Dexcom logo
DexcomPosted 2 weeks ago

Sr Cybersecurity Analyst - GRC

HybridTaguig, Metro Manila, Philippines or Cebu, Cagayan Valley, Republic of the Philippines

Full TimeSenior LevelEnterprise

Job Summary

Coordinate audit readiness, evidence collection, and remediation follow-up for internal and external audits while tracking findings and risk treatment activities. Conduct risk assessments using defined criteria, support security certification and compliance assessments, and map regulatory requirements to controls within the OneTrust GRC platform. Generate reports on control health and risk trends, manage user access and workflow configurations, and identify process improvements for continuous monitoring. Partner with control owners, auditors, and business stakeholders to drive audit, risk, and compliance activities to completion.

Required Qualifications

  • Bachelor's degree in information security, Information Systems, Computer Science, Business, or a related field
  • 5+ years of experience in cybersecurity, information security, IT risk management, compliance, audit, or a related information technology function
  • Experience configuring, administering, or supporting a GRC platform such as OneTrust, Archer, ServiceNow GRC, AuditBoard, LogicGate, or a similar tool
  • Working knowledge of cybersecurity, risk, and compliance frameworks such as ISO 27001, NIST CSF, NIST 800-53, PCI DSS, SOC 2, HIPAA, or similar standards
  • Experience supporting audit readiness, evidence collection, control testing, compliance assessments, issue tracking, and remediation activities
  • Ability to support risk assessments, control gap analysis, risk treatment plans, and remediation tracking across business and technology stakeholders
  • Ability to effectively work in cross-functional teams and collaborate with stakeholders from various departments
  • Strong analytical skills, including the ability to analyze GRC data, identify trends, validate data quality, and develop useful metrics or reports
  • Ability to plan, organize, and execute work related to GRC services
  • Strong written and verbal communication skills, with the ability to translate cybersecurity risk, compliance, and audit concepts into clear business language
  • Ability to partner with control owners, business stakeholders, auditors, and cybersecurity teams to resolve issues and drive audit, risk, and compliance activities to completion
  • Typically requires a Bachelor's degree in a technical discipline
  • Minimum of 5-8 years related experience
  • Master's degree and 2-5 years equivalent industry experience
  • PhD and 0-2 years experience

Desired Qualifications

  • OneTrust GRC experience or certification
  • Experience supporting cybersecurity, privacy, audit, or compliance activities in a regulated environment, such as medical device, healthcare, life sciences, financial services, or technology
  • Professional certification such as CISSP, CISA, CISM, CRISC, Security+, ISO 27001 Lead Implementer, or ISO 27001 Lead Auditor
  • Experience developing GRC dashboards, metrics, workflow automation, or reporting processes

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

Apply to this job in one click with Sorce

Apply on Sorce