Senior GRC Analyst Job at Black & Veatch Family of Companies, Overland Park, KS

YkdYWXE2RVFIVHBQemV3ZFFRd0xzY05kNkE9PQ==
  • Black & Veatch Family of Companies
  • Overland Park, KS

Job Description

Overview

The Sr. Analyst, Governance, Risk, and Compliance (GRC) plays an important role in the GRC delivery framework, ensuring Black & Veatch’s compliance with contractual and regulatory requirements, assessing control design and operation against common standards and frameworks, and assisting with third-party/supply chain risk management. The candidate will also promote a culture of risk awareness across the enterprise among other responsibilities. With an emphasis on cyber, contract and regulatory compliance risk management, the ideal candidate should be able to contribute to measuring success and identifying improvement opportunities and capabilities development in these areas.

This role is ideal for a detail-oriented professional with a passion for cyber and compliance risk management who is comfortable operating independently. Independent and critical thinking is absolutely necessary to be successful in this role as is a desire to drive efficiencies in function delivery and day-to-day tasks.

Key Responsibilities

  • Proven experience reviewing client contract provisions related to data security, breach reporting, cyber resilience, and compliance certifications and measuring compliance in IT and security architecture and operations.
  • Support independent certification and audit by working with D&IT peer groups and lines of business to collect documentation and evidence of security policies and operations
  • Request and review documentation and evidence from control owners to certify and validate compliance to standards and industry-accepted best practice
  • Monitor regulatory and legal landscape at a global scale and across market sectors and maintain awareness of compliance requirements
  • Act as an informed voice in development of policy and ensure alignment with regulatory, legal, and contractual requirements
  • Assist establishment and enforcement of standards of practice documentation to be referenced by architecture and operations teams
  • Contribute process and subject matter expertise in governance forums and cross-functional committees
  • Collaborate with peer D&IT groups to collect KPI’s, KRI’s and drive efficiency through automation and other means
  • Contribute subject matter expertise through third party risk assessment process
  • Identify and communicate risk of vendor engagements and mitigation actions to business owners and D&IT stakeholders
  • Assist review of client security requirements in contracts and aggregate relevant clauses to inform contractual risk
  • Assist development of user training aligned with cyber threat landscape, establish and implement metrics, and propose enhancements

Preferred Qualifications

  • Strong analytical, organizational, and communication skills
  • Professional certifications such as CRISC, CISSP or others
  • Experience with ServiceNow Risk Management platform
  • Knowledge of FAR, DFARS, CMMC
  • Experience with GRC platforms and risk management methodologies
  • Ability to work independently and collaboratively as required

Minimum Qualifications

  • Bachelor’s degree in information systems, Information Security, or a related field
  • 7–10 years of experience in GRC executing or auditing against standards, frameworks, and industry regulations
  • Demonstrated experience supporting GRC functions for global companies
  • Solid proficiency in risk assessment methodologies and frameworks
  • Proven ability to assess alignment of internal policy, process, control design and operations, and cyber risk management with regulatory standards and frameworks
  • Strong collaboration with IT teams
  • Familiarity with industry standards and frameworks (e.g., NIST CSF and supporting SP’s, ISO 27001, AICPA SOC)
  • Working knowledge of cyber and privacy laws and regulations
  • Solid understanding of information security principles and concepts
  • Strong desire to create task and functional efficiencies through use of technology and tools, especially GenAI

Job Tags

Contract work

Similar Jobs

Optimum Oral Surgery

Oral Surgery Dental Assistant Job at Optimum Oral Surgery

: Step into the dynamic world of oral surgery as an Oral Surgeon Surgical Assistant! Your role is pivotal, aiding surgeons with precision during procedures and meticulously documenting patient care. From preoperative tasks to maintaining sterile environments, your expertise... 

BAYADA Home Health Care

Registered Nurse, RN - Weekend Visits Job at BAYADA Home Health Care

 ...Home Health Registered Nurse - Visiting RN Per Diem - Part Time - Full Time(Saturday Availability Required) BAYADA Home Health Care is looking for compassionate and dedicated Registered Nurses, RN to join our North Boston Visits team and work with clients on... 

Saalex

Junior Program Financial Analyst Job at Saalex

 ...Saalex is seeking a Junior Program Financial Analyst in Corona, CA. Saalex is an Engineering and Information Technology Services company with a focus on Test Range Operations and Management, Engineering and Logistics Services, Data Analytics and Business Intelligence... 

Mason Frank International

Salesforce Administrator Job at Mason Frank International

 ...We are seeking a knowledgeable Sys Admin with experience in Salesforce technologies to enhance and support our application landscape. In this remote role, you will be pivotal in ensuring smooth operation and configuration of CPQ, Sales Cloud, and OmniStudio, ultimately... 

Housley Communications

AERIAL LINEMAN Job at Housley Communications

Position summary: Class A CDL and Medical Card preferred. Capable of working independently or as a part of a crew to perform all types of Outside Plant Aerial Construction and Maintenance/Repair work. Must have the necessary skills and work experience to perform...