Kura Sushi logo
Kura SushiPosted 2 weeks ago

GRC Senior Security Analyst

$90,000–$95,000 year

HybridChicago, Illinois, United States or Houston, Texas, United States

Full TimeSenior LevelLarge

Job Summary

Monitor security networks for breaches, conduct forensic analysis of SIEM telemetry, and respond to incidents in real time. Perform periodic vulnerability assessments, threat hunting, and penetration testing to identify security weaknesses. Evaluate and implement security solutions for access management and network security while collaborating with IT teams on secure configurations. Develop and enforce security policies, procedures, and compliance standards; create dashboards and reports for leadership. Train staff on security awareness and compliance requirements. Liaise with regulatory bodies and internal audit to ensure adherence to laws and internal policies.

Required Qualifications

  • A bachelor's degree in Cybersecurity, Computer Science, Information Technology, or a related field
  • Possess relevant certifications such as CISSP or CISM, GIAC or CEH
  • At least 5 years of experience in cybersecurity or IT security role, with a strong understanding of security frameworks and standards such as (NIST, ISO 27001, CIS)
  • Governance, risk and compliance experience from Big 4 consulting firm or fortune 500 company
  • Hands-on experience in incident response and forensic analysis
  • Knowledge of cloud security (Amazon Web Services (AWS), Azure, or Google Cloud Platform (GCP) environments)
  • Familiarity with threat intelligence platforms and malware analysis
  • Experience with regulatory compliance (CCPA, PCI DSS, SOX, GDPR)
  • Proficient with Optro (formerly AuditBoard)-Cross Comply and various security tools
  • Proficiency with SIEM tools such as Splunk, Google Security Operations, QRadar, or ArcSight
  • Knowledge of firewalls, intrusion detection/prevention systems, and endpoint security
  • Knowledge of cloud/data security platforms such as Netskope, CheckPoint, Zscaler
  • Knowledge of data security posture management (DSPM) platforms such as BigID and MS Purview
  • Ability to conduct vulnerability assessments and penetration testing
  • Basic scripting skills in Python, PowerShell, or Bash
  • Strong technical background
  • Excellent leadership and people management skills
  • Skills in documenting security, risk, and regulatory compliance activities
  • Familiarity with security/technology auditing processes
  • Familiar with dashboard creation
  • Ability to critically think about issues, research, and develop solutions/options that can be shared with stakeholders
  • Communicates confidently with executive management, corporate support personnel, cross-functional peers, and product/services providers at appropriate technical levels for each and liaises with Internal Audit to ensure appropriate IT General Controls (ITGCs). Demonstrates ability to articulate business cases for identified technology solutions
  • Excellent analytical and troubleshooting skills
  • Ability to work under pressure
  • This role is a hybrid role. The selected candidate must be able to come to the office in Irvine, CA on in office days and as needed to carry out necessary functions of the role

Desired Qualifications

  • Attends continuing professional education to keep abreast of security and technology regulations, emerging risks and strategies

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

Apply to this job in one click with Sorce

Apply on Sorce