Unfortunately, this job posting is expired.
Don't worry, we can still help! Below, please find related information to help you with your job search.
Some similar recruitments
Sr. Manager – Governance Risk And Compliance
Recruited by Saviynt 9 months ago Address , El Segundo $190,000 - $215,000 a year
Analyst, It Governance, Risk, & Compliance
Recruited by Frontier Airlines, Inc 1 year ago Address , Denver, 80239, Co
Risk And Opportunity Lead
Recruited by SciTec, Inc. 1 year ago Address Boulder, CO, United States

Associate It Governance, Risk, And Compliance Analyst - Technology Services

Company

City and County of Denver

Address , Denver
Employment type FULL_TIME
Salary $68,905 - $113,693 a year
Expires 2023-09-17
Posted at 9 months ago
Job Description
About Our Job
We encourage you to apply as soon as possible because this posting may close without advanced notice.
The City and County of Denver utilizes a hybrid model workplace that balances the responsibilities of public service with the benefits of a flexible work environment. Employees work where needed, at a city site and/or in the field several days a week and telecommute remotely at a designated workplace within the State of Colorado the remaining days.
About Technology Services
The Technology Services Department (TS) of the City and County of Denver use state-of-the-art technologies and methodologies to deliver and improve the systems, applications, and operations to our customers. Technology Services supports the people, agencies, and ideas that make the City and County of Denver a world-class city. The city offers a unique opportunity to work with a diverse business and technology environment on a large scale as we employ more than 13,000 people, of which 9,000+ are daily technology consumers in support of a diverse population over 700,000 Denverites.
About the Data Tools and Governance Division
The Data Tools and Governance Division connects both internal and external customers to information and services by providing the access, framework, tools and expertise required to fully leverage the City's data and information assets. Data is dedicated to transforming Denver’s access to and use of data to drive strategy, policy, and operations. The security team plans and implements security governance and controls, monitors and responds to cyber threats and vulnerabilities.
Diversity in the City
The City and County of Denver is committed to cultivating a culture of equity, diversity, and inclusion. This commitment is woven into our values and belief that we are strongest when we embrace and celebrate our differences. We aim to have employees who are as diverse as our residents, with different perspectives and unique ways of thinking. If you share these values and our enthusiasm for equity, we encourage you to apply to join our team.
The Technology Services Agency (TS) within the City and County of Denver (CCD) is seeking a Governance, Risk, Compliance Analyst (GRC) holistically. The selected candidate for this position will be tasked with ensuring risk and vulnerabilities are viewed not only from a system security standpoint, but also from the lens of the end user and application. In this position, you will also be a key stakeholder in the CCD GRC Team.
Specifically, you will focus on managing the CCD Technology Services (TS) Policies and Standards and ensuring all Citywide Technology Service Policies are reviewed and updated annually. Additionally, you will assist with policy stakeholders on policy language and, at times, take the lead on policy and standard creation when identified. In this position, will also work closely with the City & County of Denver Auditors Office serving as the liaison between the auditors and technology services staff, assisting with providing deliverables, briefing Technology Services leadership on audit engagement status and potential audit findings. You will also advise and at times draft audit finding recommendation responses, manage and coordinate external audits for TS, periodically audit system user permissions and make recommendations on user access ensuring appropriate permissions are provisioned and admin permissions are restricted to only those with a business need.
In this position, you will also support other GRC activities such as approval/denial of third-party file share utilization, and other governance, risk, and compliance activities such as assessing for risk, ensuring compliance with various regulatory requirements.
Additionally, as the Associate Governance, Risk, and Compliance Analyst, you can expect to:
  • Work with TS Stakeholders to annually review and publish policies providing best practices guidance and policy direction
  • Act as an ongoing liaison and G,R,C subject matter expert for other CCD Agency’s and advise on best practices to reduce risk and promote regulatory compliance
  • Assist in the collection/creation of audit deliverables
  • Review access roles and permissions, ensuring proper safeguards and user business need for access within TS governed applications
  • Work with TS stakeholders and advise on implementation of internal controls and safeguards in response to audit findings
  • Utilize ServiceNow to approve third party file share permission requests
  • Collaborate with the CCD Auditors Office throughout audit engagements
  • Collaborate with various CCD Agencies during audit engagements and other GRC oversight activities
  • Perform other duties as assigned or requested.
  • Utilize ServiceNow to manage TS audits and policies
  • Collaborate with technology services teams and various CCD Agency’s to mitigate identified risk
About You
The ideal candidate will have a background in Governance, Risk, and Compliance, policy creation, and/or audit experience. Experience with policy writing and technical writing skills are preferred. Knowledge of information security and other technical terms is preferred. Additionally, we are looking for someone with knowledge and experience with application and compliance of below regulations:
  • US Department of Commerce, National Institute of Standards and Technology (NIST), Cybersecurity and Privacy Frameworks
  • By position, must obtain Criminal Justice Information Services (CJIS) clearance within the probationary period
  • US Department of Health and Human Services, Health Insurance Portability and Accountability Act (HIPAA)
  • US Department of Justice, Federal Bureau of Investigation, Criminal Justice Information Services Security (CJIS) Policy
  • Payment Card Industry Data Security Standard (PCI-DSS)
We realize your time is valuable so please do not apply if you do not have at least the following required minimum qualifications:
  • Experience: Two (2) years of administering information security systems to include any or all of the following: information security architecture, information security procedures and controls, physical security, attack & penetration testing, application testing, information assurance program gap analysis and incident response
  • Education: Bachelor's Degree in Computer Science, Information Systems, Business Administration, Mathematics or a related field
  • Education & Experience Equivalency: One (1) year of the appropriate type and level of experience may be substituted for each required year of post-high school education. Additional appropriate education may be substituted for the minimum experience requirements
About Everything Else
Job Profile
CI3293 IT Security Analyst Associate
To view the full job profile including position specifications, physical demands, and probationary period, click
here
.
Position Type
Unlimited
Position Salary Range
$68,905.00 - $113,693.00
Starting Pay
Based on experience and education
Agency
Technology Services
The City and County of Denver provides equal employment opportunities to all employees and applicants for employment without regard to race, color, religion, national origin, sex, sexual orientation, gender identity, national origin, disability, genetic information, age, or any other status protected under federal, state, and/or local law.
For information about right to work, click
here
for English or
here
for Spanish.