Global Cybersecurity Compliance Analyst
UL Solutions United Kingdom
Professional Services · 10,001+ employees
About the role
The analyst will identify, document, and conduct compliance assessments to validate the effectiveness of ISO, NIST, and TISAX requirements across the organization. They will also partner with IT and legal stakeholders to address control deficiencies and manage internal and external audit processes.
What they look for
Requirements
Candidates must hold a Bachelor's or Master's degree in a relevant field and possess at least two years of experience in cybersecurity compliance auditing and risk management. A strong understanding of information security frameworks and the ability to interpret operational risks are essential for this role.
Full description
The Global Cybersecurity Compliance Analyst will be responsible for identifying, analyzing, reporting, and ensuring security processes and controls are designed, managed, and assessed for effectiveness to reduce overall compliance risks across the organization. Specializing specifically in ISO, NIST and TISAX based assessments.
Responsibilities
- Identify, document, and conduct compliance assessments and validate the effectiveness of applicable ISO, NIST and TISAX requirements across the organization
- Communicates assessment issues to team owners and custodians of information risk “Business Partners,” or information governance teams and information security teams.
- Partner with IT teams and other key stakeholders (e.g., Legal), advising both on applicable control requirements and potential solutions to address compliance issues
- Identify control deficiencies and maintain records of deficiency details including management response documentation and exposure check evidence
- Stay abreast of and proactively informed on changes and revisions to ISO, NIST and TISAX frameworks
- Assists with the evaluation of the effectiveness of the information security program by developing, monitoring, gathering, and analyzing information security and compliance metrics for management.
- Assist with developing and maintaining compliance and risk monitoring mechanisms such as Key Risk Indicators (KRI), reports on status of risk assessment, control effectiveness issues remediation and internal audit findings
- Train ISMS managers on ISO compliance requirements and how to prepare and conduct ISO audits
- Coordinate with internal and external auditors and manage audit schedules
Qualifications
- BS or MA in Business, Computer Science, Information Security, or a related field
- [2+] years as a Certified Cybersecurity Compliance Auditor
- [2+] years of work experience in information security, especially in an information cybersecurity risk role
- [2+] years of experience in managing risk and compliance issues, or similar experience managing applications, projects or systems that require identification, evaluation, and remediation if risk
- Technical background or demonstrable understanding of a range of operational and IT risks and operations
- Strong business background; experience gathering and interpreting risks and associated impacts in the context of financial and operational concerns
- Strong understanding of compliance and risk-related issues through demonstrated experience managing, information security or regulatory compliance programs, and audits
- [4+] years of experience with regulatory compliance and information security management frameworks (e.g., International Organization for Standardization [IS0] 27000, COBIT, National Institute of Standards and Technology [NIST] 800)
Desired, but not required:
- Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), and/or Certified Information Systems Auditor (CISA)
What we offer:
Total Rewards: We understand that rewards are an important consideration as you plan the next step in your career. Salary range varies by location and local market conditions and is based on multiple factors, including job-related knowledge/skills, experience, geographical location, and other factors.
Disclaimer: This role is gender-neutral and open to all qualified applicants, regardless of gender identity or expression.
What you’ll experience working for ULS:
UL Solutions has been pioneering change since 1894 and we’re still leading the way. From day one, we’ve blazed a trail protecting the planet and everyone on it. Our teams have influenced billions of products, plus services, software offerings and more. We break things, burn things and blow things up. All in the name of safety science. Join UL Solutions to be at the center of safety. To learn more about us and the work we do, visit https://www.ul.com
#LI-Hybrid
Similar roles
-
Senior Account Executive, Public Relations (Cybersecurity)
Highwire Connecticut, United States
-
Staff Product Security Engineer, PSIRT
ServiceNow Hyderabad, Telangana, India
-
Senior Security Engineer
Capco London, England, United Kingdom
-
Principal Security Engineer
Capco London, England, United Kingdom
-
Senior Security Engineer
DAIWA CAPITAL MARKETS AMERICA INC New York, New York, United States · $160K–$190K/yr
-
Information Security Engineer
Peoples Bank Louisville, Kentucky, United States