Jobs and Careers
WE

Information Security GRC Specialist

Western Digital
United Statesfull_timeVerifiedPosted 25 Nov 2023

About the role

Job Description

Western Digital seeks a skilled and experienced Information Security GRC Specialist to assume a pivotal role in SOX, PCI, and other critical information security risk and compliance areas. This individual contributor will play a lead role in shaping and optimizing our security posture, focusing on information security and technical controls, including IT General Controls (ITGCs), IT Application Controls (ITACs), and a deep understanding of company-level controls.

Responsibilities

IT General Controls

   - Define and document IT General Controls (ITGCs) for Sarbanes-Oxley (SOX) 404 compliance.

   - Provide expert technical guidance to stakeholders to design robust IT general controls.

   - Collaborate with IT process owners to standardize, optimize, and automate controls, enhancing overall efficiency.

   - Deliver ongoing guidance on IT control requirements, ensuring alignment with industry best practices.

Control Assessments

   - Lead the preparation, planning, and execution of IT control assessments, including SOX ITGC.

   - Prepare, review, and finalize work papers and compliance reports with meticulous attention to detail.

   - Identify technology and business-related risks, understand current regulations, and contribute to the design of internal controls and processes to mitigate potential risks.

   - Partner with key stakeholders to set the strategic direction for audit readiness, manage compliance frameworks, drive continuous improvement, and deliver meaningful reporting metrics.

   - Collaborate with internal and external auditors to optimize audits, balancing risk mitigation and administrative efficiency.

Remediation and Compliance

   - Effectively communicate control weaknesses, insights, and recommendations to relevant stakeholders.

   - Review the adequacy of corrective and preventative action plans, actively monitoring plan execution.

   - Ensure compliance with corporate reporting standards and adhere to established timelines.

Additional Responsibilities

   - Ensure compliance with PCI.

Qualifications

Qualifications

- 8+ years of relevant experience in information security risk and compliance.

- 2+ years of experience with SOX ITGC, ITAC, and company-level controls.

- Bachelor’s degree in information systems, computer science, cybersecurity, or equivalent work experience.

- In-depth knowledge and experience with diverse IT architectures, enterprise IT data centers, external hosted services, and cloud computing environments.

- Proven experience in performing information security risk assessments.

- Strong analytical skills, exceptional multitasking ability, and a proven track record of working efficiently under tight deadlines.

- Positive, energetic attitude with a proactive approach to identifying issues and opportunities.

- Professional certifications such as CISSP, CISM, SSCP, CISA, or equivalent are preferred.

- Familiarity with ISO 27001 Information Security Management System (ISMS).

- ISO 27001 Lead Auditor Certification a plus.

Skills

- Security Assessment Expertise: Demonstrate a history of working collaboratively with stakeholders to review and enhance processes and controls through assessments or other tools.

- Pragmatic and Business-oriented: Prioritize projects based on their business impact, understanding the risks and balancing security investments with bottom-line outcomes.

- Empathetic communication: Clearly communicate nuanced ideas, whether explaining compliance requirements in writing or engaging in real-time brainstorming. Build consensus by thoughtfully considering other perspectives and compromising when needed.

- Team player: Thrive in a collaborative, cross-functional environment, contributing to shared goals and fostering a culture of continuous learning and growth.

Additional Information

All your information will be kept confidential according to EEO guidelines.

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Western Digital

View company profile →