Senior Governance Risk and Compliance Analyst

Cleary Gottlieb Steen & Hamilton LLP
New York, NY Other
POSTED ON 11/15/2023 CLOSED ON 4/3/2024

Job Posting for Senior Governance Risk and Compliance Analyst at Cleary Gottlieb Steen & Hamilton LLP

Overview

Cleary Gottlieb seeks a Senior Governance Risk and Compliance Analyst. Reporting directly to the Firm's Director of Information Security, the Senior Governance, Risk, and Compliance (GRC) Analyst is instrumental in safeguarding our Firm's data and meeting clients' security requirements. Serving as the primary point of contact for day-to-day ISO 27001 program management, and a full time member of our ISO Information Security Forum (ISF), this role will report on the performance of our Information Security Management System to the Firm’s Senior IT Leadership team and assemble key artifacts required by this program (metrics, meeting agendas, attaining ongoing compliance requirements, and assembling controls evidence). This role will lead our effort to upgrade to the ISO 27001:2022 standard, and pending strategic direction may also lead efforts to adopt the ISO 27701 Privacy Information Management System, ISO 27017 code of practice for cloud management, and other frameworks as required for adoption by our clients.

 

The Senior GRC Analyst will be our Firm’s primary point of contact for ongoing client security assessment requests.  As this role will be required to interface with 50-70 such requests throughout a year, the candidate shall ensure professional and error free work and look for efficiencies to best handle those which are repetitive in nature, including the curation of a standard answer/artifact bank, as well as using generative AI tools as approved for use.  This role will regularly interface with the Firm’s Risk Department and IT Leadership, as well as other departments as required, to answer questions effectively.  Taking any feedback from our client auditors, this role will be pivotal to inform the firm’s Information Security strategy in a measured manner.

 

The Senior GRC Analyst is a full-time member of the Firm's Information Security Department. They will collaborate with Senior Security Engineers to enhance core program elements, including incident response, assimilation of threat intelligence, vulnerability management, and continuous compliance processes.

Responsibilities

 

1. Client Assessment Response Program

  • Act as the primary point of contact to track, triage, and provide a professional response to incoming client assessments/audits, RFPs, and Outside Counsel Guidelines.
  • Curate a standard answer and evidence bank that ensures a consistent response to these client assessment requests.
  • Ensure that all material findings are tracked and escalated to Information Security Department management.
  • Work within IT, and to a lesser extent but also possible other departments within the Firm, to remediate control gaps and assemble evidence.

2. ISO 27001 Program Management

  • Work with external consultants to prepare ISF meeting agendas, metrics, and other artifacts for review by ISMS leadership.
  • Lead essential ISO 27001 activities such as our annual risk assessment, BCP tabletop exercises, and other periodic compliance checks (privileged account reviews, vulnerability assessments).
  • Prepare for annual internal and external ISO audits by reviewing all in scope assets and required controls; and preparing required evidence to competently demonstrate our program through the entire audit process.
  • Monitor and report on the management initiatives.

3. Governance and Compliance Framework:

  • Within the Information Technology Department, continue to develop a set of manageable controls that help support compliance with our clients security requirements, such as:
    • Producing privileged account management oversight controls.
    • Producing data loss prevention oversight controls.
    • Producing threat and vulnerability management oversight controls. 

4. Policy Development and Documentation

  • Develop and update policies and procedures to address evolving regulatory requirements.
  • Maintain a comprehensive repository of policies, ensuring accessibility and understanding across the organization.

Qualifications

  • Bachelor's degree in Information Systems, Information Security, Risk Management, or a related field.
  • Proven experience in governance, risk management, or compliance roles.
  • In-depth knowledge of relevant industry regulations and standards.
  • Strong analytical and problem-solving skills.
  • Excellent communication and interpersonal skills.
  • Ability to work collaboratively in a team and influence stakeholders at various levels.
  • Relevant certifications (e.g., CISA, CRISC, CISSP) are a significant plus, and if not presently held, one or more should be attained within 1 year of being in the job role.

 

The base salary for this position is $140,000 to $180,000. Actual pay is determined based on a number of job-related factors, including skills, education, training, credentials, experience, scope and complexity of role responsibilities, geographic location and performance.

 

At Cleary Gottlieb, all members of our community deserve respect as individuals and appreciation for the contributions they make to our community.  We champion diversity, equity, and inclusion, and creating equal opportunities to develop and succeed.

Lead Analyst, Governance, Risk, and Compliance
SiriusXM Radio, Inc. -
New York, NY
Associate Director, Compliance
Waystone Governance Ltd. -
New York, NY
GRC Regulatory Risk Governance Analyst
City National Bank -
New York, NY

Hourly Wage Estimation for Senior Governance Risk and Compliance Analyst in New York, NY
$86.91 to $116.94
If your compensation planning software is too rigid to deploy winning incentive strategies, it’s time to find an adaptable solution. Compensation Planning
Enhance your organization's compensation strategy with salary data sets that HR and team managers can use to pay your staff right. Surveys & Data Sets

Sign up to receive alerts about other jobs with skills like those required for the Senior Governance Risk and Compliance Analyst.

Click the checkbox next to the jobs that you are interested in.

  • Business Analytics Skill

    • Income Estimation: $152,076 - $221,649
    • Income Estimation: $153,919 - $199,878
  • Business Process Modeling/Improvement Skill

    • Income Estimation: $155,219 - $219,724
    • Income Estimation: $166,623 - $214,944
This job has expired.
View Core, Job Family, and Industry Job Skills and Competency Data for more than 15,000 Job Titles Skills Library

Job openings at Cleary Gottlieb Steen & Hamilton LLP

Cleary Gottlieb Steen & Hamilton LLP
Hired Organization Address New York, NY Other
Overview The position reports to the E-Billing Manager and assists in all phases of client billing, including submission...
Cleary Gottlieb Steen & Hamilton LLP
Hired Organization Address New York, NY Other
Overview The Managing Attorney’s Office (MAO) supports and assists the firm’s practice groups – primarily the Litigation...

Not the job you're looking for? Here are some other Senior Governance Risk and Compliance Analyst jobs in the New York, NY area that may be a better fit.

Lead Analyst, Governance, Risk, and Compliance

Sirius XM Radio, New York, NY