GRC Analyst (GRC security consultant profile)

Overview

On Site
Depends on Experience
Contract - W2
Contract - Independent
Contract - 12 Month(s)

Skills

GRC Analyst

Job Details

GRC Analyst

Long Term onsite project in Suffolk County NY

 

Duties/Roles

At the direction of the CIO, CTO, CISO to perform the following activities:

  1. When called upon, participate in executive meetings.
  2. Verify current Laws and Regulation (Federal, State, County) and all associated compliance requirements for Suffolk County.
  3. Review and bolster existing IT Security policy, standards, and procedure development (aligned with industry frameworks (e.g. NIST), including but not limited to the following areas:
    1. Enterprise Information and Information Technology Security Policies, Standards and supporting procedures.
    2. Incident Management Policy and supporting procedures/testing.
      1. Cyber Incident Response Plan
    3. System and Application Configuration standards.
      1. Server CIS Hardened Builds for Server OS
      2. Endpoint CIS Hardened Builds for Endpoint OS
      3. Application Secure Coding Standards
    1. Disaster Recovery and Business Continuity Policy/Plans/Testing
      1. Development of department business impact assessments, risks, contingencies, RTO/RPO
    1. Third Party Risk Management
      1. Review existing vendor onboarding practices / offboarding practices to align with current industry standards
      2. Review existing security addendums
    1. Personnel Security
      1. Review existing Onboarding practices to align with current industry standards
      2. Review existing offboarding practices to align with current industry standards
    1. Security Awareness / Policy Acknowledgement
      1. Review existing practices to align with current industry standards
  1. Enhance current Risk Management and Risk Exception processes and supporting documentation
Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.