Cybersecurity Job at Goodwill Industries, Miami, FL

MFR2OTF6dS9BbVlJUVZFSGJaQWNwUFlFdUE9PQ==
  • Goodwill Industries
  • Miami, FL

Job Description

About the Company

The Cybersecurity Risk and Compliance Analyst ensures that the organization's technology ecosystem is evaluated correctly, assessed, and managed to ensure compliance and minimize cybersecurity risk exposure and impacts to the business. The analyst will assist with tracking open audit findings and facilitate response generation, information gathering, testing evidence, and escalation of the prior conclusions. The analyst will collaborate with infrastructure team members, drive the adoption of security best practices, assist with creating new policies, improve existing security processes, and support adherence to the organization's security policies and procedures.

Responsibilities

  • Assures successful implementation and functionality of security requirements and appropriate IT policies and procedures consistent with the organization's mission and goals.
  • Monitors and audits compliance of cybersecurity policies to identify gaps.
  • Designs, implements and maintains cybersecurity policies and procedures such as data access controls, acceptable use of technology, password management, and incident reporting procedures.
  • Oversees security activities such as access control, incident management, response, forensics, and reporting.
  • Build communication and escalation plans around third-party cybersecurity risk management activities within the enterprise.
  • Works with regulatory officers and auditors as necessary.
  • Coordinates the gathering of third-party cybersecurity risk assessment data and prepares cybersecurity risk assessments for critical-related third parties as needed, to be published and communicated to stakeholders.
  • Tracks identified cybersecurity risks and risk events.
  • Maintains a current understanding of industry trends, emerging cyber threats, and new solutions that may impact the environment.
  • Performs security reviews and identifies security gaps in security architecture, resulting in recommendations for inclusion in the risk mitigation strategy.
  • Works with stakeholders to communicate business risk and mediation by agreed protection levels.
  • Plans and conducts security authorization reviews and assurance case development for installing systems and networks.
  • Performs IT and IS control reviews including, but not limited to, operating procedures, system security, programming controls, backup and disaster recovery, and system maintenance.

Qualifications

BS or MA in computer science, information security, cybersecurity or a related field.

Required Skills

  • 3+ years of experience in an IT audit, enterprise risk management (ERM) role or cyber risk management role.
  • 3+ years of experience with regulatory compliance, risk management frameworks, and information security management frameworks (e.g., ISO 27000, CMMC, NIST 800-171, NIST Risk Management Framework, CARF, etc.).
  • Strong background in conducting Business Impact Analysis (BIA) to evaluate the potential impact of cybersecurity risk on critical business processes and functions.
  • Experience understanding and articulating business goals and objectives.
  • Experience identifying and assessing risks to the organization's business.
  • Experience communicating complex technical concepts to non-technical audiences.
  • Experience with cybersecurity principles and practices, including risk management, security controls, and incident response.
  • Experience with cybersecurity technologies and systems, such as firewalls, intrusion detection systems, and security information and event management (SIEM) systems.
  • Familiarity in one or more of the following areas: Identity management, PAM, SSO and MFA.
  • Ability to leverage research from various sources such as government research, think tanks, academic research, and industry reports.

Equal Opportunity Statement

Include a statement on commitment to diversity and inclusivity.

Job Tags

Similar Jobs

Health Advocates Network - Northeast

Local Contract Nurse RN - Med Surg - $70 per hour Job at Health Advocates Network - Northeast

 ...Health Advocates Network - Northeast is seeking a local contract nurse RN Med Surg for a local contract nursing job in Albany, New York. Job Description & Requirements ~ Specialty: Med Surg ~ Discipline: RN ~ Start Date: 05/02/2025~ Duration: 12 weeks ~3... 

Public Counsel

2025 Summer Intern - Consumer Rights & Economic Justice Project Job at Public Counsel

 ...power of our clients through comprehensive legal advocacy. Founded on and strengthened by a...  ...related trainings throughout the summer for consumer lawyers and their law clerks across the state. What do student interns do in the Consumer Rights & Economic Justice... 

Deephaven

Senior Encompass Administrator Job at Deephaven

 ...specialized investment manager focused on real estate, mortgage finance and corporate debt. Job Overview The Senior Encompass Administrator will be a pivotal role within the Technology Team and with the lines of Business. They will work closely with the Technology... 

Knight Federal Solutions

Fire Protection Engineer Job at Knight Federal Solutions

 ...security clearance - SECRET Be a graduate of an accredited Engineering college curriculum (four [4]-year degree minimum AND have a...  ...experience with the following: o Performing fire protection engineering for new and existing facilities to include analysis... 

DAVID BAGGA COMPANY

MED DEVICE SALES REP - O.R. SURGICAL/CAPITAL - SAN DIEGO Job at DAVID BAGGA COMPANY

 ...OPPORTUNITY FOR O.R. MEDICAL DEVICE SURGICAL/CAPITAL TERRITORY SALES REP MANAGER FOR SAN DIEGO! ******Fast track to hire a great candidate...  ...***4-year college degree Great benefits, Medical, Dental, and Vision, 401K great healthcare + ESOP! + Car Allowance....