Data Recognition Corporation logo

Information Security Compliance Analyst

Data Recognition Corporation

Maple Grove, MNFull-time$95–120K/yrSeen 1 day agoSeen in employer's feed 1 day ago

Most applications go out cold — see where you stand first. No sign-up to start.

Watch jobs like this.

At a glance

Compensation
$95–120K/yr
Location
Maple Grove, MN
Schedule
Full-time
Work Authorization
Not specified

Olive lists jobs from US employers, including remote roles you can work from the United States.

Job overview

The Information Security Compliance Analyst is part of DRC’s Information Security Team and manages risk and compliance activities, including internal and external security reviews. The role supports the security program through policy maintenance, security awareness, risk assessment and management, and business continuity and resiliency efforts. It focuses on maintaining and enhancing compliance maturity, including government and industry frameworks, audits, remediation, and security metrics.

Skills & qualifications

RequiredNice to have

Skills

NIST 800-53Risk Management FrameworkSTIG CompliancePOA&M DocumentationSOC 2 AuditsCommunicationTeamworkInitiative ManagementInternal AuditingExternal AuditingGovRAMPFedRAMPFISMANIST Security ControlsCISACRISCISO 27001Vendor Security AssessmentsCross-Functional Project Management

Qualifications

3+ Years Information Security ExperienceFour-Year Degree in IT or Related

Benefits

Medical Insurance
Dental Insurance
Vision Insurance
401(k) Match
Paid Time Off

Full job description

Job Duties

DRC is one of the largest educational assessment and curriculum/instruction companies in the industry.

Information Security Compliance Analyst

Data Recognition Corporation - Minnesota

Please No Agencies

Company cannot provide sponsorship for this position

Summary:

This position is part of the Data Recognition Corporation (DRC) Information Security Team that has an important role in the defining and enabling the secure operation of the DRC environment. This position has responsibility for managing and leading various risk and compliance activities, including internal and external security reviews that are key to validation of our security program.

This position also assists with other aspects of the security practice, including maintaining DRC's security policies, standard and procedures; increasing the organizations security awareness; performing risk assessment and risk management activities; and promoting business continuity and resiliency efforts.

Responsibilities:

This position will manage/lead a wide range of compliance and risk functions, with the focus being on maintaining and enhancing our compliance maturity. Key responsibilities include:

Obtain and maintain GovRAMP compliance

Support Authority to Operate (ATO) approvals for government contracts by adherence to NIST Risk Management Framework (RMF)

Support cybersecurity efforts to include the development and management of System Security Plan (SSP) documentation, Plans of Action and Milestones (POAMs), assessing and auditing systems security controls, and continuous monitoring activities

Manage internal and external annual audits (third party and customer)

GovRAMP

ISO 27000 series

SOC II Type 2

Various customer audits

Maintain and drive remediation on Plan of Action and Milestones (POAM) items

Policy and standard development and review

Mature security risk management practices

Manage and enhance Business Continuity/Disaster Recovery processes

Update and maintain security and compliance metrics

Essential Qualifications

3+ years of Information Security, GRC, audit, or compliance experience

Working knowledge in NIST 800-53 Rev 5 framework and how to implement and audit against the framework

General knowledge of the following: Risk Management Framework (RMF), compliance with security technical implementation guides (STIGs), and documenting Plan of Action and Milestones (POA&M)

Experience managing SOC 2 Type II compliance audits

Possesses a high level of personal integrity and the ability to discreetly handle sensitive, personal, and classified information.

Must have excellent communication skills and the ability to work well in a team and across the organization, in addition to independently driving initiatives.

Preferred Qualifications

Four-year college degree in IT, Computer Science, Cybersecurity, or related fields

Internal or External Audit experience

Experience with GovRAMP or FedRAMP certifications

Experience with Federal Information Security Management Act (FISMA) leveraging National Institute of Standards and Technology (NIST) security controls (NIST 800-53, rev 5).

Security certification such as Certified Information Security Auditor (CISA) and/or Certified in Risk and Information Security Controls (CRISC)

Experience with ISO 27001 certification

Experience supporting and participating in third party vendor security assessments and audits, reviewing audit findings as well as responses to security findings and remediation plans.

Ability to manage cross-functional projects and initiatives as required.

Reporting to this position: No direct reports

The Employer retains the right to change or assign other duties to this position

Company cannot provide sponsorship for this position

Please, no agencies

All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran.

DRC offers a comprehensive benefits program that allows employees to make choices that best meet their current and future needs. We offer many benefits, including medical, wellness, dental, and vision insurance, a 401(k), flexible spending and health savings accounts, short and long-term disability insurance, and life insurance. DRC also offers a generous paid time off policy and community service leave.

Data Recognition Corporation is an Affirmative Action/Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran.

The salary range is a guideline. Compensation will be based on skills, knowledge, and experience.

Data Recognition Corporation is an Affirmative Action/Equal Opportunity Employer, M/F/Disabled/Veteran

Minimum Education Required

High School Diploma or Equivalent

Minimum Experience Required

3 - 20 years

Shift

First (Day)

Number of Openings

1

Public Transportation Accessible

Yes

Veterans Encouraged to Apply

No

Physical Required

Yes

Drug Test Required

Yes

Compensation

$95,000.00 - $120,000.00 / Annually

Postal Code

55311

Job Type

Full Time

Place of Work

On-site

Requisition ID

2216

Job Benefits

Not specified

Similar jobs, posted recently

Open roles like this one, listed in the last 30 days.

You've read the whole posting — now see how you match it.