Lead DI Security and Compliance Analyst
Core
Lead IT security and compliance analyst serving as a primary liaison for the CISO organization, executing second-line-of-defense control testing and risk assessments to ensure IT control effectiveness and audit readiness.
Role type
Lead DI Security and Compliance Analyst (Second Line of Defense)
Builds
Independent assurance on IT controls, standardized GRC tools, training programs, and audit readiness checklists.
Domain
Information Technology Security, IT General Controls (ITGC), SOX Compliance, Risk Management
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
IT General Controls (ITGC) design and testing, Risk assessment methodologies, Access management and identity governance, SOX 404 compliance and testing, Control framework knowledge (COSO, COBIT, NIST, ISO 27001), Audit lifecycle management
Preferred skills
Experience in second line of defense or internal audit, Hands-on experience with ITGC in SOX-regulated environments, Familiarity with enterprise IT environments (ERP, Cloud, Identity Governance), CISA/CISM/CISSP/CIA/CPA certifications
Technologies
SAP, Oracle, Workday, Salesforce, IFS Cloud, AWS, Azure, GCP, Identity Governance platforms
Responsibilities
Conduct annual and ad hoc IT risk assessments, Perform second-line-of-defense control testing across ITGC domains, Monitor effectiveness of first-line control self-assessments, Conduct periodic access recertification reviews, Identify trends in control failures and escalate systemic issues, Develop and maintain standardized GRC tools and training programs
Seniority
Senior, hands-on IC with leadership liaison duties