Consultant - GRC Technology | Remote, USA
Kansas City, MO
Optiv
Optiv manages cyber risk so you can secure your full potential. Cybersecurity advisory services and solutions. Powered by the best minds in cyber.How you’ll make an impact
- Able to perform as contributor and a delivery lead and “point of contact" for both routine and complex GRC technology implementation projects
- Perform client facing activities such as product demonstrations, facilitate design workshops, documentation and status meeting participation if required
- Design and configure / develop GRC technology applications for potentially multiple GRC systems based on technical requirements using iterative design and build methodology. These GRC systems may include Archer, ServiceNow, LogicGate, OneTrust, Diligent or a variety of others in the industry. Training will be provided where necessary.
- Leverage API connectors for integrations between 3rd party systems and the GRC technology.
- Design and develop modules within GRC platforms such as Archer and ServiceNow including layout, workflow, reporting, notifications, questionnaires, access control, packaging, SSO, and LDAP access configuration.
- Participate in or lead GRC Technology implementation activities, connector configuration, custom rule development, workflow configuration and development, and third-party system integration.
- Facilitate client User Acceptance Testing and bug-related engineering efforts.
- Design, implement and educate on specific technology build processes, code migration, and source control use.
- Provide knowledge transfer and postproduction support activities, as necessary.
- Effective communicator with clients and internal team members.
- Maintain professional and technical knowledge by training and becoming certified in relevant GRC technology.
- Complete administrative project tasks like time and expense entry, status reporting, and project completion reporting.
- Acts as a contributor in Optiv communities for solutions of focus.
What we’re looking for
- Bachelor's degree and approximately 2-5 years of related work experience using and implementing GRC technology.
- Ability to support high demand and tight timelines to produce quality deliverables.
- Preferred experience with 2-3 years of Advance Workflow, data feeds via API or import, testing and dashboard/reporting development in GRC technology.
- Knowledge of general risk, compliance and security concepts and methods such as risk assessments, control attestations and testing, policy management, vendor risk management, vulnerability assessments, data classification, privacy assessments, incident response, security policy creation, enterprise security strategies, architectures, and governance.
- Understanding of networking (TCP/IP, OSI model), operating system fundamentals (Windows, UNIX, mainframe), security technologies (firewalls, IDS/IPS, etc.), and application programming/scripting languages (C, Java, Perl, Shell).
- Understanding of regulatory requirements and compliance issues affecting clients related to privacy and data protection, such as PCI DSS, GLBA, Basel II, EU Data Protection Directive, International Cross Border, and U.S. State Data Privacy Laws.
- Working knowledge of operating systems, virtual machine environments, mainframe security packages, and relational database management systems.
- Practical knowledge of configuring GRC technology such as Archer, ServiceNow, LogicGate, OneTrust or Navex.
- Skills in usage or design and implementation of API services (SOAP, REST).
- A good understanding of the SDLC and Agile sprint methodologies is required. Experience with JIRA a plus.
- Work independently in a highly dynamic environment with the ability to collaborate with an inter-functional team.
- Ability to build relationships with and influence other functional areas
- Well-developed negotiation skills.
- Ability to build consensus.
- Ability to manage multiple tasks in parallel
- Willingness to travel to meet client needs if required
- Related professional certifications such as the GRCP, RIMS-CRMP, CISSP, CISM, and/or CISA, are preferred but not required
- #LI-NA1
* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰
Tags: Agile APIs C CISA CISM CISSP Compliance Firewalls Governance IDS Incident response IPS Java Jira LDAP Mainframe PCI DSS Perl Privacy Risk assessment Risk management Scripting SDLC SSO TCP/IP UNIX Windows
Perks/benefits: Career development Startup environment
More jobs like this
Explore more InfoSec / Cybersecurity career opportunities
Find even more open roles in Ethical Hacking, Pen Testing, Security Engineering, Threat Research, Vulnerability Management, Cryptography, Digital Forensics and Cyber Security in general - ordered by popularity of job title or skills, toolset and products used - below.
- Open Information Security Specialist jobs
- Open Consultant infrastructure sécurité H/F jobs
- Open Senior Information Security Analyst jobs
- Open IT Security Analyst jobs
- Open Consultant SOC / CERT H/F jobs
- Open Senior Information Security Engineer jobs
- Open Information Security Officer jobs
- Open Chief Information Security Officer jobs
- Open Security Operations Engineer jobs
- Open Ingénieur DevSecops H/F jobs
- Open Staff Security Engineer jobs
- Open Analyste CERT / Incident Responder junior (H/F) jobs
- Open Senior Security Architect jobs
- Open Analyste CERT / Incident Responder senior (H/F) jobs
- Open Information Systems Security Officer (ISSO) jobs
- Open Cybersecurity Consultant jobs
- Open Senior Security Analyst jobs
- Open o365 Security Architect jobs
- Open Principal Security Engineer jobs
- Open Senior Cyber Security Engineer jobs
- Open Staff Product Security Engineer jobs
- Open Cyber Security Architect jobs
- Open Electronic Warfare Advanced Tactical Trainer jobs
- Open Security Researcher jobs
- Open Product Security Engineer jobs
- Open Application security-related jobs
- Open GCP-related jobs
- Open Governance-related jobs
- Open Risk assessment-related jobs
- Open Network security-related jobs
- Open Pentesting-related jobs
- Open Analytics-related jobs
- Open ISO 27001-related jobs
- Open CISM-related jobs
- Open IAM-related jobs
- Open Threat intelligence-related jobs
- Open SaaS-related jobs
- Open Security Clearance-related jobs
- Open Malware-related jobs
- Open Vulnerability management-related jobs
- Open CISA-related jobs
- Open Java-related jobs
- Open DevOps-related jobs
- Open Kubernetes-related jobs
- Open Security assessment-related jobs
- Open DoD-related jobs
- Open APIs-related jobs
- Open Forensics-related jobs
- Open Splunk-related jobs
- Open EDR-related jobs