Overview
On Site
$55 - $65 hourly
Contract - W2
Contract - Temp
Skills
Information Systems
Business Process
Information Security Governance
Collaboration
Training
Privacy
SAP GRC
Audit Management
Communication
Management
Analytical Skill
Problem Solving
Conflict Resolution
PCI DSS
Sarbanes-Oxley
ISO/IEC 27001:2005
Information Security
Cyber Security
Risk Management
Risk Assessment
Regulatory Compliance
Artificial Intelligence
Messaging
Job Details
RESPONSIBILITIES:
Kforce has a client in San Diego, CA that is seeking a Governance, Risk, & Compliance Specialist that provides expertise in the areas of Information Security policy development and maintenance, security training, phishing simulations, risk management and assessment, and security compliance frameworks to support global GRC initiatives across the enterprise. The ideal candidate has experience identifying cybersecurity best practices and recommending improvements to information systems and business processes to align with them, in addition to managing complex GRC initiatives and driving them to successful completion.
Responsibilities:
* Develop and support information security governance policies, standards, and processes in collaboration with business and technical teams, and align them with business goals
* Prepare and deliver information security training, education, and awareness activities appropriate for target audiences
* Evaluate effectiveness of information security controls and recommending remediation or control re-design guidance where necessary
* Fine tune and drive adoption of an information security risk assessment framework and related processes; Maintain Information Security risk registers and perform annual assessments
* Maintain knowledge of FTC Safeguards, PCI DSS, ISO 27001, and NIST CSF and ensure organizational compliance
* Partner with business leaders to gain a deeper understanding of their needs and provide solutions that meet their goals and objectives while aligning with security best practices and policy
* Maintain working knowledge of data privacy laws and regulations
* Perform other duties, as assigned
REQUIREMENTS:
* Bachelor; Computer Science, Information Systems, Information Technology, Software Engineering
* 3+ years of experience
* Proficiency in using GRC tools and software to streamline and automate risk and compliance processes (i.e., AuditBoard)
* Skilled in audit management and experience liaising with third party auditors
* Able to work in a complex, global environment, actively and effectively managing relationships with other business units and stakeholders
* Skilled in communicating technical requirements with non-technical stakeholders
* Excellent oral and written communication skills
* Excellent problem solving and analytical skills
* Strong time management skills, including effective responsibility prioritization
* Strong analytical and problem-solving skills to identify and assess security risks and develop appropriate mitigation strategies
* Familiarity with relevant industry regulations and compliance requirements such as GDPR, PCI-DSS, CCPA, SOX, etc.
* Familiarity with various cybersecurity frameworks such as NIST Cybersecurity Framework, ISO 27001, CIS Controls, etc.
* Experience in technical Information Security roles a plus
* Strong understanding of cybersecurity principles, best practices, and industry standards
* In-depth knowledge of governance, risk management, and compliance principles and practices
* Ability to develop and implement risk assessment methodologies and compliance programs
* Ability to successfully influence stakeholders in support of shared goals
The pay range is the lowest to highest compensation we reasonably in good faith believe we would pay at posting for this role. We may ultimately pay more or less than this range. Employee pay is based on factors like relevant education, qualifications, certifications, experience, skills, seniority, location, performance, union contract and business needs. This range may be modified in the future.
We offer comprehensive benefits including medical/dental/vision insurance, HSA, FSA, 401(k), and life, disability & ADD insurance to eligible employees. Salaried personnel receive paid time off. Hourly employees are not eligible for paid time off unless required by law. Hourly employees on a Service Contract Act project are eligible for paid sick leave.
Note: Pay is not considered compensation until it is earned, vested and determinable. The amount and availability of any compensation remains in Kforce's sole discretion unless and until paid and may be modified in its discretion consistent with the law.
This job is not eligible for bonuses, incentives or commissions.
Kforce is an Equal Opportunity/Affirmative Action Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, pregnancy, sexual orientation, gender identity, national origin, age, protected veteran status, or disability status.
By clicking ?Apply Today? you agree to receive calls, AI-generated calls, text messages or emails from Kforce and its affiliates, and service providers. Note that if you choose to communicate with Kforce via text messaging the frequency may vary, and message and data rates may apply. Carriers are not liable for delayed or undelivered messages. You will always have the right to cease communicating via text by using key words such as STOP.
Kforce has a client in San Diego, CA that is seeking a Governance, Risk, & Compliance Specialist that provides expertise in the areas of Information Security policy development and maintenance, security training, phishing simulations, risk management and assessment, and security compliance frameworks to support global GRC initiatives across the enterprise. The ideal candidate has experience identifying cybersecurity best practices and recommending improvements to information systems and business processes to align with them, in addition to managing complex GRC initiatives and driving them to successful completion.
Responsibilities:
* Develop and support information security governance policies, standards, and processes in collaboration with business and technical teams, and align them with business goals
* Prepare and deliver information security training, education, and awareness activities appropriate for target audiences
* Evaluate effectiveness of information security controls and recommending remediation or control re-design guidance where necessary
* Fine tune and drive adoption of an information security risk assessment framework and related processes; Maintain Information Security risk registers and perform annual assessments
* Maintain knowledge of FTC Safeguards, PCI DSS, ISO 27001, and NIST CSF and ensure organizational compliance
* Partner with business leaders to gain a deeper understanding of their needs and provide solutions that meet their goals and objectives while aligning with security best practices and policy
* Maintain working knowledge of data privacy laws and regulations
* Perform other duties, as assigned
REQUIREMENTS:
* Bachelor; Computer Science, Information Systems, Information Technology, Software Engineering
* 3+ years of experience
* Proficiency in using GRC tools and software to streamline and automate risk and compliance processes (i.e., AuditBoard)
* Skilled in audit management and experience liaising with third party auditors
* Able to work in a complex, global environment, actively and effectively managing relationships with other business units and stakeholders
* Skilled in communicating technical requirements with non-technical stakeholders
* Excellent oral and written communication skills
* Excellent problem solving and analytical skills
* Strong time management skills, including effective responsibility prioritization
* Strong analytical and problem-solving skills to identify and assess security risks and develop appropriate mitigation strategies
* Familiarity with relevant industry regulations and compliance requirements such as GDPR, PCI-DSS, CCPA, SOX, etc.
* Familiarity with various cybersecurity frameworks such as NIST Cybersecurity Framework, ISO 27001, CIS Controls, etc.
* Experience in technical Information Security roles a plus
* Strong understanding of cybersecurity principles, best practices, and industry standards
* In-depth knowledge of governance, risk management, and compliance principles and practices
* Ability to develop and implement risk assessment methodologies and compliance programs
* Ability to successfully influence stakeholders in support of shared goals
The pay range is the lowest to highest compensation we reasonably in good faith believe we would pay at posting for this role. We may ultimately pay more or less than this range. Employee pay is based on factors like relevant education, qualifications, certifications, experience, skills, seniority, location, performance, union contract and business needs. This range may be modified in the future.
We offer comprehensive benefits including medical/dental/vision insurance, HSA, FSA, 401(k), and life, disability & ADD insurance to eligible employees. Salaried personnel receive paid time off. Hourly employees are not eligible for paid time off unless required by law. Hourly employees on a Service Contract Act project are eligible for paid sick leave.
Note: Pay is not considered compensation until it is earned, vested and determinable. The amount and availability of any compensation remains in Kforce's sole discretion unless and until paid and may be modified in its discretion consistent with the law.
This job is not eligible for bonuses, incentives or commissions.
Kforce is an Equal Opportunity/Affirmative Action Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, pregnancy, sexual orientation, gender identity, national origin, age, protected veteran status, or disability status.
By clicking ?Apply Today? you agree to receive calls, AI-generated calls, text messages or emails from Kforce and its affiliates, and service providers. Note that if you choose to communicate with Kforce via text messaging the frequency may vary, and message and data rates may apply. Carriers are not liable for delayed or undelivered messages. You will always have the right to cease communicating via text by using key words such as STOP.
Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.