Principal Governance Risk & Compliance Analyst
Company
Red Canary
Location
USA
Type
Full Time
Job Description
Who We Are
Red Canary was founded to create a world where every organization can make its greatest impact without fear of cyber threats. We’re a cyber security company who protects supports and empowers organizations to make better security decisions so they can focus on their mission without fear of cyber threats.
The combination of our market-defining technology and expertise prevents breaches every day and sets a new standard for partnership in the industry. We’re united in our commitment to customers and grounded in our values which earned us a place on the Forbes Best Start-up Employers 2022 list. If our mission resonates with you let’s talk.
What We Believe In
- Do what’s right for the customer
- Be kind and authentic
- Deliver great quality
- Be relentless
Challenges You Will Solve
At Red Canary the protection of our customers and employees is of the utmost importance. Red Canary’s Governance Risk & Compliance (GRC) team provides oversight to ensure that our people platforms and data remain secure in compliance with our policies and applicable laws.
As a Principal GRC Analyst you will help ensure that our controls policies and procedures are designed implemented and tested to deliver the best possible outcomes for Red Canary and our customers. Reporting to the General Counsel the Principal GRC Analyst is responsible for activities and improvements across the entire scope of Red Canary’s GRC programs.
What You'll Do
-
Lead governance risk and compliance initiatives.
-
Lead regular reviews to ensure that policies and controls are effective while aligning them to company values and all applicable compliance requirements; identify potential improvements and manage their implementation.
-
Identify design and lead projects to automate the collection and presentation of auditing data for internal and external consumption.
-
Lead internal audits and risk assessments of the Red Canary environment; identify potential improvements and manage their implementation.
-
Schedule prepare for and lead annual external audits against SOC 2 Type II ISO 27001 ISO 27701 and other standards.
-
Maintain security and compliance certifications; identify and manage new certification initiatives.
-
Lead the vendor risk management function for evaluating Red Canary’s vendors and partners to identify potential risks; identify potential improvements and manage their implementation.
-
Lead the response to questions and questionnaires from customers potential customers and partners regarding security and compliance; identify potential improvements and manage their implementation.
-
Support the sales team in vetting security and compliance terms in customer contracts.
-
Help oversee security awareness training that is both relevant and instructive.
-
Lead relevant and engaging business continuity and incident response exercises.
What You'll Bring
-
5+ years of experience with SOC 2 Type II and ISO 27001 audits. Experience with audits under ISO 27701 FedRAMP and CMMC experience is a plus.
-
5+ years of managing or performing security questionnaires and vendor assessments.
-
Experience addressing security and compliance terms in commercial contracts.
-
The ability to articulate and shift between various compliance and regulatory frameworks.
-
An understanding of the unique risks presented by cloud-native architecture and compliance and audit strategies for environments heavily reliant on SaaS.
-
Strong experience interacting with auditors and gaining their confidence as a source of truth.
-
Expertise in designing and managing strategies to identify articulate and mitigate risks.
-
Experience in designing and implementing automation to the collection and presentation of audit data.
-
Outstanding written and verbal communication skills.
-
A practical mindset that can balance compliance and business needs.
-
The ability to lead multiple projects simultaneously.
-
A patient and positive attitude.
Targeted base salary range: $130000 - $150000 + bonus eligibility and equity depending on experience.
The application deadline is December 13th 2024.
Why Red Canary?
Red Canary is where people embody our mission to improve security outcomes for all. People work hard to maintain a culture that encourages authenticity in order to do your best work. Our people are driven and committed to finding the best security outcomes delivering real and actionable answers and being transparent along the way.
At Red Canary we offer a very rich benefits program to our full-time team members so they can focus on their families and improving our customers’ security. For a full list of benefits please review our Benefits Summary:
https://resource.redcanary.com/rs/003-YRU-314/images/RedCanary_2024BenefitsSummary.pdf?version=0
Individuals seeking employment at Red Canary are considered without regard to race color religion national origin age sex marital status ancestry physical or mental disability veteran status gender identity or sexual orientation.
Date Posted
11/27/2024
Views
0
Similar Jobs
Group Product Manager - Demand Generation - HubSpot
Views in the last 30 days - 0
HubSpot is seeking a Group Product Manager for Demand Management to lead the vision and strategy of the internalfacing product group The role involves...
View DetailsMobile Engineering Manager - Mobile Retention - Dropbox
Views in the last 30 days - 0
Dropbox is seeking a Mobile Engineering Manager to lead a team of iOS and Android engineers working on the Dropbox apps The role involves managing cri...
View DetailsAccount Manager - SMB - Syndigo
Views in the last 30 days - 0
The Syndigo Account Manager SMB role involves managing client relationships creating strategies and ensuring value delivery The individual will work c...
View DetailsSenior Manager - Customer Success - Contentsquare
Views in the last 30 days - 0
The job posting is for a Senior Manager of Customer Success position in California The role involves leading a team of Customer Success Managers CSMs ...
View DetailsLeave Management Analyst - Renaissance
Views in the last 30 days - 0
Renaissance is a global leader in preK12 education technology offering solutions that help educators create personalized learning paths for students T...
View DetailsRegulatory Counsel - hims & hers
Views in the last 30 days - 0
Hims Hers is seeking a Regulatory Counsel with 4 years of healthcare regulatory experience particularly in telehealth compliance digital health and s...
View Details