What are the responsibilities and job description for the Senior Cybersecurity Analyst, GRC position at Visa?
Company Description
Visa is a world leader in digital payments, facilitating more than 215 billion payments transactions between consumers, merchants, financial institutions and government entities across more than 200 countries and territories each year. Our mission is to connect the world through the most innovative, convenient, reliable and secure payments network, enabling individuals, businesses and economies to thrive.
When you join Visa, you join a culture of purpose and belonging – where your growth is priority, your identity is embraced, and the work you do matters. We believe that economies that include everyone everywhere, uplift everyone everywhere. Your work will have a direct impact on billions of people around the world – helping unlock financial access to enable the future of money movement.
Join Visa: A Network Working for Everyone.
Job Description
This hands-on senior analyst position will serve as part of Visa's Cybersecurity GRC M&A team, providing oversight, coordination, and delivering the activities supporting successful risk management activities around acquired entities for VISA. Members of this team work across a number of stakeholders who work with acquired entities to ensure appropriate processes, procedures and controls are adequately designed, implemented or remediated to meet VISA security requirements and mitigate any risks that are associated to with acquired entities. The success of this unit requires dedicated professionals who possess the analytical, feasibility, relationship and executive summary skills needed to form highly reliable risk management strategies to meet various Visa Inc. requirements along with compliance and regulatory requirements.
Key responsibilities
- Perform risk/security assessments of acquired entities to identify, validate, and remediate risks. This may include performing interviews, documentation/configuration reviews, and control walkthroughs to determine the design and effectiveness of security controls implemented
- Lead risk/security assessments for special projects involving acquired entities. Lead PCI-related readiness activities to ensure compliance with PCI requirements
- Exhibit pragmatism in formulating process remediation and implementation strategies, defining work tracks, and submitting assessment findings and recommendations
- Develop trusted relationships with Business Partners, Visa IT Executives, Security & Compliance Officers and other team members to gain consensus approvals on strategies, recommendations, findings and project plans etc.
- Have an understanding of the broad regulatory landscape affecting Visa business areas remain current with emerging regulatory sentiments as well as solution trends in the marketplace
- Have an understanding of emerging technologies including but not limited to mobile and cloud technology. Contribute towards process improvement of team processes, templates and tools
This is a hybrid position. Hybrid employees can alternate time between both remote and office. Employees in hybrid roles are expected to work from the office two days a week, Tuesdays and Wednesdays with a general guidepost of being in the office 50% of the time based on business needs.
Qualifications
5 or more years of relevant work experience with a Bachelor’s Degree or at least 2 years of work experience with an Advanced degree (e.g. Masters, MBA, JD, MD) or 0 years of work experience with a PhD
Preferred Qualifications
o 6 or more years of work experience with a Bachelor’s Degree or 4 or more years of relevant experience with an Advanced Degree (e.g. Masters, MBA, JD, MD) or up to 3 years of relevant experience with a PhD
o Bachelor degree in Computer Science, Information Systems, Management Information Systems, or Business Administration or other related field. (Master degree is preferred.) Significant and relevant technical experience meeting the job description may be substituted for degree requirements.
o Must have 6 years of work experience including leadership roles in Cybersecurity, Audit, Risk, and/or Compliance. Open to experience in other relevant fields (e.g., finance, business administration, information technology, etc.) as long as candidate can demonstrate relevancy to this Cybersecurity based role.
o Must have 6 years direct participation and experience across common industry security policy areas, including, but not limited to ISO, NIST, COSO, COBIT, PCI, FFIEC, SOX, SSAE16, and others.
o Must have 6 years audit and risk management experience that includes a broad understanding of the software delivery process, professional services consulting and/or program management.
o Must have 6 years of experience auditing and/or testing controls in various Cybersecurity domains, including but not limited to, Access Management, Network Security, Cryptography, Secure Software Development Methodologies, Cloud Security, Operations Security, Security Monitoring, and Security Incident Management.
o Must have 6 years experience providing information security or information technology consulting services to a broad range of companies and/or federal and state agencies.
o Must have 6 years of progressively responsible management experience in the following areas- planning, budget/forecast/financial management, and staffing.
o Solid understanding of Enterprise Risk Management and Strategy frameworks as well as understanding of current enterprise threat scenario as related to financial industry.
o Demonstrated ability to manage implementations of large-scale, complex, multi-disciplined, cross-functional and highly visible projects/programs.
o In depth knowledge of
o Current information security and compliance vendor landscape
o Control frameworks such as COSO
o Regulatory requirements in particular PCI-DSS, GLBA, FFIEC
o Ability to direct and lead cross-functional, cross-vendor teams
o Must be experienced in Project Management Methodologies and experienced in mentoring less experienced project personnel
o Certified Information Security Auditor/Manager (CISA/M) designation or CISSP
o Excellent communicator with strong client relationship focus with business sponsors, enterprise architects, and information security engineers to articulate business case and technology options
o Practical experience managing multiple large-scale compliance/audit projects simultaneously, strong internal consulting, customer account management, and defining engagement scope, negotiating commitments, gathering requirements, defining deliverables, designing integrated solutions, and overseeing technical implementations considered a plus
o Proven experience proposing enterprise level solutions to mitigate risk
Additional Information
Work Hours: Varies upon the needs of the department.
Travel Requirements: This position requires travel 5-10% of the time.
Mental/Physical Requirements: This position will be performed in an office setting. The position will require the incumbent to sit and stand at a desk, communicate in person and by telephone, frequently operate standard office equipment, such as telephones and computers.
Visa is an EEO Employer. Qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, sexual orientation, gender identity, disability or protected veteran status. Visa will also consider for employment qualified applicants with criminal histories in a manner consistent with EEOC guidelines and applicable local law.
Visa will consider for employment qualified applicants with criminal histories in a manner consistent with applicable local law, including the requirements of Article 49 of the San Francisco Police Code.