Risk Management Analyst
Core
Provide security compliance support for production transaction processing environments, evaluate security control posture, and develop mitigation plans for risks and liabilities.
Role type
Senior IC information security compliance analyst
Builds
Compliance with PCI-DSS, ISO 27001, SOC 1 & SOC 2, and regional standards for payment card and transit systems
Domain
Financial services / Intelligent transportation systems
Deliverable
dashboards & analysis
Required skills
Security risk assessment methodology, audit operations coordination, compliance gap identification, remediation plan development, vendor contract review, stakeholder escalation management, GRC system utilization
Preferred skills
Deep understanding of security risks in operating environments, knowledge of Open Payments and Mobility as a Service
Technologies
OneTrust GRC, Microsoft Office, PCI-DSS 4, ISO 27001-2022, SOC I/II
Responsibilities
Perform as Subject Matter Expert on Security Risk Assessment methodology and processes; Facilitate security audit operations including scheduling and vendor coordination; Lead design and control reviews to support continuous compliance; Identify and report significant information security risks across applications, cloud, and infrastructure; Manage escalation of compliance gaps to stakeholders; Capture compliance gaps and remediation plans in the OneTrust GRC system; Review vendor contracts and SOC reports to evaluate impact on controls.
Seniority
Senior, hands-on IC with substantial decision-making authority