Virtru

Security Governance, Risk & Compliance Analyst

Virtru

full-time

Posted on:

Origin:  • 🇺🇸 United States • District of Columbia, Washington

Visit company website
AI Apply
Apply

Salary

💰 $130,000 - $180,000 per year

Job Level

Mid-LevelSenior

Tech Stack

AWSAzureCloudGoogle Cloud PlatformJavaScriptPythonSplunk

About the role

  • Manage and implement complex controls frameworks for large systems, consisting of Cloud infrastructure and Software as a Service (SaaS) services (GCP, AWS, GitHub, Okta, etc).
  • Design and develop automation solutions for evidence collection across Cloud infrastructure, endpoints, and SaaS services.
  • Conduct risk assessments across business units and processes. Identify risk findings and recommend remediation and risk mitigation strategies.
  • Assist or implement automated controls to support risk mitigation efforts across various business units with stakeholders.
  • Incorporate CMMC certification into Virtru’s slate of compliance assessments and ongoing monitoring activities (FedRAMP, SOC 2, PCI).
  • Facilitate the third-party vendor on-boarding and annual review process by evaluating the security of current and prospective partners.
  • Participate in incident response (IR) activities, providing risk analysis and remediation support as needed.
  • Enhance the team with your individualism, spirit, and love of learning.

Requirements

  • Minimum of 5+ years of information security, IT audit and/or IT Risk Management, or GRC Analyst/Engineer experience
  • Deep understanding of at least few of the following: CMMC, NIST 800-53 & 800-171, FedRAMP, SOC 2, PCI, and/or other global privacy compliance frameworks
  • Technical acumen. Strong understanding of modern cloud technologies (AWS, GCP, Azure, etc.) and familiarity with GRC tools (Hyperproof, Vanta, Drata, etc) and SIEM tools (Datadog, Splunk)
  • You’re a relationship builder and have worked with both business and technical risk and understand how to translate risk to various levels of the organization
  • Have experience training and coaching teams to become better security and privacy practitioners
  • Like working on an autonomous agile team. At Virtru, you will have ownership of security, but you'll collaborate with everyone to make sure we produce and implement the right solutions
  • Ability to resolve conflicts and drive issues to completion.
  • Work independently with little or no supervision while maintaining a high level of efficiency.
  • Hands on experience deploying and managing vulnerability scanning/cloud security posture management tools (Wiz, Prismacloud, etc.) to meet security compliance requirements
  • Real-world IR experience participating on security On-Call teams
  • Basic knowledge of scripting languages like Bash, Python, or Javascript to automate manual tasks
  • Familiarity with GitOps and Infrastructure-as-Code concepts
Dragonfli Group

Senior Splunk Cybersecurity Engineer – Architect/SME

Dragonfli Group
Seniorfull-time🇺🇸 United States
Posted: 33 days agoSource: www.comeet.com
AWSAzureCloudCyber SecurityGoogle Cloud PlatformJavaScriptLinuxPythonSplunkSQLUnix
CVS Health

Staff Security Engineer

CVS Health
Leadfull-time$130k–$261k / yearWashington · 🇺🇸 United States
Posted: 39 days agoSource: cvshealth.wd1.myworkdayjobs.com
AWSAzureCloudGoogle Cloud PlatformJavaScriptPythonSplunkSQL
Dragonfli Group

Cybersecurity Engineer – Splunk SME

Dragonfli Group
Mid · Seniorfull-time🇺🇸 United States
Posted: 33 days agoSource: www.comeet.com
AWSAzureCloudCyber SecurityGoogle Cloud PlatformJavaScriptLinuxPythonSplunkSQLUnix
General Dynamics Information Technology

Splunk Cyber Security Architect/Engineer

General Dynamics Information Technology
Senior · Leadfull-time$144k–$195k / year🇺🇸 United States
Posted: 40 days agoSource: gdit.wd5.myworkdayjobs.com
AWSAzureCloudCyber SecurityGoogle Cloud PlatformJavaScriptLinuxPythonSplunkSQLUnix
Maveris

Cybersecurity Implementation Engineer

Maveris
Mid · Seniorfull-timeDistrict of Columbia, Illinois · 🇺🇸 United States
Posted: 13 days agoSource: apply.workable.com
AWSAzureCloudCyber SecurityGoogle Cloud PlatformJenkinsSplunk