ICE logo
ICEPosted 4 months ago

Engineer, Information Security GRC

On-siteAtlanta, Georgia, United States

Full TimeLarge

Job Summary

Produce regular reports on Information Security program status using automated and manual processes. Maintain corporate policies and procedures, mapping them to control standards while organizing documentation for regulator, audit, and customer inquiries. Operate periodic recertification processes to ensure compliance with hire, transfer, and termination protocols, and conduct regular access reviews. Build and maintain security awareness education programs, and operate the company platform to document, measure, and report risk assessments, controls, findings, and remediation activity. Leverage Excel, workflow automation, and scripting to visualize data within NIST Cyber Security Framework and GRC platforms.

Required Qualifications

  • University degree in Information Security, Engineering, MIS, CIS, or related discipline
  • 3+ years of relevant work experience
  • Experience in Cybersecurity Framework (such as NIST, COBIT)
  • Experience with Regulatory Compliance
  • Experience with senior management and board metrics generation and communication
  • Advanced certifications (for example, the CISSP)
  • Advanced technical writing and/or communication education and experience
  • Excel
  • Workflow automation tools
  • Data collection
  • normalization
  • indexing
  • correlation
  • visualization
  • Scripting
  • regular expressions
  • string-parsing
  • light SDLC
  • project management
  • NIST Cyber Security Framework
  • CIS
  • GRC Platforms

Desired Qualifications

  • Experience with Systems Administration and/or IP Networking
  • Experience in an exchange, trading facility, or financial services
  • Experience in Customer communication and Vendor evaluation

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

Apply to this job in one click with Sorce

Apply on Sorce