Jobs and Careers
F5

Governance, Risk and Compliance Analyst III

F5
F5 Tower, United States, United Statesfull_timeVerifiedPosted 18 Dec 2024
💰 $179,494/yr($119,662/yr$179,494/yr)

About the role

At F5, we strive to bring a better digital world to life. Our teams empower organizations across the globe to create, secure, and run applications that enhance how we experience our evolving digital world. We are passionate about cybersecurity, from protecting consumers from fraud to enabling companies to focus on innovation. 
 

Everything we do centers around people. That means we obsess over how to make the lives of our customers, and their customers, better. And it means we prioritize a diverse F5 community where each individual can thrive.

Position Summary

A Governance, Risk and Compliance (GRC) Analyst III is a Cybersecurity professional responsible for the maintenance and support of Cybersecurity’s many programs (including risk management, compliance, and vulnerability management) that meets the parameters prescribed by the Office of the CISO for the organization.

Primary Responsibilities

An individual contributor in the Cybersecurity department that is chartered with supporting the company’s Cybersecurity program, with special focus on controls and policies intended to meet requirements across multiple compliance frameworks, including PCI DSS, SOC-2, ISO 27001, HIPAA, and BSI C5.  Responsible for assisting with management and monitoring the company’s security risks, security compliance guidelines and controls, vulnerability management and development / dissemination of best-practice standards, policies and procedures. The individual will work with various functions throughout the enterprise to evaluate the design and effectiveness of the control environment and maintain the security posture of the program.

  • Responsible for upholding F5’s Business Code of Ethics and for promptly reporting violations of the Code or other company policies.
  • Provide daily support to security-related, services, including security assessments and the information security management systems program.
    • Assist as escalation point for support requests related to Information Security Programs
    • Support documenting procedures for specific compliance and regulatory requirements
    • Assist with supporting security assessments, including external security assessment and customer security questionnaires
  • Assist with audit, risk management, and compliance program
    • Support and improve security, risk management, and control framework
    • Monitor internal compliance against information security governance frameworks by conducting routine testing and internal control reviews as well as enterprise security risk assessments
    • Identify and communicate control gaps, evaluate management remediation action plans, and provide ongoing monitoring of resolution
    • Maintain awareness of external regulations and industry standards for new or modified requirements (FedRAMP, GDPR, PCI-DSS, CCPA, NIST 800-53, ISO 27001, etc.)
    • Perform assessments of supporting third parties to evaluate current security posture and monitor ongoing adherence to F5’s information security requirements
  • Assist with management of the security assessment program
    • Lead and improve supporting of security assessments, including third-party security assessment and customer security questionnaires.
    • May work with external vendors to perform assessments (i.e., pen testing, assessments) as directed.
    • Develop knowledge pertaining to Threat Model Assessments
    • May work with Legal and/or Privacy department to understand regulatory and contractual information security obligations
    • May work with external vendors to perform assessments (i.e., pen testing, assessments) as directed.
  • Assist with management of the vulnerability management program
    • Review and analyze enterprise scale remediation of findings.
    • Monitor, notify and/or assist with remediation steps for identified vulnerabilities.
    • Engage with stakeholders to address outstanding vulnerabilities.
    • May assist with reporting on status of program to Cybersecurity Leadership or other management teams.
  • Performs other related duties as assigned.

The Job Description is intended to be a general representation of the responsibilities and requirements of the job.  However, the description may not be all-inclusive, and responsibilities and requirements are subject to change.

Knowledge, Skills and Abilities

  • Strong familiarity with systems and network infrastructure security technologies, including application/OS hardening techniques, network protocols, network & application firewalls, intrusion detection systems.
  • Strong hands-on familiarity with security risk-assessment tools & techniques (vulnerability testing, penetration testing, social engineering, etc.).
  • Soph

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

F5

View company profile →