Governance and Compliance Analyst - Culver City, United States - NavitsPartners

    NavitsPartners
    NavitsPartners Culver City, United States

    2 weeks ago

    Default job background
    Description

    Job Description

    Job Description

    Governance and Compliance Analyst (Intermediate)

    Personnel Qualifications:

    • A bachelor's degree in Computer Science or five (5) years of experience.
    • At least 10 years of experience with: FISMA, NIST, SOX, configuration and change management, CMMI, IT frameworks, ITIL, task order applications/technologies.

    Capabilities:

    • Ensure that all department operations occur within a prescribed framework are aligned with required performance metrics and service levels and comply with governance and compliance policies.
    • Stay abreast of, implement, maintain, and monitor industry best practices in information technology, compliance, security, and configuration management methodologies such as Capability Maturity Model (CMMI), Committee of Sponsoring Organizations (COSO)/ Sarbanes-Oxley (SOX), Federal Information Security management Act (FISMA), National Institute of Standards and Technology (NIST) guidelines Information.
    • Track, monitor and ensure application patches and security alerts are properly tested and implemented before the applicable deadline.
    • Ensure patches and alerts encompass all layers of the multi-tiered environment including applications, databases, servers and hardware.
    • Facilitate a clear understanding among all parties about security and compliance requirements.
    • Monitor access to information systems and database while protecting data storage.
    • Implement application access controls, such as password authentication.
    • Work with employees at all levels of the organization; work closely with other branches and divisions with the Board such as Information Assurance and Information Technology (IT).
    • Verify and validate user roles and access on a regular basis by distributing reports of use to system owners.
    • Ability to apply Information Technology Infrastructure Library (ITIL) framework.
    • Familiarity with audit requirements of external independent audit firms.