REMOTE Compliance Analyst

SAMPRASOFT

Irvine, CA(remote)

JOB DETAILS
SKILLS
Analysis Skills, Business Solutions, CISA - Certified Information Systems Auditor, CISM - Certified Information Security Manager, CISSP - Certified Information Systems Security Professional, Communication Skills, Computer Science, Consulting, Data Quality, Detail Oriented, Education Regulations, Establish Priorities, GIAC - Global Information Assurance Certification, High Level Architecture (HLA), Higher Education, ISO (International Organization for Standardization), Information Technology & Information Systems, Information/Data Security (InfoSec), Legal, Metrics, PCI, People Management, Performance Management, Project Tracking, Purchasing/Procurement, Reporting Skills, Risk, Risk Analysis, Risk Management, System Architecture, Training/Teaching, U.S. National Institute of Standards and Technology (NIST), Vendor/Supplier Evaluation
LOCATION
Irvine, CA
POSTED
3 days ago
Job Title

Review incoming documents from suppliers (e.g., SOC 2 Type II reports, high level system architecture diagrams, information security policies)

Consult with other shared service departments, as appropriate (e.g., Procurement, Privacy, Operational Risk, Legal)

Compile information into a summary report, highlighting concerns in the form of a risk report/profile for a supplier or particular engagement

Monitor key supplier changes and risk indicators

Issue monitoring, exception tracking and oversight of remediation actions to improve overall supplier performance

Define, measure and monitor progress of supplier risk management activities (Issue Tracking, Risk Remediation Efforts, Key Supplier Metrics)

Create reporting materials detailing program activities, supplier metrics and issue remediation

Maintain supplier data accuracy within designated systems

Provide guidance and training to stakeholders on supplier risk management policies and procedures

Bachelor's degree in Business Information Systems, Computer Science or similar

Minimum four years related experience, including at least two years of third party risk management experience conducting risk or compliance assessments

Understanding of information security frameworks and standards (e.g., NIST 800-171, ISO27002/27002, PCI, GDPR)

Ability to document and communicate assessment results clearly and concisely

Knowledge of supplier risk management methodologies, risk mitigation principles

Ability to work both independently and as part of a team to deliver quality work

Attention to detail, and the ability to prioritize works efficiently and effectively

Experience with OneTrust

Security-related certifications (CISA, CISM, CISSP, SANS GIAC)

Higher education and/or research institution experience

Understanding of higher education legal and regulatory environment (e.g.

About the Company

S

SAMPRASOFT