Job Description
We are Digital Science and we are advancing the research ecosystem.Â
As our GRC Technical writer, you will be part of our Information Security team, overseeing our Governance, Risk and Compliance documentation. This role partners with several areas of Digital Science and adds value through contributing to a robust compliance framework to meet our ever evolving compliance requirements. You will be a member of a new sub-team, primarily responsible for the delivery and maintenance of compliance specific to large, US (Federal) customers with enhanced security and privacy requirements alongside providing support to the wider organization. This is a very important role which requires a high standard of communication and stakeholder management.Â
This role (due to Federal requirements) can only be satisfied by a âUS citizen, US national, or US personâ and additional checks may be required.
- Work with the stakeholders from across the group, our customer-base and third-party vendors/partners, to embed and enhance InfoSec compliance for products, services and business units under your purview.Â
- Writing, reviewing and updating information security policies, procedures, standards and guidelines spanning across several frameworks including FedRAMP, NIST and ISO 27001 primarily.Â
- Managing and maintaining a documentation inventory using existing GRC tool(s).
- Assist in drafting responses to risk assessments and where appropriate, audit responses and security questionnaires.
- Advising on the implementation of security controls, risk frameworks and alignment with regulatory and compliance frameworks.
- Assist in auditing controls across multiple security frameworks to identify gaps
- Collaborate with subject matter experts across the organization as a bridge between technical and infosec functions.
- Provide customers and auditors with documentation relating to security assessments and audits.
- Reporting to CISO, Deputy CISO, senior management and stakeholders in order to understand the performance of the system.
- You will have a demonstrable track record in GRC technical writing and tooling (Ideally utilizing Hyperproof or similar)
- You have significant, expert, professional experience in Information Security Compliance with demonstrable expertise spanning several frameworks simultaneously e.g. FedRAMP (to at least âmoderateâ level), DoD IL4 and NIST-800 (53 and 218 at a minimum).
- You have parallel knowledge of ISO/IEC 27001 and 27701 in order to compare, contrast and advise on meeting requirements and controls required to achieve and maintain FedRAMP compliance.Â
- You will have successfully contributed to a FedRAMP implementation programme utilizing consultants, third-parties and internal resources.Â
- Youâre highly organized and have the ability to work on intricate details without losing the big picture
- Youâll be a strong communicator and comfortable communicating with people at all organizational levels and leading conversations around recommendations for improvementsÂ
- You have a collaborative approach to how you work and ensure all groups are communicated with and understand your process and approachÂ
- Youâre a self learner and have an inquisitive mindÂ
- Youâre resourceful and solutions focussed, making practical considerations for all groups involvedÂ
- Youâre a natural problem solver and have strong analytical skillsÂ
- Bachelor degree in English, Technical Communication, Information Systems or a Cyber Security related field, and/or equivalent Information Security related certifications.
We're an equal opportunity employer. All applicants will be considered for employment without attention to race, colour, religion, sex, sexual orientation, gender identity, national origin, veteran or disability status
Additional Information
Please note that, in light of vaccination mandates for US Government contractors, Digital Science requires that all US-based employees are fully vaccinated against COVID-19, subject to approved accommodations.
Date Posted
05/25/2024
Views
15
Similar Jobs
Engineering Manager - Software Supply Chain Security: Auth Infrastructure - GitLab
Views in the last 30 days - 0
This job description highlights a leadership role in developing secure scalable authentication infrastructure for GitLab It emphasizes technical exper...
View DetailsStaff Salesforce Engineer - CRM Systems - GitLab
Views in the last 30 days - 0
This job description outlines a Staff Salesforce Developer role focusing on designing building and scaling enterprisegrade solutions across Salesforce...
View DetailsGrowth Product Lead - Loyalty - Trafilea
Views in the last 30 days - 0
Trafilea promotes itself as a transformative consumer tech platform with AIdriven growth solutions highlighting achievements like 1B revenue and globa...
View DetailsSales Prospecting Account Executive - Financial Solutions - Blackbaud
Views in the last 30 days - 0
This job posting seeks Prospect Account Executives to sell Financial Management applications for nonprofits and governments Responsibilities include s...
View DetailsSolutions Architect - phData
Views in the last 30 days - 0
This job posting seeks a Solutions Architect to join phDatas Elastic Platform Operations team focusing on cloudnative data platforms like Snowflake AW...
View DetailsTeam Lead - Publisher Success Management (AdTech) - MGID
Views in the last 30 days - 0
MGID is a fastgrowing digital advertising company seeking a resultsdriven Team Lead to oversee client relationships and drive business growth in the U...
View Details