Object Technology Solutions, Inc(OTSI) has an immediate opening for a Sr. Information Security Analyst - GRC
Sr. Information Security Analyst – GRC (Cary, NC- Onsite)
Other Location: Overland Park, KS - Onsite
MAJOR RESPONSIBILITES:
Contract Risk ManagementProven experience reviewing client contractprovisions related to data security, breach reporting, cyber resilience, andcompliance certifications and measuring compliance in IT and securityarchitecture and operations.
Regulatory Compliance Risk Management
Support independent certification and audit byworking with D&IT peer groups and lines of business to collect documentationand evidence of security policies and operations
Request and review documentation and evidencefrom control owners to certify and validate compliance to standards andindustry-accepted best practice
Monitor regulatory and legal landscape at aglobal scale and across market sectors and maintain awareness of compliancerequirements
IT Governance
Act as an informed voice in development ofpolicy and ensure alignment with regulatory, legal, and contractualrequirements
Assist establishment and enforcement ofstandards of practice documentation to be referenced by architecture andoperations teams
Contribute process and subject matter expertisein governance forums and cross-functional committees
Cyber Risk Management
Support establishment, collection, and ongoingimprovement of metrics to measure effectiveness of cyber risk management andprovide data-driven insight to decision makers and control owners
Collaborate with peer D&IT groups tocollect KPI’s, KRI’s and drive efficiency through automation and other means
Supplier/Third Party Risk Management
Contribute subject matter expertise throughthird party risk assessment process
Identify and communicate risk of vendorengagements and mitigation actions to business owners and D&IT stakeholders
Assist review of client security requirementsin contracts and aggregate relevant clauses to inform contractual risk
Miscellaneous:
Assist development of user training alignedwith cyber threat landscape, establish and implement metrics, and proposeenhancements
Support internal audit
Assist with securitycertification/attestations/audits to demonstrate control effectiveness toindependent service auditors/assessors and C3PAO’s
Assist in development of risk treatment plansand monitoring progress of actions.
Collaborate with members of the GRC team toensure timely and quality deliverables to internal and external customers
Contribute subject matter expertise in reviewand response to internal and external sourced GRC related requests
SKILLS AND ABILITIES REQUIRED:
Bachelor’s degree in information systems,Information Security, or a related field
7–10 years of experience in GRC executing orauditing against standards, frameworks, and industry regulations
Demonstrated experience supporting GRCfunctions for global companies
Solid proficiency in risk assessmentmethodologies and frameworks
Proven ability to assess alignment of internalpolicy, process, control design and operations, and cyber risk management withregulatory standards and frameworks
Strong collaboration with IT teams
Familiarity with industry standards andframeworks (e.g., NIST CSF and supporting SP’s, ISO 27001, AICPA SOC)
Working knowledge of cyber and privacy laws andregulations
Solid understanding of information securityprinciples and concepts
Strong desire to create task and functionalefficiencies through use of technology and tools, especially GenAI
Preferred Qualifications
Strong analytical, organizational, andcommunication skills
Professional certifications such as CRISC,CISSP or others
Experience with ServiceNow Risk Managementplatform
Knowledge of FAR, DFARS, CMMC
Experience with GRC platforms and riskmanagement methodologies
Ability to work independently andcollaboratively as required
Competencies
Attention to detail and critical thinking
Ethical judgment and integrity
Ability to manage multiple tasks and deadlines
Strong interpersonal and stakeholder engagementskills
About us
About us:
OTSI is a global technologypartner providing enterprise IT consulting, digital solutions, and managedservices. We help organizations modernize complex technology landscapes,harness the power of data, and build scalable AI-led ecosystems to accelerate innovationand business growth. With over 26 years of experience, we consistently turncomplex challenges into success stories through our strong technicalcapabilities and deep industry knowledge. Our global team of 1,800+professionals, spread across 6 countries, delivers cutting-edge solutions forcustomers across Banking, Financial Services, Insurance, Transportation &Logistics, Energy & Utilities, Healthcare & Life Sciences, Government,Hi-Tech, Telecom & Media, Manufacturing, and more.
Our focused technologyareas:
· AI/ML (Agentic AI Solutions, GenAI/LLMs, Natural Language Processing,Intelligent Processing, Physical Intelligence)
· Data & Analytics (Data Architecture, Data Engineering, DataMigration, Data Modernization, Big Data, Analytics and BI)
· Cloud (Cloud Computing, Cloud Migration, Cloud-Native Architecture,Hybrid and Multi-Cloud)
· Digital Engineering (Application Modernization, Product Engineering,Platform Engineering, DevSecOps)
· Quality Engineering (Manual Testing, Nonfunctional testing, TestAutomation, Digital Testing)
· Enterprise Platforms (SAP, Microsoft, Oracle, etc.)
Our focused industries andtarget segments:
· Banking, Financial Services, & Insurance
· Manufacturing, Transportation, & Logistics
· Energy & Utilities
· Telecom & Media
· Healthcare & Lifesciences
· Government & Public Sector (FED, SLED, & Partners)
· Hi-Tech
| Location | Cary, North Carolina |
Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.
Free resume templatesImprove your existing resume or start from scratch and create a standout, ATS-friendly resume. Add job-specific content, download and apply.
Free resume builder