Full-Time

Senior Analyst-Security Governance Risk & Compliance

Posted on 9/26/2025

HEXAWARE

HEXAWARE

No salary listed

Dublin, CA, USA

Hybrid

Location: Dublin, CA; 4 days onsite in a week; hybrid.

Category
IT & Security (4)
, , ,
Requirements
  • Experience in Security Governance, Risk and Compliance (GRC)
  • Knowledge of information security frameworks (e.g., NIST, ISO 27001, SOC2) and regulatory requirements
  • Ability to develop and maintain security standards, process documentation and control objectives
  • Experience with risk assessments for Information Security, IT and Third-Party risk
  • Experience in monitoring risk treatment strategies and control effectiveness
  • Ability to collaborate with First Line of Defense and Internal Audit/Compliance teams
  • Strong communication and reporting skills to track program metrics
  • Experience in security control mappings to relevant frameworks
  • Diligence in monitoring industry regulatory environment and changes to security standards
  • Experience in security awareness and training program development
  • Ability to identify security weaknesses, define risk impacts and develop mitigation strategies
  • Experience in monitoring and escalating security issues to leadership
  • 4 days onsite in Dublin, CA? (Location may be requested as job requirement)
  • Bachelor's degree in Information Security, Computer Science, or related field or equivalent work experience
  • Professional certifications (e.g., CISSP, CISM) preferred
Responsibilities
  • Supports the development and on-going management of the Security Governance, Risk & Compliance program
  • Develops and maintains security standards, process documentations and control objectives
  • Develops and maintains security control mappings to relevant frameworks
  • Matures and enhance the information security awareness and training program
  • Performs and manages the Information Security, Information Technology and Third-Party risk assessments
  • Develops and maintains risk and controls register and monitor risk treatment strategies and control effectiveness
  • Monitor and escalate unresolved security issues, exposures, misuse, policy violations and other non-compliance situations to Security Leadership
  • Provide continuous tracking and monitoring of Security Program metrics
  • Work closely with First Line of Defense teams, to identify potential security weaknesses, define potential impact and develop effective mitigation strategies
  • Collaborating with Internal Audit and Compliance teams for security and technology audit-related activities
  • Monitor industry regulatory environment for impact on security programs and changes to security compliance standards
  • Performs other duties as may be assigned
Desired Qualifications
  • Professional certifications preferred
  • Bachelor's degree in Information Security, Computer Science, or related field or equivalent work experience preferred

Company Size

N/A

Company Stage

N/A

Total Funding

N/A

Headquarters

N/A

Founded

N/A

INACTIVE