This role partners closely with Information Security, IT, Legal, Human Resources, Compliance, business stakeholders, and external partners to strengthen governance practices, mature risk management ...
This role partners closely with Information Security, IT, Legal, Human Resources, Compliance, business stakeholders, and external partners to strengthen governance practices, mature risk management ...
This role partners closely with Information Security, IT, Legal, Human Resources, Compliance, business stakeholders, and external partners to strengthen governance practices, mature risk management ...
This role partners closely with Information Security, IT, Legal, Human Resources, Compliance, business stakeholders, and external partners to strengthen governance practices, mature risk management ...
You should be a technically experienced and innovative security, risk, compliance, and audit professional who has the ability to understand systems, security, and privacy processes, communicate to ...
You should be a technically experienced and innovative security, risk, compliance, and audit professional who has the ability to understand systems, security, and privacy processes, communicate to ...
The Governance, Risk, and Compliance (GRC) Specialist supports the organization's information security and enterprise risk management programs by facilitating risk identification, control assessment ...
The Governance, Risk, and Compliance (GRC) Specialist supports the organization's information security and enterprise risk management programs by facilitating risk identification, control assessment ...
Cyber Security Risk & Compliance Specialist
Irving, TX · On-site
$119K - $145K/yr
Cyber Security Risk & Compliance Specialist About Us EF Johnson Technologies, Inc. is a subsidiary ... This is an Information Security Systems Officer (ISSO) role, responsible for developing and ...
Quick apply
Cyber Security Risk & Compliance Specialist
Irving, TX · On-site
$119K - $145K/yr
Cyber Security Risk & Compliance Specialist About Us EF Johnson Technologies, Inc. is a subsidiary ... This is an Information Security Systems Officer (ISSO) role, responsible for developing and ...
Network Security Analyst
Austin, TX · On-site
... Risk, and Compliance (GRC) solutions. • This role works closely with Information Security, Data Privacy, Risk Management, Compliance, and system stakeholders to deliver scalable, user-friendly ...
Quick apply
Network Security Analyst
Austin, TX · On-site
... Risk, and Compliance (GRC) solutions. • This role works closely with Information Security, Data Privacy, Risk Management, Compliance, and system stakeholders to deliver scalable, user-friendly ...
This role owns security operations, governance, risk management, and incident response while partnering closely with infrastructure, cloud, compliance, and business leaders. The ideal candidate has ...
This role owns security operations, governance, risk management, and incident response while partnering closely with infrastructure, cloud, compliance, and business leaders. The ideal candidate has ...
This role owns security operations, governance, risk management, and incident response while partnering closely with infrastructure, cloud, compliance, and business leaders. The ideal candidate has ...
This role owns security operations, governance, risk management, and incident response while partnering closely with infrastructure, cloud, compliance, and business leaders. The ideal candidate has ...
This role owns security operations, governance, risk management, and incident response while partnering closely with infrastructure, cloud, compliance, and business leaders. The ideal candidate has ...
This role owns security operations, governance, risk management, and incident response while partnering closely with infrastructure, cloud, compliance, and business leaders. The ideal candidate has ...
This role owns security operations, governance, risk management, and incident response while partnering closely with infrastructure, cloud, compliance, and business leaders. The ideal candidate has ...
This role owns security operations, governance, risk management, and incident response while partnering closely with infrastructure, cloud, compliance, and business leaders. The ideal candidate has ...
Manages contract analyst workflow queue within Governance, Risk and Compliance (GRC) software ... and Information Security Risk. * Ensures appropriate New Vendor Analysis and or vendor Due ...
Manages contract analyst workflow queue within Governance, Risk and Compliance (GRC) software ... and Information Security Risk. * Ensures appropriate New Vendor Analysis and or vendor Due ...
Manages contract analyst workflow queue within Governance, Risk and Compliance (GRC) software ... and Information Security Risk. * Ensures appropriate New Vendor Analysis and or vendor Due ...
Manages contract analyst workflow queue within Governance, Risk and Compliance (GRC) software ... and Information Security Risk. * Ensures appropriate New Vendor Analysis and or vendor Due ...
Manager - Fraud Risk and Compliance - Risk Control The Role Fraud Risk & Control is seeking a ... Risk Please be advised that Fidelity's business is governed by the provisions of the Securities ...
Manager - Fraud Risk and Compliance - Risk Control The Role Fraud Risk & Control is seeking a ... Risk Please be advised that Fidelity's business is governed by the provisions of the Securities ...
This role works closely with Information Security, Data Privacy, Risk Management, Compliance, and system stakeholders to deliver scalable, user-friendly Archer applications that enable assessment ...
This role works closely with Information Security, Data Privacy, Risk Management, Compliance, and system stakeholders to deliver scalable, user-friendly Archer applications that enable assessment ...
Manager - Fraud Risk and Compliance - Risk Control The Role Fraud Risk & Control is seeking a ... Risk Please be advised that Fidelity's business is governed by the provisions of the Securities ...
Manager - Fraud Risk and Compliance - Risk Control The Role Fraud Risk & Control is seeking a ... Risk Please be advised that Fidelity's business is governed by the provisions of the Securities ...
Cyber Strategy, Risk & Compliance - Senior Associate
Dallas, TX · On-site
$77K - $202K/yr
In regulatory risk compliance at PwC, you will focus on confirming adherence to regulatory ... Systems Security Professional (CISSP), ISACA in Risk and Information Systems Control (CRISC ...
Cyber Strategy, Risk & Compliance - Senior Associate
Dallas, TX · On-site
$77K - $202K/yr
In regulatory risk compliance at PwC, you will focus on confirming adherence to regulatory ... Systems Security Professional (CISSP), ISACA in Risk and Information Systems Control (CRISC ...
Cyber Strategy, Risk & Compliance - Senior Associate
Houston, TX · On-site
$77K - $202K/yr
In regulatory risk compliance at PwC, you will focus on confirming adherence to regulatory ... Systems Security Professional (CISSP), ISACA in Risk and Information Systems Control (CRISC ...
Cyber Strategy, Risk & Compliance - Senior Associate
Houston, TX · On-site
$77K - $202K/yr
In regulatory risk compliance at PwC, you will focus on confirming adherence to regulatory ... Systems Security Professional (CISSP), ISACA in Risk and Information Systems Control (CRISC ...
... an experienced Information Security Risk Officer (ISRO) to lead its overall technology and ... , and digital transformation initiatives. Serving as the subject matter expert on regulatory ...
... an experienced Information Security Risk Officer (ISRO) to lead its overall technology and ... , and digital transformation initiatives. Serving as the subject matter expert on regulatory ...
The Senior Director partners closely with Legal, Compliance, Finance, Operations, IT/Security, and Sustainability to ensure supplier risk is identified, mitigated, and monitored throughout the ...
The Senior Director partners closely with Legal, Compliance, Finance, Operations, IT/Security, and Sustainability to ensure supplier risk is identified, mitigated, and monitored throughout the ...
GRC Consultant
Houston, TX · Remote
$38 - $40/hr
RSA Archer Engage * Cyber Security * GRC (Governance, Risk & Compliance) * Data Security * Information Security Experience Required * 810 years of relevant experience Qualifications * Bachelor ...
Quick apply
GRC Consultant
Houston, TX · Remote
$38 - $40/hr
RSA Archer Engage * Cyber Security * GRC (Governance, Risk & Compliance) * Data Security * Information Security Experience Required * 810 years of relevant experience Qualifications * Bachelor ...
Security Risk Compliance information
What is the difference between Security Risk Compliance vs Security Analyst?
| Aspect | Security Risk Compliance | Security Analyst |
|---|---|---|
| Certifications | ISO 27001 Lead Implementer, CISSP, CISA | CISSP, CompTIA Security+, GIAC Security Certifications |
| Work Environment | Policy development, compliance audits, risk assessments | Monitoring security systems, incident response, vulnerability analysis |
| Employer & Industry Usage | Financial, healthcare, government sectors focusing on regulatory adherence | IT departments across various industries focusing on security operations |
Security Risk Compliance professionals focus on ensuring organizations meet regulatory standards and manage security risks through policies and audits. Security Analysts primarily monitor security systems, analyze threats, and respond to incidents. While both roles require security certifications and work within similar environments, their core responsibilities differ: compliance versus active security monitoring.
What are some common challenges faced by Security Risk Compliance professionals when balancing regulatory requirements with business objectives?
What are the key skills and qualifications needed to thrive as a Security Risk Compliance professional, and why are they important?
What is Security Risk Compliance?
Other
Posted 7 days ago
O'Neil Digital Solutions rating
9.2
Based on 5 frontline employees who took The Breakroom Quiz
9th of 204 rated it services
Job description
Data Analysis Incorporated (DAI) is the controlling entity of the O'Neil family of businesses. DAI and its subsidiaries operate in diverse industries worldwide, including global equity markets, health care, financial services, digital news, and insurance. Our global footprint allows our teams to be responsive to customer needs in a timely and efficient manner. We are dedicated to using technology and innovation to bring change and growth to our businesses. We believe in a dynamic workplace, creating engaging, informative products and services that help our customers succeed. Integrity is an essential characteristic for our firms and our associates
The Manager, Governance, Risk, Compliance & Privacy (GRCP) is responsible for leading and managing the organization's governance, risk, compliance, and privacy initiatives to ensure alignment with applicable laws, regulations, contractual obligations, security standards, and internal policies. This role partners closely with Information Security, IT, Legal, Human Resources, Compliance, business stakeholders, and external partners to strengthen governance practices, mature risk management processes, support audit and regulatory readiness, and promote privacy and security accountability across DAI companies.
Lead the implementation and continuous improvement of governance frameworks, policies, standards, procedures, and controls related to information security, privacy, and technology compliance.
Manage cybersecurity, operational risk, and third-party risk management activities including risk identification, assessment, remediation tracking, and executive reporting.
Lead compliance initiatives supporting regulatory, contractual, and industry requirements, including audit coordination, evidence collection, remediation tracking, and certification readiness efforts.
Direct privacy and data protection activities including privacy impact assessments (PIAs/DPIAs), privacy risk assessments, privacy incident coordination, and data subject request support.
Facilitate governance reviews, compliance meetings, and cross-functional initiatives to ensure accountability and timely remediation of identified risks and compliance gaps.
Develop, maintain, and report metrics related to governance, risk, compliance, privacy, audits, control effectiveness, remediation activities, and program maturity.
Partner with business and technical teams to integrate security, privacy, and compliance requirements into operational and technology processes using privacy-by-design and security-by-design principles.
Lead enterprise-wide security and privacy awareness initiatives, training programs, communications, and guidance to promote a culture of compliance, accountability, and secure business operations.
Support governance activities associated with incident response, business continuity, disaster recovery, crisis management, and operational resilience programs.
Monitor evolving regulatory, privacy, and security requirements and evaluate impacts to organizational policies, controls, and business operations.
Required Education, Experience, Certification/Licensure
- Bachelor's degree in Information Security, Cybersecurity, Information Technology, Business, Risk Management, or related field.
- Minimum 5-7 years of experience in Governance, Risk, Compliance (GRC), Privacy, Information Security, Audit, or related disciplines.
- Experience leading or managing governance, compliance, privacy, audit, or risk management programs within complex organizations.
- Experience supporting internal and external audits, assessments, and compliance initiatives involving security and privacy controls.
- Experience collaborating across technical and business teams to drive governance and compliance initiatives.
Preferred Education, Experience, Certification/Licensure
- Master's degree in a related field.
- CISM (Certified Information Security Manager)
- CRISC (Certified in Risk and Information Systems Control)
- CISA (Certified Information Systems Auditor)
- CISSP (Certified Information Systems Security Professional)
- ISO 27001 Lead Implementer or Lead Auditor
- CDPSE, CIPM, CIPT, or other privacy-related certifications
- Experience supporting international privacy and regulatory compliance requirements.
KNOWLEDGE, SKILLS AND ABILITIES (KSAs)
- Strong knowledge of governance, risk management, compliance, privacy, and information security principles.
- Working knowledge of ISO 27001/27002, ISO 42001, SOC 2 Type II, NIST Cybersecurity Framework (CSF), NIST 800-53, HITRUST, PCI-DSS, and privacy/data protection frameworks.
- Strong analytical, problem-solving, and risk assessment capabilities.
- Ability to translate complex compliance, security, and privacy requirements into practical business guidance.
- Excellent written, verbal, presentation, and stakeholder management skills.
- Strong organizational skills with the ability to manage multiple priorities and initiatives simultaneously.
- Experience with governance, risk, and compliance platforms and supporting technologies.
- Familiarity with cloud security concepts, vulnerability management tools (e.g., Qualys), CNAPP platforms (e.g., Wiz, Qualys), and Identity & Access Management solutions (e.g., Ping, Auth0, Entra ID).
Must be able to perform essential job duties. Work is performed primarily in an office environment. Typically requires the ability to sit for extended periods of time (66%+ each workday), hear the telephone, and enter data on a computer and may also require the ability to lift up to 10 pounds.
Data Analysis Inc is an equal opportunity employer. All aspects of employment, including the decision to hire, promote, discipline, or discharge, will be based on merit, competence, performance, and business needs. We do not discriminate on the basis of race, color, religion, marital status, age, national origin, ancestry, physical or mental disability, medical condition, pregnancy, genetic information, gender, sexual orientation, gender identity or expression, veteran status, or any other status protected under federal, state, or local law.