Go Back   Wireless and Wifi Forums > News > Newsgroups > alt.computer.security
Register FAQ Forum Rules Members List Calendar Search Today's Posts Advertise Mark Forums Read

 
Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 10-25-2010, 01:50 PM
TOM
Guest
 
Posts: n/a
Default IT Security, Risk & Compliance Analyst

Tom Gugger
Independent Recruiter
tgugger@bex.net

This is a career position with an established profitable company. They
are a leader in their industry and continue to grow even in this
economy. The company is located in the greater Fort Wayne, Indiana
area.

If interested and qualified, email resume to tgugger@bex.net. Make
sure your resume reflects your experience with SOX, PCI, and other
needed or highly desired skills.


IT Security, Risk, and Compliance Analyst
FUNCTION
Responsible for providing IT and security governance and support for
the entire organization, focusing on all aspects of data compliance,
with particular emphasis on Sarbanes Oxley (SOX), PCI, and other
industry and regulatory compliance requirements. Work closely with the
functional business leaders, Sr. IT Director and Infrastructure
Manager to manage the balance between business needs and corporate
standards.
ESSENTIAL DUTIES &RESPONSIBILITIES (Note: Other duties may be
assigned)
• Lead the development, implementation and maintenance of a Risk
Assessment model.
• Assist with the development and implementation of information
classification and control policies and procedures.
• Remain current with changes in the information resources security
legislation and regulation.
• Develop, implement and maintain an annual Risk Assessment review of
information systems.
• Conduct periodic reviews of information security policies,
procedures, and compliance. Prepare reports of findings for review by
Management.
• Assist various business units to implement and maintain information
resources security.
• Conduct periodic audits of various applications and systems to
ensure information security processes and procedures are effective.
Develop and distribute reports that include findings and recommended
remediation steps.
• Assist with the investigation, documentation, and response to all
suspected information security events.
EDUCATION AND/OR EXPERIENCE
• Bachelor of Science in Information Systems/MIS, computer science,
business or related field or equivalent experience
• 3+ years experience administering and supporting IT security, risk
and compliance program(s)
• Experience with Sarbanes-Oxley section 404 compliance
implementation and monitoring required
• Experience in developing policies, procedures, technical
configuration standards and guidelines
• Experience in developing and implementing compliance monitoring
processes and procedures
• Experience with formal project planning and risk assessment
methodologies
• Experience conducting risk assessments and system/application
reviews
• Experience preparing management reports, remediation plans, and
related planning documents
• Experience with Payment Card Industry Data Security Standard (PCI-
DSS) implementation and monitoring preferred
• CISSP or CISA certification preferred
KNOWLEDGE, SKILLS, AND ABILITIES
• Extensive knowledge of IT security and compliance standards and
regulations
• Ability to build and maintain good rapport with internal and
external customers and handle situations with confidence, tact and
resourcefulness
• Strong project management skills
• Strong written and oral communication skills



Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
Issue 18 of The ISO 27000 Newsletter Released Sue Thomas alt.computer.security 0 05-15-2008 06:59 PM
Doctor Who's security & encryption FAQ v21.4 newsmanis@yahoo.com.au alt.computer.security 0 10-10-2007 09:34 PM
ISO 27001 and ISO 27002 Newsletter: Issue 16 Published Sue Thomas comp.security.misc 0 10-09-2007 09:47 AM
SSRT5954 rev.4 - HP-UX TCP/IP Remote Denial of Service (DoS) Security Alert comp.security.misc 0 07-12-2005 11:27 AM


All times are GMT. The time now is 01:57 AM.



Powered by vBulletin® Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.6.0 PL2

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45