Mondelēz International
Sr Analyst, Governance, Risk & Compliance (GRC), Information Security
Be an Early Applicant
This role involves managing risk assessments for third parties and internal technologies, performing compliance activities, and maintaining risk and control registers.
Job Description
Are You Ready to Make It Happen at Mondelēz International?
Join our Mission to Lead the Future of Snacking. Make It Uniquely Yours.
As an individual contributor, the successful candidate will be proficient at managing risk assessments of both third parties and internal technologies. In addition, the candidate will be performing compliance activities related to technology assurance areas around access management, vulnerability management and configuration management. Candidate will also demonstrate ability and experience in governance related activities including administrative management of risk and control registers as well as policies and standards.
How you will contribute
Risk Management Responsibilities
Compliance Responsibilities
Requirements
Business Unit Summary
At Mondelēz International, our purpose is to empower people to snack right by offering the right snack, for the right moment, made the right way. That means delivering a broad range of delicious, high-quality snacks that nourish life's moments, made with sustainable ingredients and packaging that consumers can feel good about.
We have a rich portfolio of strong brands globally and locally including many household names such as Oreo, belVita and LU biscuits; Cadbury Dairy Milk, Milka and Toblerone chocolate; Sour Patch Kids candy and Trident gum. We are proud to hold the top position globally in biscuits, chocolate and candy and the second top position in gum.
Our 80,000 makers and bakers are located in more than 80 countries and we sell our products in over 150 countries around the world. Our people are energized for growth and critical to us living our purpose and values. We are a diverse community that can make things happen-and happen fast.
Mondelēz International is an equal opportunity employer and all qualified applicants will receive consideration for employment without regard to race, color, religion, gender, sexual orientation or preference, gender identity, national origin, disability status, protected veteran status, or any other characteristic protected by law.
Job Type
Regular
Information Security
Technology & Digital
Are You Ready to Make It Happen at Mondelēz International?
Join our Mission to Lead the Future of Snacking. Make It Uniquely Yours.
As an individual contributor, the successful candidate will be proficient at managing risk assessments of both third parties and internal technologies. In addition, the candidate will be performing compliance activities related to technology assurance areas around access management, vulnerability management and configuration management. Candidate will also demonstrate ability and experience in governance related activities including administrative management of risk and control registers as well as policies and standards.
How you will contribute
Risk Management Responsibilities
- Execute risk assessment testing supporting the Risk Manager.
- Document risk assessment results.
- Support Risk Manager in drafting risk assessment reports.
- Perform administrative management of risk register (additions/editions/deletions, etc).
- Document risk acceptance/exemptions that have been approved per the program.
- Manage quarterly/annual review of risk acceptance/exceptions.
- Manage risk assessment results in relevant dashboards.
- Document Issues and Remediation activities for all exceptions noted during risk assessments.
Compliance Responsibilities
- Perform quarterly compliance assurance testing.
- Document compliance testing results.
- Maintain Management Action Plan (MAP) catalog with due dates.
- Manage monthly audit MAPs. Includes the timely communication of open MAPs an escalation as needed of risks to completing MAPs at their agreed delivery dates.
- Perform administrative activities in GRC Solution for compliance related activities.
- Provide administrative support for ad-hoc external audits.
- Provide administrative support for internal audits.
- Support compliance program reporting activities.
Requirements
- 3 years in Information Security field, with at least 2 years working in GRC.
- Experience with GRC tools (e.g., Archer).
- Knowledge of security concepts and methodologies such as risk assessments, risk & controls, policies & standards, enterprise security strategies, network, and cloud security.
- Knowledge of security frameworks such as CIS and NIST.
- Excellent written and verbal communications skills, including presentational skills and able to clearly communicate issues to management and other key stakeholders.
Business Unit Summary
At Mondelēz International, our purpose is to empower people to snack right by offering the right snack, for the right moment, made the right way. That means delivering a broad range of delicious, high-quality snacks that nourish life's moments, made with sustainable ingredients and packaging that consumers can feel good about.
We have a rich portfolio of strong brands globally and locally including many household names such as Oreo, belVita and LU biscuits; Cadbury Dairy Milk, Milka and Toblerone chocolate; Sour Patch Kids candy and Trident gum. We are proud to hold the top position globally in biscuits, chocolate and candy and the second top position in gum.
Our 80,000 makers and bakers are located in more than 80 countries and we sell our products in over 150 countries around the world. Our people are energized for growth and critical to us living our purpose and values. We are a diverse community that can make things happen-and happen fast.
Mondelēz International is an equal opportunity employer and all qualified applicants will receive consideration for employment without regard to race, color, religion, gender, sexual orientation or preference, gender identity, national origin, disability status, protected veteran status, or any other characteristic protected by law.
Job Type
Regular
Information Security
Technology & Digital
Top Skills
Archer
Cis
Grc Tools
Nist
Similar Jobs at Mondelēz International
Big Data • Food • Hardware • Machine Learning • Retail • Automation • Manufacturing
As a Global Consumer Website Technical Analyst, you'll provide expertise in web technologies, overseeing governance, resolving complex issues, and facilitating web projects and processes.
Top Skills:
ContentfulGa/GtmGcp Cloud ServicesGoogle AnalyticsNode.jsOnetrustReact
Big Data • Food • Hardware • Machine Learning • Retail • Automation • Manufacturing
The role involves assessing information security risks, implementing cyber security technologies, managing compliance, and providing training to teams.
Top Skills:
Cyber Security TechnologyInformation Security ComplianceIt Asset SecuritySecurity Solutions
3 Days Ago
Big Data • Food • Hardware • Machine Learning • Retail • Automation • Manufacturing
Lead packaging design and deployment projects in a cross-functional team, ensuring specifications meets manufacturing requirements while influencing stakeholders and managing resources.
Top Skills:
Equipment DesignGood Manufacturing PracticesHaccpPackaging DesignSamplingSupplier Management
What you need to know about the Boston Tech Scene
Boston is a powerhouse for technology innovation thanks to world-class research universities like MIT and Harvard and a robust pipeline of venture capital investment. Host to the first telephone call and one of the first general-purpose computers ever put into use, Boston is now a hub for biotechnology, robotics and artificial intelligence — though it’s also home to several B2B software giants. So it’s no surprise that the city consistently ranks among the greatest startup ecosystems in the world.
Key Facts About Boston Tech
- Number of Tech Workers: 269,000; 9.4% of overall workforce (2024 CompTIA survey)
- Major Tech Employers: Thermo Fisher Scientific, Toast, Klaviyo, HubSpot, DraftKings
- Key Industries: Artificial intelligence, biotechnology, robotics, software, aerospace
- Funding Landscape: $15.7 billion in venture capital funding in 2024 (Pitchbook)
- Notable Investors: Summit Partners, Volition Capital, Bain Capital Ventures, MassVentures, Highland Capital Partners
- Research Centers and Universities: MIT, Harvard University, Boston College, Tufts University, Boston University, Northeastern University, Smithsonian Astrophysical Observatory, National Bureau of Economic Research, Broad Institute, Lowell Center for Space Science & Technology, National Emerging Infectious Diseases Laboratories

