Security Compliance Analyst | Salt Lake, UT

Detailed Information

  • Location: Salt Lake City, UT

  • Company: Sorenson Communications

of security controls for compliance with applicable information security laws, regulations, and policies. Identifies, analyzes, evaluates, and documents information security risks and controls based on established risk criteria. Develop and conduct comprehensive audit plans including backssing the effectiveness of controls and identifying areas for improvement.

Ensures key security controls are identified, implemented, tested, and remediated as required. Evaluate Sorensons compliance with relevant cybersecurity frameworks and standards (e. g. NIST, ISO 27001, HIPAA, Fed Ramp, SOC 2) Maintain detailed and accurate audit documentation, including findings, recommendations, and corrective

action plans. Governance Creates roadmaps, data visualizatoins, dashboards and facilitates metrics selection and reporting. Prepare reports and other deliverables that contain technical analysis, findings and recommendations.

Researches, recommends, and contributes to information security polices, standards, and procedures. Assists with the lifecycle management of information security policies and supporting documents. Executes and documents control mapping and performs control maintenance in company GRC. Evaluates and advises on security control recommendations to mitigate information security risks. Scopes and supports the execution of targeted and enterprise-wide information security

risk backssments, including reporting. Develops and implements strategies to mitigate risks effectively.

Works with business partners, enterprise risk management, IT Risk, Product & Data Security, and outside consultants on required information security risk backssments and audits. Communicates risk findings and recommendations that are clear and actionable by business stakeholders. Project Management and Requirements Analysis Plans and manages small to medium size projects using both waterfall and agile methodologies Creates and utilizes lightweight project management tools and artifacts including RASCI and RAID. Conducts requirements gathering, documents requirements analysis, and generates reports Specialty Assignments ISO 27001 mapping, gap analysis, scoping, control design and evaluation, and journey to certification Fed Ramp gap analysis, scoping, control design, implementation and journey to certification.

Knowledge, Skills, and Abilities Ability to write solution workflow diagrams, system documentation, playbooks, etc. Strong analytical skills Excellent written and verbal communications skills, including presentational skills Ability to work with others in both individual and team settings. Come be a part of our mission and make a meaningful and positive impact with the industry leading provider of language services for the Deaf and heard-of-hearing!

Benefits Paid Vacation Time and Paid Sick Time and Paid Holidays 401k 6% match with immediate vesting Nationwide Medical Insurance plans and coverage (Medical, Dental/Orthodontia, Vision) Tele Doc HSA company match 3 Medical plan options including a Low Deductible PPO Medical Plan Offering Employee Assistance Program Engaged Employee Resource Groups Outstanding Learning and Career Development Opportunities Pay Range: Actual pay may vary up or down depending on job-related factors which may include knowledge, skills, experience, and location.

In addition, this position may be eligible for incentive compensation. Company Summary Our Mission.Harnessing the power of language, we connect diverse people and enrich the human experience. Our Vision.To provide global language services that expand opportunities, nurture belonging, and empower the world to connect beyond words. As one of the world's leading language services providers, Sorenson combines patented technology with human-centric solutions. We strive to increase diversity, equity, inclusion, and accessibility for underrepresented people through communication solutions for all: call captioning and video relay services, over-video and in-person sign language and spoken language interpreting, translation, real-time captioning, and post-production language services.

Sorenson's impact vision and plan extends to supporting employment opportunities for diverse employees, customers, and communities. As a minority-owned company, we are committed to expanding opportunities for underserved communities while promoting an inclusive workplace for our own employees. Equal Employment Opportunity: Sorenson Communications is an Equal Opportunity, Affirmative Action Employer.

Equal Opportunity Employer/Protected Veterans/Individuals with Disabilities The contractor will not discharge or in any other manner discriminate against employees or applicants because they have inquired about, discussed, or disclosed their own pay or the pay of another employee or applicant. However, employees who have access to the compensation information of other employees or applicants as a part of their essential job functions cannot disclose the pay of other employees or applicants to individuals who do not otherwise have access to compensation information, unless the disclosure is (a) in response to a formal complaint or charge, (b) in furtherance of an investigation, proceeding, hearing, or action, including an investigation conducted by the employer, or (c) consistent with the contractor's legal duty to furnish information.

41 CFR 60-1.35(c) Behavior Detail Oriented: Capable of carrying out a given task with all details necessary to get the task done well Skills Builds Relationships Novice Work Experience 5 years: Experience in Information Security with combinations in operational security, risk management, testing and QA, IT, compliance and audit 3 years: Experience specific to Security Risk Management and Compliance programs, project management, gap analysis, and business process improvement.

Proven experience in conducting compliance audits Education Required: Bachelors PDN-9ad5be65-c04f-42e1-a1a0-54ca61886345

View Jobs by Category >>

Related Jobs