Jobs and Careers
RU

Sr. Information Security Analyst

Rubrik
UKRemotefull_timeVerifiedPosted 4 Apr 2023
💰 $252,000/yr($126,000/yr$252,000/yr)

About the role

The Information Security organization advances the overall state of security at Rubrik through critical initiatives and coordination of large security projects. Information Security builds technologies, tools, and processes to better enable teams at Rubrik to develop secure software and protect data and systems with appropriate security controls. Information Security also develops systems to monitor and respond to attacks against our systems, provides awareness education to teams on security best practices for data protection, and ensures data sharing relationships with third parties in order to securely protect Rubrik information.

What you’ll Do:

Rubrik is seeking a Senior Information Security Analyst to be a part of our Information Security team that leads our Corporate Compliance functions. As a member of our Information Security team, you will be a highly motivated individual who will be responsible for the execution and continuous maturity of these service areas. The successful candidate will need to build and maintain strong cross-functional relationships across the company. To achieve this you must have excellent leadership, communication, and decision-making skills.

Experience you'll need:

In this role, you will:

  • Perform annual internal audits and assessments against industry standards, such as ISO 27001, SOC 1 and SOC 2, HITRUST, SOX, etc.
  • Prepare and implement a risk-based audit plan to assess, report on, and make suggestions for improving the company's key operational and finance activities and internal controls for SOX
  • Document and communicate compliance activities, collaborating with a range of stakeholders from individual contributors to senior leadership levels.
  • Contribute to security program development by identifying new or emerging opportunities to apply security principles and technologies.
  • Analyze the security of new or existing applications, software, or specialized utility programs and provide recommendations for maintaining compliance.
  • Monitor and evaluate emerging security regulations and best practices to reasonably anticipated changes to the privacy and security compliance landscape.
  • Be an integral member of the compliance team to build and maintain strong cross-functional relationships across the company to aid in achieving consensus, expectation setting, training and awareness, and promote consistency and improvement in our processes.
  • Contribute to the production and improvement of the content, quality, and timing of security governance, risk and compliance analysis and reporting.
  • Own and drive activities related to the remediation of technical security and compliance risks with cross-functional teams, including, but not limited to, leading meetings, working to assign, track work items, and producing reports.

Preferred Qualifications:

  • 5+ years of related work experience in Information Security Governance, Risk and Compliance (GRC) or relevant Compliance roles in the tech industry.
  • Summarize test results at the conclusion of testing and communicate to the process owners any control deficiencies and provide recommendations for remediation
  • Assist with the maintenance of consistency and quality in SOX compliance work across the organization
  • Stay apprised of all new SOX compliance guidelines and interpretations and new PCAOB requirements
  • Plan the scope of work and monitor progress on audit projects, ensuring quality audit work within defined time frames
  • Provide audit deliverables inclusive of, but not limited to, creating process flow documents, performing detailed test work, and summarizing results in work papers
  • Experience with compliance audits across a range of industries and regulations (e.g., SOC 2, SOC 1, ISO, HITRUST, ISMAP, SOX).
  • Experience with prioritizing compliance related work.
  • Can implement a solution (design), operational plan, and roadmap to achieve goals.
  • Experience implementing agile use cases in a GRC technology solution.
  • Executive presence: can represent a vision and build consensus across a variety of partners.
  • Knows how to estimate work effort and incubate skill sets to achieve team goals.
  • Has advanced knowledge of common security and compliance requirements and can escort these issues through triage / risk treatment conversations.
  • Strong knowledge of audit and risk management methodologies, such as SOX, COBIT, NIST RMF / 800-37 / 800-30.
  • Hands-on experience with data analytics and business intelligence dashboarding tools (e.g., Power BI) and with agile project management tools (e.g., Jira).
  • Detail-oriented and able to understand the bigger picture by using your technical expertise and problem solving abilities to prioritize and manage blo

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Rubrik

View company profile →