Full-Time

Senior Information Security Governance

Risk and Compliance Analyst, USA

Posted on 8/20/2024

Snowflake

Snowflake

5,001-10,000 employees

Data management and analytics platform

Data & Analytics
Enterprise Software
AI & Machine Learning

Senior, Expert

Dublin, CA, USA

Category
Cybersecurity
IT & Security
Required Skills
Microsoft Azure
Communications
Management
Git
AWS
Data Analysis
Google Cloud Platform
Requirements
  • Minimum of 10 years of tactical and operational experience in Governance, Risk and Compliance, or Information Security, with a focus on risk assessments/management
  • Strong analytical skills along with the ability to effectively communicate complex security related information including risk identification, assessment, and remediation activity.
  • Knowledge and practical experience with the following risk management frameworks: ISO, NIST, and FAIR.
  • Experience with creating and utilizing risk KPIs and KRIs with data visualization tooling.
  • Technical certifications within the area of security and risk are a strong plus (CISSP, CRISC, CISM or equivalent).
  • Knowledge and experience pertaining to: AWS or Azure or GCP (or similar) cloud security and infrastructure, Software as a Service (SaaS) applications, CI/CD pipeline tools (such Github, Jenkins, etc.), Network infrastructure security, Encryption technology and implementation, Database security, Operating system security, Artificial intelligence and machine learning.
  • Expert, communicator and writer; you can coach others on their writing skills, you can adapt your communication style for your audience, and you have experience drafting policies, reports, and other written materials for a variety of executive audiences.
  • Knowledge of global cybersecurity, technology and data privacy regulatory requirements
  • Experience reporting policy and compliance posture to senior stakeholders
  • Ability to direct cross functional work and hold others accountable to committed deadlines.
Responsibilities
  • Ensure relevant cybersecurity risks identified are captured in the risk register and keep it updated with the related information
  • Facilitate risk decomposition (scenario generation) activities with the relevant key stakeholders and document the outcomes
  • Develop a broader understanding of the motives, targets and activities of cyber threat actors and manage threat actor profile for Snowflake
  • Perform cyber risk assessments on new and existing cyber security risks in partnership with risk owners and subject matter experts
  • Analyze cybersecurity risks to determine likelihood and impact to Snowflake business and describe risks in quantitative and qualitative terms
  • Implement a quantitative risk methodology based on FAIR approach and quantify cybersecurity risks in financial terms
  • Develop risk mitigation plan by partnering with the risk and system owners
  • Identify and develop appropriate metrics such as key performance indicators (KPIs) and key risk indicators (KRIs) to measure risks and highlight trends or themes
  • Track and monitor risk mitigation plan activities with metrics and timeline
  • Help make risk-based decisions and trade-offs impacting business strategies
  • Help project prioritization for quarterly planning activities that could mitigate the risks
  • Develop reports and dashboards to provide an update on risk posture to key stakeholders, risk owners and leadership team
  • Maintain a strong understanding of risk management methodologies and frameworks
  • Educate and build awareness of cybersecurity risk management across the organization
  • Empower key stakeholders and risk owners to use the common risk taxonomy
  • Influence behaviors to reduce cybersecurity risk and foster a strong risk-based culture throughout the organization
  • Assess, evolve, and drive the policy management framework for all Security policies and standards in partnership with Security teams and Security Risk Management
  • Review and make recommendations for streamlining existing and future security policies
  • Appropriately assess control design and effectiveness in order to ensure policy and standard enforcement
  • Create a process and collateral for rolling out new security policies to the whole company
  • Establish, document, and broadly communicate security policy management norms to the Security organization, outlining how to create, maintain, enforce, and deprecate security policies in line with enterprise policy requirements
  • Collaborate within Security Compliance, Product Security, Corporate Security, Legal and other partners to incorporate security and compliance requirements into the security policy framework and track policy implementation and issues
  • Manage the Security Exception Process to enable Security teams to track exceptions, manage approvals, and improve automation
  • Partner with Security Analytics team to develop key performance indicators and dashboards to monitor and report on the Security policies
  • Utilize people, process and technology in order to build tightly integrated policy tooling into a broad set of security internal tooling.

Snowflake provides a platform called the AI Data Cloud that helps organizations manage and analyze their data. This platform allows users to store and process large amounts of data efficiently, offering services like data warehousing, data lakes, data engineering, data science, and data sharing. Snowflake's system works by uniting data from different sources, enabling secure sharing and performing various types of analytics. What sets Snowflake apart from its competitors is its ability to operate seamlessly across multiple public clouds, allowing users to access their data from anywhere. The company's goal is to help businesses leverage their data for better decision-making by providing a flexible subscription-based service that scales according to their needs.

Company Stage

IPO

Total Funding

$1.3B

Headquarters

Bellevue, Washington

Founded

2012

Growth & Insights
Headcount

6 month growth

1%

1 year growth

0%

2 year growth

2%
Simplify Jobs

Simplify's Take

What believers are saying

  • Acquisition of Datavolo enhances Snowflake's open data integration capabilities.
  • Investment in Metaplane boosts AI-driven data quality solutions for Snowflake users.
  • Snowflake Ventures' investment in Hex expands accessibility of data tools to non-technical users.

What critics are saying

  • Integration challenges from Datavolo acquisition may disrupt operations and customer service.
  • Increased competition from Mistral AI could challenge Snowflake's market position.
  • Convertible senior notes pricing may increase financial pressure if market conditions worsen.

What makes Snowflake unique

  • Snowflake offers a unified platform for diverse data workloads, unlike traditional solutions.
  • The AI Data Cloud enables near-unlimited scale and performance for data mobilization.
  • Snowflake's seamless multi-cloud experience ensures efficient data operations across locations.

Help us improve and share your feedback! Did you find this helpful?

Benefits

We've got your back - We offer comprehensive health insurance plans, health savings accounts, robust retirement plans, and generous life and disability insurance.

A Balanced Lifestyle - All Snowflakes have access to our weekly online lunch and learns, virtual workout classes, and ergonomic work-from-home equipment. We offer on-demand mental health and wellness programs to support our employees and their families.

Your People Matter - Help offset the cost of growing your family with our fertility benefits and family planning resources. Count on our generous time-off and various leave plans for you to rest, refuel, and sustain a great work-life balance.

Global Snowflake Team - No matter where you are in the world, we will get you connected and supported with a work-from-home setup.

Treat Yourself - Personalize your Snowflake benefits by tapping into our employee discounts and pre-tax selections.

Invest In Your Future - Eligible employees enjoy new hire equity, Employee Stock Purchase Plan (ESPP), and a quarterly bonus or commission program.

INACTIVE