Lead Business Technology Analyst- ISRMID_25

Thomson Reuters · East Bay

Company

Thomson Reuters

Location

East Bay

Type

Full Time

Job Description

Are you someone who is willing to not only find answers for your questions but brainstorm with others in your team? Someone who proactively finds solutions or brings ideas to the table before we encounter any issues? If the answer to this and other questions we have not added is a yes, then we are currently looking for a Lead within the FedRAMP, SOC & Customer Attestation Team to join our Cyber Governance & Compliance team as part of the ISRM function in Eagan or Richmond.

You will be a leader within the Cyber Governance & Compliance team who will ensure that the cyber security compliance program and all its moving parts are completed, reported, and tracked. You will manage external compliance to relevant programs such as the FedRAMP, CJIS, ISO & SOC policies/standards and external compliance to frameworks/regulations that ultimately sustains customer confidence in Thomson Reuters (TR).

About the Role

In this opportunity as Lead, FedRAMP, SOC & Customer Attestation Team, you will

  • Define and provide recommendations and actively participate in defining the control testing and regulatory assessment scope to be completed using TR's control framework.
  • Responsible for executing on all aspects of information security audits including FedRAMP, SOC 1, SOC 2, HIPAA, CJIS, ISO and Cyber Essentials Plus efforts including working with stakeholders, planning, preparation, control documentation, reporting and follow-up activities.
  • Be a subject matter expert for governance over control testing activities by working collaboratively and providing awareness to stakeholders as required.
  • Guide other team members on approach and steps to be followed when finalizing control population, sampling, re-testing, exception reporting and tracking requirements, reviewing work papers, the evidence submitted, finalizing remediation plans, etc.
  • Provide technical or compliance advice to teams/people responsible for programs, software, and information systems security.
  • Contribute to test one, cover many requirements approach and align with the long-term vision of automation of audit/testing.
  • Ensure all documentation and reporting meets the process and quality requirements of the Thomson Reuters ISRM Compliance function. This includes managing metrics for the team to reflect the volume and timeliness of assessments.
  • Manage and lead compliance or security projects / teams to achieve milestones and objectives on complex initiatives.
  • Come up with ideas to tackle a scenario, project or ad-hoc request and execute with minimal guidance.
  • Work independently on multiple initiatives simultaneously, and act decisively and with a high degree of autonomy.
  • Exhibit willingness and drive to learn continuously and approach change with openness.
  • Have a creative and diplomatic approach to solving problems while being customer driven.
  • About You

You are a fit for the role of Lead, SOC & Customer Attestation Team, if your background includes:

  • Bachelor's degree in IT, Accounting or equivalent education and experience.
  • At least 5+ years of relevant work experience in FedRAMP, CJIS, SOC, ISO, ITGC, PCI within Audit, Big 5, consulting firms or as line 1a or 1b completing IT-IS control testing or working within a Governance or Compliance function across Financial Services organisations.
  • One of these certifications in order of preference is essential CISA, CISSP, CCAK, CISM, CRISC.
  • Strong ethical principles and understanding of business and IS ethics.
  • Working knowledge of common security vulnerabilities of web and cloud applications and operating techniques from sources such as SANS, OWASP Top 10 and Cloud Security Alliance (CSA). Experience in testing Cloud controls and related technologies will be preferred.
  • Excellent oral and written communication skills in English. Additional expertise in French, Spanish or another language will be an asset.
  • Experience working with GRC platforms like ServiceNow, ProcessUnity, RSA Archer, MetricStream and like.

What's in it For You?

You will join our inclusive culture of world-class talent, where we are committed to your personal and professional growth through:

  • Hybrid Work Model: We've adopted a flexible hybrid working environment for our office-based roles while delivering a seamless experience that is digitally and physically connected.
  • Culture: Globally recognized and award-winning reputation for equality, diversity and inclusion, flexibility, work-life balance, and more.
  • Wellbeing: Comprehensive benefit plans; flexible and supportive benefits for work-life balance: two company-wide Mental Health Days Off; work from another location for up to a total of 8 weeks in a year, 4 of those weeks can be out of the country and the remaining in the country, Headspace app subscription; retirement, savings, tuition reimbursement, and employee incentive programs; resources for mental, physical, and financial wellbeing.
  • Learning & Development: LinkedIn Learning access; internal Talent Marketplace with opportunities to work on projects cross-company; Ten Thousand Coffees Thomson Reuters cafe networking.
  • Social Impact: Eight employee-driven Business Resource Groups; two paid volunteer days annually; Environmental, Social and Governance (ESG) initiatives for local and global impact.
  • Purpose Driven Work: We have a superpower that we've never talked about with as much pride as we should - we are one of the only companies on the planet that helps its customers pursue justice, truth and transparency. Together, with the professionals and institutions we serve, we help uphold the rule of law, turn the wheels of commerce, catch bad actors, report the facts, and provide trusted, unbiased information to people all over the world.

#LI-SMT2

Do you want to be part of a team helping re-invent the way knowledge professionals work? How about a team that works every day to create a more transparent, just and inclusive future? At Thomson Reuters, we've been doing just that for almost 160 years. Our industry-leading products and services include highly specialized information-enabled software and tools for legal, tax, accounting and compliance professionals combined with the world's most global news services - Reuters. We help these professionals do their jobs better, creating more time for them to focus on the things that matter most: advising, advocating, negotiating, governing and informing.

We are powered by the talents of 25,000 employees across more than 75 countries, where everyone has a chance to contribute and grow professionally in flexible work environments that celebrate diversity and inclusion. At a time when objectivity, accuracy, fairness and transparency are under attack, we consider it our duty to pursue them. Sound exciting? Join us and help shape the industries that move society forward.

Accessibility

As a global business, we rely on diversity of culture and thought to deliver on our goals. To ensure we can do that, we seek talented, qualified employees in all our operations around the world regardless of race, color, sex/gender, including pregnancy, gender identity and expression, national origin, religion, sexual orientation, disability, age, marital status, citizen status, veteran status, or any other protected classification under applicable law. Thomson Reuters is proud to be an Equal Employment Opportunity/Affirmative Action Employer providing a drug-free workplace.

We also make reasonable accommodations for qualified individuals with disabilities and for sincerely held religious beliefs in accordance with applicable law.

Protect yourself from fraudulent job postings click here to know more.

More information about Thomson Reuters can be found on https://thomsonreuters.com.

Date Posted

05/16/2023

Views

16

Back to Job Listings Add To Job List Company Profile View Company Reviews
Positive
Subjectivity Score: 0.8

Similar Jobs

Sr. Financial Analyst - Energy Recovery

Views in the last 30 days - 0

Energy Recovery is a company that builds sustainable products helping to limit global temperature rise reduce carbon emissions and provide safe drinki...

View Details

Senior Systems Infrastructure Engineer - BlackLine

Views in the last 30 days - 0

BlackLine is seeking a highly skilled Infrastructure Engineer to design build and manage corporate environments across Azure AWS and GCP platforms The...

View Details

Solution Manager, Workday - BlackLine

Views in the last 30 days - 0

BlackLine is a leading provider of cloud software that automates and controls the entire financial close process The company is committed to modernizi...

View Details

Sales Development Representative- French - Qualtrics

Views in the last 30 days - 0

Qualtrics is a company that creates software for top brands to enhance customer experiences team performance and product design They are looking for a...

View Details

Senior Software Engineer, Devices Automation - Block

Views in the last 30 days - 0

Square a company that has evolved since its inception in 2009 is seeking a Software Engineer with extensive experience in embedded devices and test en...

View Details

Growth Account Executive SMB - French - Klaviyo

Views in the last 30 days - 0

Klaviyo a company that values diverse backgrounds and perspectives is seeking an Account Executive with a minimum of 1 year of experience in carrying ...

View Details