Jobs and Careers
WE

Information Security GRC Specialist

Western Digital
United Statesfull_timeVerifiedPosted 3 Jan 2024

About the role

Company Description

At Western Digital, our vision is to power global innovation and push the boundaries of technology to make what you thought was once impossible, possible.

At our core, Western Digital is a company of problem solvers. People achieve extraordinary things given the right technology. For decades, we’ve been doing just that. Our technology helped people put a man on the moon.

We are a key partner to some of the largest and highest growth organizations in the world. From energizing the most competitive gaming platforms, to enabling systems to make cities safer and cars smarter and more connected, to powering the data centers behind many of the world’s biggest companies and public cloud, Western Digital is fueling a brighter, smarter future.

Binge-watch any shows, use social media or shop online lately? You’ll find Western Digital supporting the storage infrastructure behind many of these platforms. And, that flash memory card that captures and preserves your most precious moments? That’s us, too.

We offer an expansive portfolio of technologies, storage devices and platforms for business and consumers alike. Our data-centric solutions are comprised of the Western Digital®, G-Technology™, SanDisk® and WD® brands.

Today’s exceptional challenges require your unique skills. It’s You & Western Digital. Together, we’re the next BIG thing in data.

Job Description

This is a Hybrid role with 2 days in office per week. 

Western Digital seeks a skilled and experienced Information Security GRC Specialist to assume a pivotal role in SOX, PCI, and other critical information security risk and compliance areas. This individual contributor will play a lead role in shaping and optimizing our security posture, focusing on information security and technical controls, including IT General Controls (ITGCs), IT Application Controls (ITACs), and a deep understanding of company-level controls.

ESSENTIAL DUTIES AND RESPONSIBILITIES:

IT General Controls

  • Define and document IT General Controls (ITGCs) for Sarbanes-Oxley (SOX) 404 compliance.
  • Provide expert technical guidance to stakeholders to design robust IT general controls.
  • Collaborate with IT process owners to standardize, optimize, and automate controls, enhancing overall efficiency.
  • Deliver ongoing guidance on IT control requirements, ensuring alignment with industry best practices.

Control Assessments

  • Lead the preparation, planning, and execution of IT control assessments, including SOX ITGC.
  • Prepare, review, and finalize work papers and compliance reports with meticulous attention to detail.
  • Identify technology and business-related risks, understand current regulations, and contribute to the design of internal controls and processes to mitigate potential risks.
  • Partner with key stakeholders to set the strategic direction for audit readiness, manage compliance frameworks, drive continuous improvement, and deliver meaningful reporting metrics.
  • Collaborate with internal and external auditors to optimize audits, balancing risk mitigation and administrative efficiency.
  • Remediation and Compliance
  • Effectively communicate control weaknesses, insights, and recommendations to relevant stakeholders.
  • Review the adequacy of corrective and preventative action plans, actively monitoring plan execution.
  • Ensure compliance with corporate reporting standards and adhere to established timelines.

Additional Responsibilities

  • Ensure compliance with PCI.

Qualifications

REQUIRED:

  • 8+ years of relevant experience in information security risk and compliance.
  • 2+ years of experience with SOX ITGC, ITAC, and company-level controls.
  • Bachelor’s degree in information systems, computer science, cybersecurity, or equivalent work experience.
  • In-depth knowledge and experience with diverse IT architectures, enterprise IT data centers, external hosted services, and cloud computing environments.
  • Proven experience in performing information security risk assessments.
  • Strong analytical skills, exceptional multitasking ability, and a proven track record of working efficiently under tight deadlines.
  • Positive, energetic attitude with a proactive approach to identifying issues and opportunities.
  • Professional certifications such as CISSP, CISM, SSCP, CISA, or equivalent are preferred.
  • Familiarity with ISO 27001 Information Security Management System (ISMS).
  • ISO 27001 Lead Auditor Certification a plus.

SKILLS:

  • Security Assessment Expertise: Demonstrate a history of working collaboratively with stakeholders to review and enhance processes and controls through assessments or other tools.
  • Pragmatic and Business-oriented: Prioritize projects based on their business i

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Western Digital

View company profile →