Senior Analyst, Security Governance, Risk, and Compliance - Philadelphia, United States - Jazz Pharmaceuticals

    Default job background
    Full time
    Description

    Brief Description:

    Jazz Pharmaceuticals is looking for an experienced Senior Analyst– Security Governance, Risk, and Compliance. Reporting to the Associate Director or Director, Security GRC, the Senior Analyst will assist in the oversight of the company's Security Governance, Risk, and Compliance program globally.

    We welcome an innovative individual that embraces challenges and offers creative solutions. This Senior Analyst is expected to possess strong process management and communication skills and subject matter expertise.

    Essential Functions/Responsibilities:

  • Support information security risk management programs.
  • Be the advocate for information security risk management, engage with stakeholders, supports the identification of security risks and risk exceptions to treatment.
  • Ensure identified security risks impacting the company are effectively evaluated and communicated.
  • Collaborate with stakeholders on remediation and risk mitigation activities, including tracking and progress of action plans across compliance, policy, and process gap remediation activities and risk mitigation activities in partnership with internal business partners.
  • Manage dashboards that deliver practical, meaningful security risk metrics to internal and external stakeholders.
  • Participate in technical design, process reviews, and support stakeholders in risk identification.
  • Assist in building a security-focused culture through partnership and collaboration with the business, information services, and other risk-related (., Quality, Legal, Compliance, teams to deliver value and improve the security posture of Jazz.
  • Required Knowledge, Skills, and Abilities:

  • A minimum of 3-5 years experience supporting security (technical and non-technical) risks
  • Excellent written and verbal communication skills; ability to convey security concepts to non-technical audiences (. senior and executive management, internal customers)
  • Ability to articulate and demonstrate a risk-relevant approach for Information Security Risk Management
  • Basic understanding of IT Systems, Network Security Concepts, Cloud Security concepts, Virtualization, Threat and Vulnerability Management etc.
  • Ongoing familiarity with emerging and prevalent technologies and IT systems
  • Strong analytical, risk-based problem solving and critical thinking skills and the ability to support decisions that balance Information security while also enabling business objectives
  • Ability to work independently on assigned tasks with minimal direction and/or supervision
  • Required/Preferred Education and Licenses:

  • Security certifications are a strong plus (CISSP, CRISC, CISM or equivalent)
  • Demonstrated ability to collaborate with technical and non-technical teams
  • Experience in working in a global cross-functional project teams, along with strong technical expertise preferred
  • Experience in security frameworks such as ISO 27001, 27002, 27005; NIST
  • Bachelor's degree preferred
  • FOR US-BASED CANDIDATES ONLY