Jobs and Careers
TH

Information Security Policy & Governance Analyst

Thomson Reuters
United Statesfull_timeVerifiedPosted 26 Jun 2024

About the role

Are you someone who relentlessly seeks solutions and ensures timely delivery to commitments? Someone with a detective mind that proactively finds solutions and considers various scenarios? If the answer to this and other questions is yes, then you are a great fit for an open Technology Analyst role.  We are currently looking for an IS Policy & Governance Analyst to join our Cyber Compliance team as part of the ISRM function in Richmond, Toronto, or Dallas. 

You will be a key member of the Cyber Compliance team who will ensure Information Security (IS) and Information Technology (IT) policies, standards, and guidelines are up to date and in line with enterprise guidance.  Additionally, you will work closely with teams responsible for testing controls, reporting, and tracking which tie directly to internal compliance with relevant policies/standards and external compliance with frameworks/regulations that ultimately sustains customer confidence in Thomson Reuters (TR). 

About the Role  

In this opportunity as IS Policy & Governance Analyst, you will be responsible for: 


Policy Development & Management: 

  • With the support of domain experts, develop, update, and maintain IT policies, standards, and procedures. 

  • Ensure policies are in compliance with legal and regulatory requirements. 

  • Monitor changes in laws, regulations, and industry standards and make recommendations to update policies accordingly. 

  • Collaborate with compliance & attestation program leads to ensure IT policies, standards, and procedures reflect applicable updates and meet required language requirements. 

Compliance and Risk Management: 

  • Monitor compliance with IT policies & procedures via data analysis of continuous compliance reporting, audit results, etc. 

  • Compile reporting on policy compliance at a regular cadence and present to senior management. 

  • Identify and facilitate risk mitigation with IT operations including facilitating impact analysis of policy updates and changes. 

Training and Awareness: 

  • Design and deliver training programs to educate employees about IT policies and procedures. 

  • Promote awareness of IT security and best practices across the organization. 

Collaboration, Communication & Cross-Functional Support: 

  • Work closely with IT teams, legal, HR, Risk & Compliance and ISRM leadership to ensure cohesive policy implementation. 

  • Serve as a point of contact for inquiries related to IT policies, standards, and procedures. 

  • Provide support to the Customer Attestation and Cyber Compliance Testing Team to facilitate the development of continuous compliance and supporting evidence. 
     

About You 

You are fit for the role of IS Policy & Governance Analyst, if your skills and background include: 

  • Bachelor's degree in IT, Accounting, Finance or equivalent education and experience. 

  • Proven experience in data analysis including writing SQL queries. 

  • Strong analytical and problem-solving skills. 

  • Strong ethical principles and understanding of business and IS ethics. 

  • Knowledge of IT compliance standards and regulations. 

  • Certification such as CISA, CISSP, CCAK, CISM, or CRISC or the ability to obtain the certi

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Thomson Reuters

View company profile →