Info Sec GRC Analyst III Job at PSECU, Harrisburg, PA

YXF6MmxJdTBJMDl4M2JhdU1NNEtTV2NnN2c9PQ==
  • PSECU
  • Harrisburg, PA

Job Description

Members Achieve More isn't just a tagline for us, it's part of everything we do! We're looking for passionate individuals to join our team to help us maintain that focus every day. Want to work somewhere that's remained strong for 90 years, that encourages you to learn, grow, and pursue your dreams? If yes, then read on...

The Information Security GRC Analyst III is responsible for analyzing and assessing the information security controls in an effort to protect the confidentiality, integrity, and availability of PSECU's information. The individual is responsible for ensuring network and cloud security access and for implementing and documenting measures to safeguard the network against accidental or authorized modifications, destruction, or disclosure.

Schedule: Monday - Friday 9:00am - 5:00pm

In this position, you will

  • Monitor Compliance: Assist in protecting the integrity, availability and confidentiality of network resources and data. Assist in the development and enforcement of security policies, standards, and procedures. Participate in network, system, and application vulnerability assessments, generate report findings, and oversee remediation activities. Participate in the monitoring and periodic testing of IT compliance controls to ensure ongoing adherence to PSECU policies, standards, and industry frameworks for both cloud and on-prem solutions.

  • Control and Risk Assessments: Perform or coordinate control testing, assessments, and monitoring to ensure that Information Technology processes and controls are effective, functioning as designed, and managed to the appropriate level of risk. Coordinate IT self-assessment compliance reviews based on regulatory, industry standards, and internal policy requirements. Evaluate any related external frameworks or standards ((e.g., ITIL, COBIT, National Institute of Standards and Technology [NIST], ISO 27002, Center for Internet Security Critical Security Controls (SANS 20) etc.) or internal policies/standards (e.g., code of conduct, record retention, and acceptable use, etc.) to determine the relevant IT compliance requirements and controls. Independently conduct risk assessments to identify gaps in the control structure.

  • Vendor Due Diligence: Participate in the vendor management and due diligence process. Consult with business units when negotiating and contracting third-party service provider arrangements to ensure associated information security risks are considered. Perform necessary due diligence activities to determine third-party adherence with IT compliance requirements prior to establishing a business relationship.

  • Incident Response: Participate in or conduct incident response investigations by using and understanding PSECU's Incident Management procedures. Participate in the Incident Management Program in order to plan and respond effectively to a compromise of PSECU's IT infrastructure or to an unauthorized access and/or disclosure of sensitive company, member, or employee data. Review SIEM, operational logs, and event console activity to identify and determine the cause of security related events.

  • Awareness Program: Assist in developing Information Security and Privacy Awareness content employees, members. Assist in socializing PSECU Policies and Standards to PSECU employees.

  • Internal Audit Coordination: Collect evidence for internal and external audits. Research and respond to internal and external audit finding

  • Other duties as assigned.

Qualifications:
Bachelors: Computer and Information Science, Bachelors: Information Technology, Bachelors (Required)

Any equivalent combination of experience and education. | RequiredFour - Six years of experience in CyberSecurity, Information Security, Auditing, Risk Management, Information Assurance, and/or work supporting and maintaining a network or cloud environment. | Required

Certified Information Security Manager (CISM) - ISACA (Information Systems Audit and Control Association), Certified Information System Auditor (CISA) - ISACA (Information Systems Audit and Control Association), Certified Information Systems Security Professional (CISSP) - ISC2

Job Tags

Monday to Friday

Similar Jobs

Paradym Trucking

Class A CDL - Solo Company - .60+ cpm - Dry Van - No touch - Drop & Hook Job at Paradym Trucking

Paradym Trucking is searching for qualified CDL A Drivers with at least 12 months of driving experience that are interested in joining our team. If you're a driver looking for a new home that has great miles and great pay, APPLY today! Qualifications : 12 months...

Beemac Trucking

CDL-A Flatbed Owner-Operator Jobs - Savannah, GA Job at Beemac Trucking

 ...OverviewTop 10 National Flatbed Carrier | High-Paying Regional & OTR FreightBeemac Trucking is now hiring experienced CDL-A Flatbed Owner-Operators in Savannah, GA , and surrounding areas. Whether you're an established owner-operator or ready to grow your flatbed business... 

The Vallejo Company

General Application Job at The Vallejo Company

 ...willing to join them for these roles. If you are not part of a union and have little to no experience, but still want to join our team, please advise and complete our apprenticeship application. This description is designed as an overview and does not represent every... 

Chewy

1099 Relief Veterinarian - Dallas, TX - Chewy Vet Care Job at Chewy

 ...Job Description: At Chewy Vet Care, we're changing the veterinary care experience from the ground up! Chewy Vet Care is seeking Relief Veterinarians to complete and support staffing/coverage needs at our hospitals. The ideal candidate must be able to multitask in... 

Allspring Global Investments

Performance Analyst Job at Allspring Global Investments

 ...Performance Analyst Location US-WI-Milwaukee ID 2026-1161 Position Type Full-Time Category Global Investment Services Overview Performance analyst will be responsible for calculating and reviewing Composite level...