Governance, Risk and Compliance Analyst

Sorry, this job was removed at 7:19 a.m. (EST) on Saturday, July 31, 2021
Find out who's hiring in Somerville.
See all Cybersecurity + IT jobs in Somerville
Easy Apply
By clicking Apply Now you agree to share your profile information with the hiring company.

Quality isn’t just a goal. It’s the whole point.

Our customers are under a lot of pressure to deliver great software. But to compress lifecycles, add features, and compete in a world where ‘every company is now a software company’ is hard. And one mistake can mean their reputation, even future. That’s why it’s our mission to help. At any part of their software development lifecycle (SDLC), we provide the tools and discipline to focus on quality while streamlining their processes. So our customers can create and deploy software that works as designed – especially when it’s needed most. And we’re looking for people to join us.

Governance, Risk and Compliance (GRC) Analyst

  • Ensures regulatory compliance enterprise wide
  • Has a full grasp of information security, cyber security, and privacy issues and awareness of regulated data environments
  • Supports and is involved in communication around internal and external audit
  • Creates policies and controls to ensure compliance

As an integral member of the Information Security team, reporting to the Director of Information Security, the responsibility of the GRC Analyst is to help support the day-to-day assurance operations related to policy compliance, process and organizational policies and security requirements governance, as well as risk management functions. You will be responsible for the collection and management of data from multiple systems to allow for proper reporting of the Information Security program effectiveness through risk analysis and trends. The ideal candidate will have knowledge of risk management, security and privacy practices and be an effective communicator, both written and verbal.

You will engage business personnel to ensure all requisite data and information is complete, accurate, and consistently delivered. You will use your experience and knowledge of security in working with a team to deliver on Governance, Risk and Compliance goals related to developing the complete perspective for operational and management visibility of overall compliance to the Information Security program, policies, and practices. You will be expected to establish and foster relationships with the various areas of the business to build rapport and be viewed as a trusted partner to help teams deliver on their commitment of compliance with security and privacy policies and regulations.

What you will be responsible for:

  • Implement the enterprise-wide strategy and key initiatives/projects focused on the reduction of technology risk, governance and compliance to policies and external regulatory compliance
  • Assist in the execution of departmental plans, including business, production and/or organizational priorities and contribute to the Governance, Risk and Compliance functional strategy
  • Work with IT and business teams to perform security and compliance assessments on new and existing systems, processes, and technology
  • Collaborate to define Information Security requirements and develop / update associated policies
  • Support internal and external audit processes for relevant compliance concerns
  • Participate in disaster recovery and business continuity planning and exercises, as appropriate
  • Perform periodic gap assessments to validate compliance on an ongoing basis
  • Tactically operate the systems for: risk register management, vendor and software risk assessments, incident-related risk logging and mitigation, data subject access request workflows and management, management for the configuration of cookie compliance, enterprise policy management, and data mapping
  • Assist with the education and awareness programs to promote and foster the delivery of systems and services with security and privacy controls built-in.

Qualifications:

  • 3+ years of relevant experience in the Information Security field with experience in the GRC area
  • Experience with information security ISMS such as NIST CSF and ISO27001, and CIS controls beneficial
  • Possess strong of comprehension of security and risk
  • Knowledge and experience with SOC2 and the Trust Service Criteria beneficial
  • Familiarity with eGRC tools
  • Knowledge and experience with diverse IT architectures and enterprise IT data centers, large-scale transaction processing environments, external hosted services and cloud computing environments
  • Experience working with security management tools (e.g., vulnerability scanners, file integrity monitoring, configuration monitoring, etc.) and perimeter technologies (e.g., router, firewalls, web proxies and intrusion prevention, etc.)
  • Knowledge of configuration management, change control/problem management integration, risk assessment and acceptance, exception management and security baselines (e.g. CIS Baselines, NIST, vendor security technical implementation guides, etc.)

Education and Certification Requirements:

  • Bachelor’s degree in Information Systems, Cybersecurity, or a related field
  • GRC related certifications are preferred: GRCP, GRCA
  • Privacy and risk related certifications are beneficial: CIPP, CIPT, CIPM, CERA, CRM

About SmartBear At SmartBear, we focus on your one priority that never changes: quality. We know delivering quality software over and over is complicated. So our tools are built to streamline your process while seamlessly working with the products you use – and will use. Whether it’s TestComplete, Swagger, Cucumber, ReadyAPI, Zephyr, or one of our other tools, we span from test automation, API lifecycle, collaboration, performance testing, test management, and more. Whichever you need, they’re easy to try, easy to buy, and easy to integrate. We’re used by 15 million developers, testers, and operations engineers at 24,000+ organizations – including world-renowned innovators like Adobe, JetBlue, FedEx, and Microsoft. Wherever you’re going, we’ll help you get there. Learn more at smartbear.com, or follow us on LinkedIn, Twitter, or Facebook.

SmartBear is an equal employment opportunity employer and encourages success based on our individual merits and abilities without regard to race, color, religion, gender, national origin, ancestry, mental or physical disability, marital status, military or veteran status, citizenship status, age, sexual orientation, gender identity or expression, genetic information, medical condition, sex, sex stereotyping, pregnancy (which includes pregnancy, childbirth, and medical conditions related to pregnancy, childbirth, or breastfeeding), or any other legally protected status. 

Read Full Job Description
Easy Apply
By clicking Apply Now you agree to share your profile information with the hiring company.

Technology we use

  • Engineering
  • Sales & Marketing
    • C#Languages
    • C++Languages
    • CSSLanguages
    • ElixirLanguages
    • JavaLanguages
    • JavascriptLanguages
    • PerlLanguages
    • PythonLanguages
    • RubyLanguages
    • SassLanguages
    • SqlLanguages
    • SwiftLanguages
    • BigQueryDatabases
    • Microsoft SQL ServerDatabases
    • MongoDBDatabases
    • MySQLDatabases
    • OracleDatabases
    • SnowflakeDatabases
    • AWS (Amazon Web Services)Services
    • GitHubServices
    • GitLabServices
    • Microsoft AzureServices
    • SalesforceCRM

Location

Our office in located in Assembly Row overlooking the beautiful Mystic River surrounded by shopping, dining, and entertainment. We're conveniently located steps from the Assembly MBTA Orange line stop.

An Insider's view of SmartBear

What’s the vibe like in the office?

I think the office space is great for people of all ages and tenures. It's a warm environment for everyone, but as a recent college graduate, it's nice being able to see others who are in my age bracket. The office is very open to conversation and is always willing to extend a helping hand. All in all, the vibes here are good!

Lesly Nerette

Account Executive I

What does your typical day look like?

My typical day-to-day varies! As a growing company, I'm always working on ad-hoc projects that are challenging and rewarding. Currently, the FP&A expense team is working on the 2024 plan, where we work closely with our business partners to plan and forecast expenses. It is my favorite time of the year because I get to know my business partners!

Kayla Bauerlein

Senior Financial Analyst

What makes someone successful on your team?

Although there are many ways, the first thought that comes to mind is someone driven for results, open to feedback, and having a growth mindset. The other way we measure our success is by delivering a quality candidate experience. Our team celebrates the different experiences and backgrounds we come from because we know it leads to better outcomes.

Allison Stone

Talent Acquisition Specialist

How do you empower your team to be more creative?

We give our teams autonomy and trust they will work to achieve their goals. We have a culture of transparency and clear company strategic initiatives. Also, a lot of the creativity happens in our hybrid work environment where we have in-office team days, great food, collaborative spaces and the right digital tooling to encourage group brainstorming

Cynthia Gumbert

Chief Marketing Officer

How do you empower your team to be more creative?

As a leader, I always empower my team to challenge me and debate a really good idea. I believe the voice of many outperform the voice of few. For me, it’s about fostering psychological safety, allowing time for free-thinking, fast failing, and more. It's most important to make space for creativity, remove barriers, nurture talent and communicate!

Stephanie Manzelli

VP, People Partners & Total Rewards

What are SmartBear Perks + Benefits

SmartBear Benefits Overview

SmartBear is proud to offer a comprehensive benefits package designed to serve the needs of our employees. Just a few of which include:

-Great office perks including: $75 fitness gear reimbursement, free catered lunches on Friday's, and cold brew on tap
-Health benefits that offer varying levels of coverage and accessibility through Blue Cross Blue Shield
-Company-Paid benefits that protect you and your family from financial hardship
-Voluntary benefits to provide you with added security (We even offer Pet Insurance!)
-Open vacation policy

Culture
Volunteer in local community
We've cleaned up the Mystic River, helped out at Rosie's Kitchen, and visted the YMCA
Partners with nonprofits
Open door policy
OKR operational model
Team based strategic planning
Open office floor plan
Employee resource groups
Day off for your birthday
Hybrid work model
In-person all-hands meetings
In-person revenue kickoff
Summer hours
President's club
Employee awards
Remote work program
Diversity
Documented equal pay policy
Dedicated diversity and inclusion staff
Highly diverse management team
Mandated unconscious bias training
Mean gender pay gap below 10%
Diversity employee resource groups
Hiring practices that promote diversity
Health Insurance & Wellness Benefits
Flexible Spending Account (FSA)
Disability insurance
Dental insurance
Vision insurance
Health insurance
Life insurance
Pet insurance
Wellness programs
Team workouts
Mental health benefits
Transgender health care benefits
Financial & Retirement
401(K)
401(K) matching
Company equity
Performance bonus
Charitable contribution matching
Child Care & Parental Leave Benefits
Childcare benefits
Family medical leave
Company sponsored family events
We have a Family Halloween Party every year!
Fertility benefits
Vacation & Time Off Benefits
Unlimited vacation policy
Paid volunteer time
Paid holidays
Paid sick days
Bereavement leave benefits
Office Perks
Commuter benefits
Company-sponsored outings
Free snacks and drinks
Some meals provided
Company-sponsored happy hours
Onsite office parking
Recreational clubs
Fitness stipend
Mother's room
Onsite gym
Professional Development Benefits
Job training & conferences
Lunch and learns
Promote from within
Mentorship program
Online course subscriptions available
Customized development tracks
Paid industry certifications
Budget for industry certifications is determined by departmental budget.

More Jobs at SmartBear

Easy Apply
By clicking Apply Now you agree to share your profile information with the hiring company.
Learn more about SmartBearFind similar jobs like this