Senior Risk, Governance and Compliance Analyst
VeriskAbout the role
Company Description
We help the world see new possibilities and inspire change for better tomorrows. Our analytic solutions bridge content, data, and analytics to help business, people, and society become stronger, more resilient, and sustainable.
Job Description
We are seeking a Senior Risk, Governance and Compliance Analyst to join our Operations team based in Boston, Massachusetts. You will be responsible for supporting our mission-critical compliance and privacy work which includes assisting with internal policy compliance initiatives and addressing security and privacy questions on behalf of our clients. The successful candidate should have knowledge and experience of information security frameworks and related compliance issues, and have the flexibility to adapt to evolving requirements in the security and regulatory landscape.
About the Day to Day Responsibilities of the Role
- Assist with security assessments and audits. Monitor and report on implementation of enterprise information security and privacy controls.
- Respond to customer / business partner security inquiries and assist with remediating findings in a timely manner. Serve as a company representative for prospects, customers, and partners regarding security questionnaires, assessments, and audits.
- Operationalize policies and procedures to ensure effective risk mitigation and regulatory compliance while balancing operating efficiency.
- Keep abreast of updates to regulations, frameworks, and client requirements (including GDPR, CCPA, NIST, HIPAA, and state regulations). Understand emerging threats that warrant additional controls. Liaise with technical and business owners to implement necessary changes.
- Provide security communication, awareness, and training for staff. Promote a culture of risk management and compliance throughout all levels.
- Develop & maintain a repository of reference documents concerning information security requirements and strategies applicable across the organization.
- Assist with Third Party Risk Management (TPRM) activities; conduct due diligence assessments of prospective vendors and perform periodic reviews of third-party vendor environments; identify current vulnerabilities for vendor utilized environments and/or applications; provide feedback to business leaders and risk owners.
#LI-SM1
Qualifications
About You and How You Can Excel in This Role
- Working knowledge of information security/privacy standards and best practices (e.g. NIST, SANS) as well as regulations related to information security and data confidentiality (e.g. CCPA, GDPR, HIPAA, etc.)
- General understanding of infrastructure architecture including WANs, LANs, Internet, intranets, databases, cloud computing on AWS, and communication protocols
- Demonstrated ability to operationalize enterprise-wide data security/privacy standards and policies, taking account of business constraints
- Experience reviewing and monitoring client and vendor contracts for appropriate data security/privacy considerations
- Proficiency with Microsoft Word, Excel and PowerPoint
- Strong organizational skills
- Ability to work collaboratively across multiple diverse departments
- Strong written and verbal communication skills
- Bachelor’s degree in a technology-related discipline
- 3+ years of information systems security or related auditing experience
Additional Information
At the heart of what we do is help clients manage risk. Verisk (Nasdaq: VRSK) provides data and insights to our customers in insurance, energy and the financial services markets so they can make faster and more informed decisions.
Our global team uses AI, machine learning, automation, and other emerging technologies to collect and analyze billions of records. We provide advanced decision-support to prevent credit, lending, and cyber risks. In addition, we monitor and advise companies on complex global matters such as climate change, catastrophes, and geopolitical issues.
But why we do our work is what sets us apart. It stems from a commitment to making the world better, safer and stronger.
It’s the reason Verisk is part of the UN Global Compact sustainability initiative. It’s why we made a commitment to balancing 100 percent of our carbon emissions. It’s the aim of our “returnship” program for experienced professionals rejoining the workforce after time away. And, it’s what drives our annual Innovation Day, where we identify our next first-to-market innovations to solve our customers’ problems.
At its core, Verisk uses data to minimize risk and maximize value. But far bigger, is why we do what we do.
At Verisk you can build an exciting career with meaningful work; create positive and lasting impact on business; and find the su
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s