What are the responsibilities and job description for the INFORMATION SECURITY GRC ANALYST position at Green Thumb?
The Role
We're looking for an Information Security Governance, Risk & Compliance Analyst to join our growing Information Security team. This role will be reporting to the Manager of Information Security Governance, Risk & Compliance. Our security team works to create a strong Information Security function within GTI that enables the business to continue its tremendous growth. The Information Security Governance, Risk & Compliance Analyst is responsible for maintaining continuous compliance with security policies, industry laws, and regulations (HIPAA, SOX, NIST, etc.). The candidate must communicate effectively with business partners and team members to help raise the level of security awareness, security compliance, and security risk. The candidate will perform environment-specific risk assessments factoring in both qualitative and quantitative risks and assist with the deployment of various controls based on those assessments. This role will also involve ongoing monitoring and improvement of security governance, ensuring a proactive approach to risk management.
This is a hybrid position and requires onsite work 1-2 days per week at our Rolling Meadows, IL office.
Responsibilities
- Own the relationship working with IT and business stakeholders to perform ongoing internal and vendor risk assessments, providing reporting to stakeholders, and ensuring appropriate action is taken.
- Update and track KPIs from the Information Security risk register and work with stakeholders on developing Corrective Action Plans to address risks.
- Provide guidance to newer staff working with internal IT stakeholders for vulnerability management, ensuring vulnerabilities are remediated in accordance with policy and SLAs.
- Own the process for working with IT and business stakeholders to perform ongoing compliance reviews in line with security policies, information security regulations (HIPAA, SOX / ITGC), and security frameworks (NIST, MITRE, etc.).
- Assist with ongoing internal operations and tasks, including ITGC security reviews.
- Spearhead the ongoing internal and external SOX and HIPAA audits and other security audits that are relevant to GTIs business.
- Provide updates and insight during the development and maintenance of Information Security policies, standards and procedures, aligning with NIST.
- Lead the identification of security training and awareness initiatives for the organization.
- Participate in incident response tabletops, business continuity tests, and other compliance activities and exercises.
- Maintain KPIs and KRIs for Information Security risk & compliance activities.
- Execute tasks as a member of the Information Security team as assigned by management.
- Provide mentorship and guidance to Associate Information Security GRC Analysts.
- Stay up to date on relevant laws and regulations to ensure continuous compliance and audit readiness.
- Collaborate with the IT and security teams in response to security incidents, ensuring proper documentation and reporting.
Qualifications
Additional Requirements
LI-HYBRID
The pay range is competitive and based on experience, qualifications, and / or location of the role. Positions may be eligible for a discretionary annual incentive program driven by organization and individual performance.
Green Thumb Pay Range
80,000 - $90,000 USD
Salary
80000 - $90000 USD per year
recblid v22lxgu7te474likam937by5gvdiv1
Salary : $80,000 - $90,000