Information Security GRC Specialist
Western DigitalAbout the role
Job Description
Western Digital seeks a skilled and experienced Information Security GRC Specialist to assume a pivotal role in SOX, PCI, and other critical information security risk and compliance areas. This individual contributor will play a lead role in shaping and optimizing our security posture, focusing on information security and technical controls, including IT General Controls (ITGCs), IT Application Controls (ITACs), and a deep understanding of company-level controls.
Responsibilities
IT General Controls
- Define and document IT General Controls (ITGCs) for Sarbanes-Oxley (SOX) 404 compliance.
- Provide expert technical guidance to stakeholders to design robust IT general controls.
- Collaborate with IT process owners to standardize, optimize, and automate controls, enhancing overall efficiency.
- Deliver ongoing guidance on IT control requirements, ensuring alignment with industry best practices.
Control Assessments
- Lead the preparation, planning, and execution of IT control assessments, including SOX ITGC.
- Prepare, review, and finalize work papers and compliance reports with meticulous attention to detail.
- Identify technology and business-related risks, understand current regulations, and contribute to the design of internal controls and processes to mitigate potential risks.
- Partner with key stakeholders to set the strategic direction for audit readiness, manage compliance frameworks, drive continuous improvement, and deliver meaningful reporting metrics.
- Collaborate with internal and external auditors to optimize audits, balancing risk mitigation and administrative efficiency.
Remediation and Compliance
- Effectively communicate control weaknesses, insights, and recommendations to relevant stakeholders.
- Review the adequacy of corrective and preventative action plans, actively monitoring plan execution.
- Ensure compliance with corporate reporting standards and adhere to established timelines.
Additional Responsibilities
- Ensure compliance with PCI.
Qualifications
Qualifications
- 8+ years of relevant experience in information security risk and compliance.
- 2+ years of experience with SOX ITGC, ITAC, and company-level controls.
- Bachelor’s degree in information systems, computer science, cybersecurity, or equivalent work experience.
- In-depth knowledge and experience with diverse IT architectures, enterprise IT data centers, external hosted services, and cloud computing environments.
- Proven experience in performing information security risk assessments.
- Strong analytical skills, exceptional multitasking ability, and a proven track record of working efficiently under tight deadlines.
- Positive, energetic attitude with a proactive approach to identifying issues and opportunities.
- Professional certifications such as CISSP, CISM, SSCP, CISA, or equivalent are preferred.
- Familiarity with ISO 27001 Information Security Management System (ISMS).
- ISO 27001 Lead Auditor Certification a plus.
Skills
- Security Assessment Expertise: Demonstrate a history of working collaboratively with stakeholders to review and enhance processes and controls through assessments or other tools.
- Pragmatic and Business-oriented: Prioritize projects based on their business impact, understanding the risks and balancing security investments with bottom-line outcomes.
- Empathetic communication: Clearly communicate nuanced ideas, whether explaining compliance requirements in writing or engaging in real-time brainstorming. Build consensus by thoughtfully considering other perspectives and compromising when needed.
- Team player: Thrive in a collaborative, cross-functional environment, contributing to shared goals and fostering a culture of continuous learning and growth.
Additional Information
All your information will be kept confidential according to EEO guidelines.
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s