Strength in Trust OneTrust’s mission is to enable organizations to use data and AI responsibly. Our platform simplifies the collection of data with consent and preferences, automates the governance of data with integrated risk management across privacy, security, IT/tech, third-party, and AI risk, and activates the responsible use of data by applying and enforcing data policies across the entire data estate and lifecycle. OneTrust supports seamless collaboration between data teams and risk teams to drive rapid and trusted innovation. Recognized as a market pioneer and leader, OneTrust boasts over 300 patents and serves more than 14,000 customers globally, ranging from industry giants to small businesses.
OneTrust’s mission is to enable organizations to use data and AI responsibly. Our platform simplifies the collection of data with consent and preferences, automates the governance of data with integrated risk management across privacy, security, IT/tech, third-party, and AI risk, and activates the responsible use of data by applying and enforcing data policies across the entire data estate and lifecycle. OneTrust supports seamless collaboration between data teams and risk teams to drive rapid and trusted innovation. Recognized as a market pioneer and leader, OneTrust boasts over 300 patents and serves more than 14,000 customers globally, ranging from industry giants to small businesses.
We are looking for a dynamic Information Security GRC Analyst to support Information Security by performing various governance, risk, and compliance activities as part of the OneTrust InfoSec GRC team.
Security Risk Analyst is responsible for identifying, assessing, and mitigating risks related to the security of an organization's information systems and data. This role encompasses analyzing potential threats, developing strategies to protect against security breaches, and ensuring compliance with industry standards and regulations.
Key Responsibilities
Risk Assessment and Analysis: Conduct thorough risk assessments to identify vulnerabilities and potential threats to the organization's information systems. • Work within the OneTrust platform on a daily basis to monitor, track, document and analyze risks. • Be the technical Subject Matter Expert on the OneTrust ITSRM product (from implementation to maintenance) • Create repeatable metrics for OneTrusts risk posture
Reporting: Prepare detailed reports on security findings from risk assessments & audits that includes recommendations for improvements. • Collaborate with Information Security to establish reporting process for risks and exceptions
Security Audits: Perform regular security audits to ensure compliance with internal policies and external regulations.
Policy Development: Assist in the creation and maintenance of security policies, procedures, and protocols. • Support customer audits as needed • Support the overall ERM function A team player who can work well within the GRC team.
Critical Thinking: Ability to think critically and strategically about potential security threats and solutions.
Proactivity: Proactive approach to identifying and mitigating risks before they become issues.
Team Collaboration: Strong teamwork and collaboration skills to work effectively with cross-functional teams.
Adaptability: Ability to adapt to changing security landscapes and emerging threats.
Efficient: Facilitate and manage multiple questionnaires and due diligence activities simultaneously
Organized: Maintain a high level of organization to manage multiple tasks and projects effectively.
A Trusted Advisor: Serve as a reliable advisor to stakeholders, providing expert guidance on security matters.
A Relationship builder: Ability to listen, build rapport, and credibility as a partner vertically and horizontally
A Technical Innovator: Possess the ability to become a technical SME in the OneTrust platform and create and manage your own assessments and workflows.