performs due diligence on third party vendors to determine the effectiveness of their controls to protect the firm’s data, identifies any discrepancies and provides recommendations to management

Develops, implements, assigns, and monitors third party vendor assessments

Monitors third party vendor security posture using third party services (e.g., security scorecard, BitSight, risk recon, etc.)

Executes and documents assessment activities following established processes and procedures

Improves existing SIG questionnaire review/response process

Keeps abreast of regulatory and compliance related information to enhance the third-party due diligence program

Collaborates with team members to provide subject matter expertise with respect to the Firm’s third-party risk management program and creates and updates documents and presentations that can be used to inform internal employees, external auditors or internal auditors about the program

Contributes to the continuous improvement, including automation where possible, of all aspects of the third-party risk management program based on expert knowledge, industry best practices, business objectives and risk tolerance, keeping the program relevant and in alignment with the business objectives

Leads third party risk/threat notification to third party vendors by assessing vendor risk, impact and response to risks/threats (e.g., assessing Log4Shell vendor impact and response communications)

Tracks vendor mitigation progress of identified threats and risks

Develops, implements, monitors KPI, KRI for third party risk management program

Develops and updates third party risk management program policies, procedures, and best practices

Actively participates in outside Third-Party Risk Management communities

Works with the security team to develop, manage and maintain the Firm’s Information Security Program, security awareness programs, insider threat programs, etc.

Identifies Information Security & Business Continuity risks to senior management & makes recommendations for corrective actions/mitigation of risks

Assesses BCP/DR compliance status of third-party vendors and communicates their status/impact to the firm’s BCP/DR team

Assists IT Compliance team with completing vendor risk assessments submitted to GT by clients and prospective clients; responds to client Requests for Proposals (RFPs) and questionnaires related to security

Performs other related duties as required / assigned

Skills & Competencies:

Understanding of information security (IS) concepts, IT, information security awareness and third-party risk management processes, methodologies, and practices

Demonstrate strong customer service skills to ensure a smooth data collection experience for both our customers and our internal business unit partners

As a specialist on complex technical and business matters, work is highly independent

Demonstrate strong customer service skills to ensure a smooth evidence collection experience for both clients and vendors

Explain and articulate technical concepts to non-technical stakeholders, and follow basic troubleshooting steps to work through issues

Strong interpersonal skills, capable of interacting at all levels of the organization from analyst level to C-suite

Demonstrate basic project management and documentation skills to manage multiple parallel work streams

Ability to multitask and complete assignments within deadlines that may have short lead times

Work well under pressure with tight deadlines to deliver superior service to our clients and stakeholders

Ability to write reports, briefs or create presentations resulting from third party vendor assessments

Ability to perform and document a gap analysis as part of third-party vendor assessments

Familiar with contractual clauses best practices that may be enforced to achieve third-party vendor compliance (right to audit, minimum security requirements, SLAs, 3rd party assessments, etc.)

Qualifications & Prior Experience:

Bachelor’s degree in Information Technology, Information Systems, Information Security, Business Administration, or Risk Management or equivalent experience

1-3 years of experience in implementing and/or supporting IT risk management processes.

1-3 years of experience in responding to vendor IT risk assessments

Industry certifications preferred (e.g. CTPRP, CISSP, CISM, CRISC, CIPP, CISA)or willingness to obtain

Proficiency with Governance, Risk, Compliance tools (e.g., VSAQ, CIS, VRMMM, SCA, SIG, risk exchanges)

Working knowledge of security standards, frameworks and best practices (ISO 27001/27701, NIST 800-53, CSA, OWASP, CIS, HiTech)

Proficient knowledge of third-party related regulatory policies

Experience working with compliance issues dealing with sensitive data preferred

Working knowledge of cloud technologies (AWS, Azure, Alibaba, GCP, IBM cloud) and software delivery models (SaaS, PaaS, IaaS)

Proficiency with Windows-based software and Microsoft Office suite

Greenberg Traurig is an Equal Opportunity Employer and committed to diversity and inclusion in the workplace. Individuals seeking employment at Greenberg Traurig are considered without regards to race, color, religion, sex, sexual orientation, gender identification, national origin, age, marital status, ancestry, disability, veteran status, or genetic information, among other protected bases.

In support of our commitment to a diverse and inclusive workplace, GT participates in the Mansfield Rule Certification Program. The program, which is administered by The Diversity Lab, seeks to increase diversity representation in the legal profession and within law firm leadership roles. In 2019, GT achieved Mansfield 3.0 Certification, and in 2020, we achieved an even higher standard: Mansfield 4.0 Certification Plus. GT is currently participating in the Mansfield Rule 5.0 Certification Program. Providing your data during the application process helps us with achieving that goal and with meeting reporting/record-keeping obligations under federal and state law and other legal requirements.

Company info

Greenberg Traurig, L.L.P
Website : http://www.gtlaw.com/

EmploymentCrossing provides an excellent service. I have recommended the website to many people..
Laurie H - Dallas, TX
  • All we do is research jobs.
  • Our team of researchers, programmers, and analysts find you jobs from over 1,000 career pages and other sources
  • Our members get more interviews and jobs than people who use "public job boards"
Shoot for the moon. Even if you miss it, you will land among the stars.
ComplianceCrossing - #1 Job Aggregation and Private Job-Opening Research Service — The Most Quality Jobs Anywhere
ComplianceCrossing is the first job consolidation service in the employment industry to seek to include every job that exists in the world.
Copyright © 2024 ComplianceCrossing - All rights reserved. 169 192