Senior Analyst, Cybersecurity and Compliance
White & Case LLPAbout the role
Position Summary
The Senior Analyst, Cybersecurity and Compliance plays a pivotal role in protecting the firm against cybersecurity threats. This position is tasked with identifying, evaluating, and monitoring potential cybersecurity risks. They will collaborate with various teams within the firm to ensure that Governance, Risk Management, and Compliance (GRC) areas such as Audits, Information Security Certifications, and Vendor Management Risks are effectively managed. This includes adhering to industry and cybersecurity standards, as well as client and government regulations.
Furthermore, the Senior Analyst, Cybersecurity and Compliance will guide stakeholders in incorporating appropriate security measures into business operations, system designs, and software development processes. This role is responsible for enhancing and implementing processes that assist in planning remediation strategies to ensure compliance with policies and regulations. By providing valuable insights for risk prioritization, the Analyst will prepare reports that highlight trends, risk levels, and metrics. They will focus on building trust and fostering cross-functional partnerships to elevate awareness and successfully implement cybersecurity controls across the firm.
Duties and Accountabilities
The roles and responsibilities of this job include:
Maintain and improve the GRC function
Provide support for internal assessments and audits at planned intervals and on an ad hoc basis to evaluate and validate the design and operational effectiveness of technical, and administrative controls to help reduce risk in the organization
Mentor junior GRC Analysts on the team
Assist with monitoring open audit items from internal audits and external compliance/client/certification audits to ensure completion of remediation activities defined in the agreed action plans and risk treatment plans
Support continuous monitoring processes to assess compliance with information security policies and standards, legal and regulatory compliance
Provide compliance subject matter expertise support to various departments
Assist with conducting third-party vendor information security assessment and ongoing third-party assurance activities
Design, manage, and update company’s compliance related documentation and reports
Create any necessary road maps for regulatory compliance
Qualifications
The qualifications for this job include:
5-7+ years of experience within GRC, specifically vendor & risk management standards and frameworks
Possessing any cybersecurity certifications, CRISC, CISM, CGEIT, CISA,CISSP, etc.
Possessing an understanding of industry standards, certifications, and regulations including NIST800/CSF, ISO 27001
Experience with compliance programs related to SSAE16 SOC1, SOC2, PCI, and/or NIST-800-53
Working knowledge in Cloud Security assessments, systems, tools, and web application reviews including Secure SDLC life cycle assessments.
Working knowledge of enterprise infrastructure and application monitoring tools.
Proficient in Microsoft Office applications; SME in Excel and data manipulation
Attention to detail. Clear logical and analytical thinker.
Able to prioritize and manage multiple tasks under pressure
Good verbal, written and numeric
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s