Jobs and Careers
WO

Senior IT Security Analyst - Risk/Control/Audit

Wolters Kluwer
Francefull_timeVerifiedPosted 7 Oct 2024

About the role

<p><b><span>The </span><span>Global Information Security</span></b><span><b> team</b> works diligently every day to keep </span><span>Wolters Kluwer</span><span>'s </span><span>systems, data, and digital infrastructure secure, while protecting its people, assets, brand, and </span><span>reputation from malicious cyber actors. </span></p><p><span>Through training, sharing of best practices and the rollout of expanded enterprise security tools, the GIS team empowers employees to do their part </span><span>to keep our systems secure.</span></p><p><span>Within Global Information Security, the </span><b><span>Compliance &amp; Assurance</span></b><span><b> </b>function leads compliance </span><span>programs (SOC 2, SOC 1, ISO 27001, HIPAA, FedRamp, NIST...) and ensures the supporting </span><span>control framework is adequate</span></p><p></p><p><b>ROLE</b></p><p>Within the Compliance &amp; Assurance function, the <b>Senior IT Security Analyst </b>establishes information security compliance and assurance programs that meet business requirements and undertakes risk management, control management, audit management, and control framework improvement related activities.</p><p></p><p><b>ESSENTIAL DUTIES AND RESPONSIBILITIES</b></p><p>Compliance &amp; Assurance programs:</p><ul><li><p>Collaborate with Wolters Kluwer businesses to understand their information security compliance and assurance needs.</p></li><li><p>Establish and manage compliance and assurance programs accordingly.</p></li><li><p>Bring information security compliance expertise; educate on compliance matters.</p></li><li><p>Support the design, implementation, and performance of IT controls to help ensure compliance.</p></li></ul><p></p><p>IT Audit:</p><p>Contribute to compliance and assurance audits in general, including:</p><ul><li><p>Help define pluriannual audit plans.</p></li><li><p>Coordinate interactions between internal teams and auditors.</p></li><li><p>Prior to audits, prepare audited teams.</p></li><li><p>During audits, facilitate walkthroughs, gathering and checking of evidence requested by auditors; perform audit activities, if applicable.</p></li><li><p>After audits, ensure that resulting observations are addressed, with corrective and preventive actions defined, assigned, understood, and implemented within agreed timeframes.</p></li><li><p>Maintain audit management methodology and associated tools.</p></li></ul><p></p><p>IT Risk management:</p><p>Contribute to risk management activities in general, including:</p><ul><li><p>Risk identification, evaluation, and treatment.</p></li><li><p>Regular review of risks.</p></li><li><p>Implementation of risk treatment actions.</p></li><li><p>Maintenance of risk management methodology and associated tools.</p></li></ul><p></p><p>IT control:</p><p>Contribute to the management of information security controls in general, including:</p><ul><li><p>Review controls regularly to ensure their continuing adequacy and effectiveness.</p></li><li><p>Perform controls that fall under Compliance &amp; Assurance.</p></li><li><p>Monitor controls to help ensure timely completion with the expected quality.</p></li><li><p>Manage control deviations.</p></li><li><p>Maintain control management methodology and associated tools.</p></li></ul><p></p><p>Action plans:</p><p>Manage corrective and preventive actions, and other improvement projects, resulting from the above compliance, audit, risk, and control activities, including:</p><ul><li><p>Support the definition of action plans that adequately address audit observations, compliance deviations, risk treatment actions, and control improvement overall.</p></li><li><p>Monitor and document the progress of action plans.</p></li><li><p>Timely alert of any issues with the action plans.</p></li></ul><p></p><p><b>EXPERIENCE/JOB QUALIFICATIONS</b></p><ul><li><p>University degree in general engineering or related to information security, IT, or software development (BAC+5 in France).</p></li><li><p>Security certifications are valued.</p></li><li><p>8 to 15 years in IT environment.</p></li><li><p>IT risk, control, audit.</p></li><li><p>Compliance frameworks, such as SOC 2, SOC 1, ISO 27001, HIPAA, FedRamp, NIST.</p></li><li><p>Cloud environments: Microsoft Azure, AWS (Amazon Web Services).</p></li><li><p>Enablon software – or equivalent – nice to have.</p></li><li><p>Software development in an Agile environment.</p></li><li><p>Security tools: antivirus, firewalls, WAF, SIEM…</p></li><li><p>Microsoft 365 – Outlook, Word, Excel, PowerPoint, Teams.</p></li><li><p>Ability to write documents that are read, adopted, and used by the intended audience.</p></li><li><p>Fluent in French and English. Dutch is a nice to have.</p></li></ul><p></p><p><b>Location: </b>France, Bois-Colombes office (Hauts de Seine)</p><p>2 days remote work per week</p><p></p><p><b>Join us at Wolters Kluwer </b>and be part of a dynamic global technology company that makes a difference every day through our deep domain experti

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Wolters Kluwer

View company profile →