Risk Management Analyst
Core
Provide security compliance support for production transaction processing environments and evaluate security control posture to ensure adherence to organizational policies.
Role type
Senior IC information security compliance analyst
Builds
Compliance with PCI-DSS, ISO 27001, SOC 1 & SOC 2, and regional standards for fare and payment card services
Domain
Transportation technology / Payment card processing / Information security
Deliverable
dashboards & analysis (via careerplan.io/jobs/48883-1-risk-management-analyst-at-cubic)
Required skills
Security risk assessment methodology, audit facilitation, compliance gap identification, stakeholder management, remediation planning, contract review, OneTrust GRC system usage
Preferred skills
Deep understanding of security risks in operating environments, knowledge of Open Payments and Mobility as a Service
Technologies
OneTrust GRC, Microsoft Office, PCI-DSS 4, ISO 27001-2022, SOC I/II
Responsibilities
Perform as Subject Matter Expert on Security Risk Assessment methodology; Facilitate security audit operations and coordinate with internal/external auditors; Lead design and control reviews to support continuous compliance; Identify and report information security risks across applications, networking, and infrastructure; Manage security review processes for solutions to ensure compliance; Capture compliance gaps and remediation plans in OneTrust GRC system; Liaise with customers and security teams to build positive relationships; Support efforts to educate security management on compliant IT processes.
Seniority
Senior, hands-on IC