We are currently seeking a cybersecurity and risk management analyst to work closely with our consultants and IT personnel on internal and client-sourced cybersecurity posturing and regulatory compliance projects. The candidate is expected to work across different levels of the organization to ensure cybersecurity and regulatory compliance controls are well-defined, properly implemented and always compliant, whether within our organization or at our clients’ organizations that outsource their risk management needs to our company.
As a Cybersecurity and Risk Management Analyst, you will leverage your analytical, technical and inter-personal communication skills to coordinate with different roles within the organization to maintain a good grasp of the risk profile of that organization, whether it is Mobius Logic’s risk profile or the risk profile of a client of Mobius Logic. You will also be responsible to work with the organization leadership on defining the parameters of its risk profile and the standards and regulatory framework to which it needs to comply with. On any given day you will be challenged on three types of work:
Business Analysis
- Your role will be to link between the information technology capacity and the business objectives (which would include cybersecurity and regulatory compliance objectives) by supporting and ensuring the successful implementation of cloud and non-cloud-based IT systems.
- Identifying areas that can be improved, strengthening processes where necessary and communicating findings with those you work closely with throughout the different levels in the organization.
Cybersecurity
- Ensuring that operating systems are safe given the cybersecurity profile adopted by the organization and establishing cybersecurity strategies and implementing tactics to achieve strategic cybersecurity goals.
- Participate and potentially lead in incident response plan executions and post-op briefings and corrective actions.
- Stay up to date on cybersecurity trends, vulnerabilities, and threat management systems.
Regulatory Compliance
- Ensuring that regulatory controls, codes, and policies are well documented and implemented as desired by the organization. This may include controls from a variety of regulatory bodies, such as the FDA, FAA, SEC, HHS, EU, etc.
- Acting as a liaison between different functions within the organization to ensure proper communication and understanding of the regulator controls.
- A Master’s degree in IT/Computer Science or any related field.
- Any additional certification in Cybersecurity would be a plus.
- Previous experience in Business/Systems Analysis.
- A minimum of 7 years’ experience working with cybersecurity and regulatory compliance programs.
- Knowledge of the related federal and state rules and regulations.
- Demonstrated experience with at least two regulatory frameworks (e.g. SOX< SOC 2, ISO, NIST, COSO, HITRUST, FDA Title 21, CMMC, etc.).
- Familiarity with common compliance standards (SOX, SOC2, PCI-DSS, GDPR, COSO, COBIT, CMMC, NIST 800-171, NIST 800-53, and/or ISO 27001) and experience working directly with internal or external auditors for at least one of the listed standards.
- Experience in analyzing data to draw business-relevant conclusions and in data visualization techniques and tools.
- Work with senior business stakeholders to define and deliver prioritized roadmaps, strategies and solutions to meet our evolving business needs.
- Ensure our existing production infrastructure, application support and environments are maintained to deliver exceptional service levels to our users and clients.
- Working understanding of how compliance works with cloud-native technology stacks.
- Solid experience with technical programs such as information systems, network security, and any other related field.
- Basic knowledge in generating process documentation.
- Exceptional interpersonal skills.
- Strong written and verbal communication skills including technical writing skills.
- Excellent problem-solving skills.
- Analytical mindset.
- Strong work ethic with excellent attention to detail.
- Willingness to learn, and adaptability to understand and create new procedures.