Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy
Jobs / Job page
Senior Information Security Analyst (Compliance) image - Rise Careers
Job details

Senior Information Security Analyst (Compliance)

Granicus is driven by the excitement of building, implementing, and maintaining technology that is transforming the Govtech industry by bringing governments and its constituents together. We are on a mission to support our customers with meeting the needs of their communities and implementing our technology in ways that are equitable and inclusive. Granicus has consistently appeared on the GovTech 100 list over the past 5 years and has been recognized as the best companies to work on BuiltIn.  


Over the last 25 years, we have served 5,500 federal, state, and local government agencies and more than 300 million citizen subscribers power an unmatched Subscriber Network that use our digital solutions to make the world a better place. With comprehensive cloud-based solutions for communications, government website design, meeting and agenda management software, records management, and digital services, Granicus empowers stronger relationships between government and residents across the U.S., U.K., Australia, New Zealand, and Canada. By simplifying interactions with residents, while disseminating critical information, Granicus brings governments closer to the people they serve—driving meaningful change for communities around the globe. 


Want to know more? See more of what we do here.


Granicus is looking for NetSuite Administrator to configure, maintain, and optimize Granicus’s NetSuite Application. As the administrator, it will be critical to understand Granicus’ business process and accounting practices to provide options to improve and support growth, while balancing the cost effectiveness and efficiency of the NetSuite instance.

 


Job description
  • We are looking for an experienced Senior Information Security Analyst with experience managing multiple audit frameworks, such as ISO 27001, SOC 2, PCI, FedRAMP, TxRAMP, and others. You will be part of the information security and compliance team and report to the Senior manager, Information Security. Your role will have a focus on compliance audits, control mapping, and analysis of compliance requirements. Your expertise will lend itself to identifying control gaps, collaborating with control owners to identify remediation paths, assessing risks, and providing analysis of control requirements. 
  • In this role, you will:
  • Manage external compliance audits, including for FedRAMP, TxRAMP, ISO 27001, SOC 2, HIPAA, FISMA, CJIS, PCI, and Cyber Essentials. This includes internal audit preparation, evidence review and submission, coordinating audit schedules, and managing audit deliverables. 
  • Centralize and manage audit runbooks, including evidence runbooks. Build audit runbooks. 
  • Track audit findings and resolution.
  • Lead audit retrospections to identify improvement opportunities, address challenges, and highlight success points. 
  • Identify and communicate control gaps, provide analysis of compliance requirements, evaluate remediation plans, and track through resolution. 
  • Build and maintain relationships with external auditors and control owners.
  • Provide guidance to control owners. Work with control owners to identify opportunities to improve control implementation and scalability. 
  • Partner with product teams and control owners; provide guidance on compliance requirements for planned changes.
  • Participate in change control review meetings to provide Security feedback and decisions. 
  • Manage security projects geared towards improvement of the ISMS, compliance audits, and security resources for internal stakeholders. 
  • Assist as security SME for support request escalations.
  • Respond to customer questions, including to provide customer-facing responses and maintain a security answer library. 
  • Review and update security training content at least annually. 


We are looking for:
  • 7+ years in information security and compliance 
  • Direct experience leading third party cloud security audits, such as ISO 27001, SOC 2 Type II, FedRAMP, StateRAMP, TxRAMP
  • Knowledge of common security frameworks, such as NIST 800-53, ISO 27001, PCI, HIPAA, SOC 2, and/or Cyber Essentials
  • Understand nuances between different audit frameworks in order to educate and support internal control owners, prepare for audits, and manage the audit process
  • Experience documenting company security policies and procedures
  • Strong communication skills, written and verbal
  • Program management experience for multiple compliance frameworks
  • Experience working with a robust product set, including software and cloud services
  • Ability to work with technical teams and non-technical teams
  • Familiarity with AWS, Azure, and/or GCP cloud security and infrastructure
  • Relevant security certifications are a plus, such as CISSP, CISM, CISA, CRISC, or equivalent. 


Security Requirement
  • Responsible for Granicus information security by appropriately preserving the Confidentiality, Integrity, and Availability (CIA) of Granicus information assets in accordance with the company's information security program.


CLOSING FROM DEFAULT - ALL LOCATIONS


Don’t have all the skills/experience mentioned above? At Granicus, we are trying to build diverse, inclusive teams. We do not have degree requirements for most of our roles. If you don’t meet every requirement above but are excited to learn more, we encourage you to apply. We might just be able to find another role that could be a perfect fit! 


The Team

- We are a remote-first company with a globally distributed workforce across the United States, Canada, United Kingdom, India, Armenia, Australia, and New Zealand.


The Culture

- At Granicus, we are building a transparent, inclusive, and safe space for everyone who wants to be

a part of our journey.

- A few culture highlights include – Employee Resource Groups to encourage diverse voices

- Coffee with Mark sessions – Our employees get to interact with our CEO on very important and

sometimes difficult issues ranging from mental health to work-life balance and current affairs. 

- Microsoft Teams communities focused on wellness, art, furbabies, family, parenting, and more.-=- - We bring in special guests from time to time to discuss issues that impact our employee

population 


The Impact

- We are proud to serve dynamic organizations around the globe that use our digital solutions to make the world a better place — quite literally. We have so many powerful success stories that illustrate how our solutions are impacting the world. See more of our impact here.


Granicus is committed to providing equal employment opportunities. All qualified applicants and employees will be considered for employment and advancement without regard to race, color, religion, creed, national origin, ancestry, sex, gender, gender identity, gender expression, physical or mental disability, age, genetic information, sexual or affectional orientation, marital status, status regarding public assistance, familial status, military or veteran status or any other status protected by applicable law.

Granicus Glassdoor Company Review
3.5 Glassdoor star iconGlassdoor star iconGlassdoor star icon Glassdoor star icon Glassdoor star icon
Granicus DE&I Review
No rating Glassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star icon
CEO of Granicus
Granicus CEO photo
Mark Hynes
Approve of CEO

Average salary estimate

$125000 / YEARLY (est.)
min
max
$100000K
$150000K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

What You Should Know About Senior Information Security Analyst (Compliance), Granicus

Join Granicus as a Senior Information Security Analyst (Compliance) and become a pivotal part of our mission to connect governments with their communities through innovative technology. Based in the vibrant city of Bengaluru, you'll work within our dedicated information security and compliance team, focusing on a range of compliance audits, including ISO 27001, SOC 2, and FedRAMP. Your expertise will be crucial in managing external audits, tracking findings, and providing insightful analysis for compliance requirements. You'll have the opportunity to collaborate closely with control owners and product teams, helping to strengthen our security posture and improve control implementations. Your role will also include building audit runbooks and engaging with auditors to ensure we maintain our high standards. With at least 7 years of experience in information security and compliance, you're familiar with various audit frameworks and possess strong communication skills. At Granicus, we pride ourselves on fostering diversity and inclusivity in our workforce. Join us and play a significant role in shaping secure, effective governance solutions for our clients worldwide. If you're passionate about security and compliance, let’s connect and see how you can make an impact with us at Granicus!

Frequently Asked Questions (FAQs) for Senior Information Security Analyst (Compliance) Role at Granicus
What are the key responsibilities of a Senior Information Security Analyst (Compliance) at Granicus?

As a Senior Information Security Analyst (Compliance) at Granicus, your primary responsibilities include managing external compliance audits such as FedRAMP, SOC 2, and ISO 27001. You'll prepare for audits, review evidence, coordinate schedules, and oversee audit deliverables. Additionally, you will centralize and manage audit runbooks, track findings, offer guidance to control owners, and ensure compliance with various standards.

Join Rise to see the full answer
What qualifications are required for the Senior Information Security Analyst (Compliance) position at Granicus?

To qualify for the Senior Information Security Analyst (Compliance) role at Granicus, candidates should possess 7+ years of experience in information security and compliance. Familiarity with audit frameworks like ISO 27001, SOC 2, and FedRAMP is essential. Strong communication skills and the ability to work with technical and non-technical teams are also key. Relevant certifications like CISSP or CISM are a plus.

Join Rise to see the full answer
What is the work culture like at Granicus for the Senior Information Security Analyst (Compliance)?

At Granicus, the culture is centered around transparency, inclusion, and support. As a Senior Information Security Analyst (Compliance), you will be part of a remote-first team that's distributed globally. The company values diverse voices through Employee Resource Groups and fosters dialogue between employees and leadership, creating a safe space to discuss important issues.

Join Rise to see the full answer
How does Granicus support professional growth for Senior Information Security Analysts (Compliance)?

Granicus is committed to fostering professional growth for its employees, including Senior Information Security Analysts (Compliance). Through mentorship opportunities, access to training materials, and engagement with various teams, you can expect a continuous learning environment that encourages you to sharpen your technical skills and advance your knowledge in information security.

Join Rise to see the full answer
What types of projects will a Senior Information Security Analyst (Compliance) at Granicus work on?

As a Senior Information Security Analyst (Compliance) at Granicus, you will manage security projects aimed at improving the Information Security Management System (ISMS) and enhancing compliance audit processes. You will also have the chance to engage with product teams to provide insights on how security requirements impact planned changes, ensuring that our solutions remain secure and compliant.

Join Rise to see the full answer
Common Interview Questions for Senior Information Security Analyst (Compliance)
Can you explain your experience with compliance audits, particularly in relation to ISO 27001 and SOC 2?

When answering this question, focus on specific experiences you’ve had in preparing and managing compliance audits. Discuss your role in previous audits, the challenges you faced, and how you overcame them. Highlight your understanding of both ISO 27001 and SOC 2 requirements and any specific contributions you made that resulted in successful audit outcomes.

Join Rise to see the full answer
How do you handle control gaps during audits?

Describe your process for identifying control gaps, documenting them, and working collaboratively with control owners to develop remediation plans. Share examples of past experiences where you successfully addressed control gaps, ensuring that you demonstrate your analytical skills and your ability to work as part of a team.

Join Rise to see the full answer
What strategies do you use to maintain relationships with external auditors?

In your response, emphasize the importance of communication in maintaining relationships. Discuss your approach to prompt responses, setting a positive tone in interactions, and providing necessary documentation ahead of time. Share any specific feedback or strategies that led to successful collaborations in previous roles.

Join Rise to see the full answer
How do you prioritize multiple compliance projects at the same time?

It's important to demonstrate your project management skills when answering this question. Discuss methods you've employed to prioritize tasks, such as risk assessment, deadlines, and resource availability. Provide real-life examples to illustrate your ability to handle multiple projects and how you maintained quality and compliance standards in a busy environment.

Join Rise to see the full answer
What is your approach to training and educating team members about compliance requirements?

Explain your philosophy on continuous education and how you develop training materials. Talk about previous experiences where you created or delivered training on compliance topics, making sure to emphasize the feedback received from participants and any improvements in compliance awareness as a result.

Join Rise to see the full answer
Describe a situation where you had to communicate complex security requirements to non-technical stakeholders.

Share a specific example that demonstrates your ability to tailor your communication style to your audience. Discuss the steps you took to ensure understanding and minimize jargon, as well as the successful outcome of your efforts, such as gaining stakeholder buy-in or successfully implementing necessary changes.

Join Rise to see the full answer
What metrics do you use to assess the effectiveness of compliance controls?

In your response, discuss specific metrics you’ve utilized to evaluate compliance controls, such as audit success rates, risk assessment scores, or incident response times. Highlight any continuous improvement processes you’ve adopted based on these metrics to bolster your overall compliance strategy.

Join Rise to see the full answer
How do you stay updated on changes in compliance regulations and standards?

Talk about your commitment to ongoing education. Mention attending industry conferences, participating in webinars, and subscribing to relevant publications. Emphasize how you integrate new information into your compliance strategies and share it with your team.

Join Rise to see the full answer
In your opinion, what are the biggest challenges facing information security compliance today?

Provide insights into current trends impacting the industry, such as the rise in cyber threats or evolving regulations. Discuss how your experience has prepared you to address these challenges, and be ready to share thoughts on the importance of adaptability in a constantly changing landscape.

Join Rise to see the full answer
What would you do if you discovered non-compliance in your organization’s practices?

Share a well-thought-out response that illustrates not only your commitment to compliance but also your problem-solving capabilities. Explain the steps you would take to assess the scope of non-compliance, engage with relevant teams, and formulate a plan to rectify the issue while maintaining transparency throughout the process.

Join Rise to see the full answer
Similar Jobs
Photo of the Rise User
Posted 8 days ago
Photo of the Rise User
Posted 6 days ago
Photo of the Rise User
Wipro Hybrid Louisville, KY
Posted 1 hour ago
Photo of the Rise User
Ramboll Remote Unit No. B802, 8th Floor, Tower B, Commerzone IT Park, Door No. 111, Mount Poonamallee Road, Porur Chennai- 600116 India, Chennai, India, Chennai, India
Posted 3 days ago
Photo of the Rise User
AECOM Remote Birmingham, United Kingdom
Posted 42 minutes ago
Photo of the Rise User
Bosch Group Remote Składowa 35, 90-127 Łódź, Poland
Posted 3 days ago

Granicus is a leading provider of a platform of solutions that make digital government possible to more than 6,000 government agencies, including 850 state departments across the U.S., U.K., Australia, New Zealand, and Canada.

136 jobs
MATCH
Calculating your matching score...
BADGES
Badge ChangemakerBadge Diversity ChampionBadge Family FriendlyBadge Work&Life Balance
FUNDING
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
EMPLOYMENT TYPE
Full-time, remote
DATE POSTED
December 6, 2024

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!