
Security Analyst, GRC
2 days ago
Security Analyst - GRC
At CDK, the Security Analyst provides comprehensive information security risk management services across the organization. The analyst is responsible for operating the current program, identifying opportunities to uplevel the program and implement identified improvements. This role involves close coordination with business stakeholders, information security governance, and other security functions to ensure robust security practices and risk management across the whole CDK Enterprise.
Key Responsibilities
Leadership & Strategy:
- Exemplify security principles and culture
- Effectively partner across security, technology, and business teams
- Be a thought leader on matters of security risk to business and technology partners
Third Party
- Support the full lifecycle of Third Party Risk Management from onboarding to offboarding
- Conduct initial and ongoing risk assessments of third-party vendors to identify potential privacy and security risks
- Request, track, and analyze vendor due diligence documentation (e.g., SIG questionnaires, SOC reports, security policies)
- Coordinate with internal stakeholders and vendors to identify, document, and monitor risk remediation efforts
- Evaluate vendor cybersecurity controls and align with the organizations risk management framework
- Collaborate with Contracts/Procurement teams on reviews related to vendor engagements
Business Continuity And Disaster Recovery
- Works with stakeholders (e.g., department managers, project managers, and systems administrators) at different levels in the organization to understand their respective resilience needs and assists with implementing practices and procedures consistent with CDK policies and standards.
- Conducts business impact analysis, facilitates creation Business Continuity & Disaster Recovery Plans, and conducts tabletop exercises.
- Develops dependency mapping models representing capabilities and relationship with the respective applications in preparation for failover projects and the creation of runbooks and DR plans.
- Partners with other IT groups to conduct service resilience and continuity risk assessments on new solutions and systems, ensuring they align with our resilience standards and reference architecture requirements.
- Helps support and maintain all disaster recovery related workstreams end to end.
Required Qualifications
- Bachelor's degree or higher in cybersecurity or a related field, or an equivalent experience.
- Minimum of 4 years of experience in security, with at least 2 years in risk assessments, BCDR, or TPRM.
- Relevant certifications such as CISM, CRISC, CISSP, and cloud certifications are highly desirable.
- Strong logical, critical thinking, and problem-solving skills.
- Extensive knowledge of Cyber Security and Risk in the context of application security (AppSec), cloud security, and IT infrastructure.
At CDK, we believe inclusion and diversity are essential in inspiring meaningful connections to our people, customers and communities. We are open, curious and encourage different views, so that everyone can be their best selves and make an impact.
CDK is an Equal Opportunity Employer committed to creating an inclusive workforce where everyone is valued. Qualified applicants will receive consideration for employment without regard to race, color, creed, ancestry, national origin, gender, sexual orientation, gender identity, gender expression, marital status, creed or religion, age, disability (including pregnancy), results of genetic testing, service in the military, veteran status or any other category protected by law.
Applicants for employment in the US must be authorized to work in the US. CDK may offer employer visa sponsorship to applicants.
-
SAP GRC and Security Consultant
1 week ago
Hyderabad, Telangana, India IDESLABS PRIVATE LIMITED Full time US$ 60,000 - US$ 1,20,000 per yearAny Bachelors degree in IT, Engineering, or related field. 46 A GRC Consultant is an experienced GRC professional who supports enterprise wide GRC initiatives such as assessing current state, developing a strategy, and selecting and implementing GRC tools and frameworks.A Security Consultant assesses, designs, and implements security measures for...
-
GRC Security Engineer
1 week ago
Hyderabad, Telangana, India SinglePoint Solutions Full time ₹ 54,300 - ₹ 18,08,741 per yearRole: GRC Security Engineer ( 6-8 years)Duration: FulltimeLocation: HyderabadWe're looking for a "Security Engineer" with a tech-first mindset that can help grow and enhance Nordstrom's Cybersecurity and Privacy Organization. We work to make technology the easiest part of our internal customers' jobs. This position will enable process clarity and efficiency...
-
GRC Security Engineer
1 week ago
Hyderabad, Telangana, India Singlepoint Solutions Full time US$ 1,25,000 - US$ 1,75,000 per yearWe're looking for a "Security Engineer" with a tech-first mindset that can help grow and enhance Nordstrom's Cybersecurity and Privacy Organization. We work to make technology the easiest part of our internal customers' jobs. This position will enable process clarity and efficiency and create new insights empowering Nordstrom for decades to come.As an...
-
SAP GRC Security consultant
1 week ago
Hyderabad, Telangana, India IDESLABS PRIVATE LIMITED Full time ₹ 9,00,000 - ₹ 12,00,000 per yearKey Responsibilities:Configure and support SAP GRC modules (ARA, BRM, ARM, EAM)Perform SoD analysis and manage risk violationsDesign and maintain SAP roles and authorizationsHandle user provisioning and access issuesCollaborate with audit/compliance teams (SOX, GDPR)Support security-related transports and documentationRequirements:4+ years in SAP Security...
-
Hyderabad, Telangana, India MosChip Full time ₹ 5,00,000 - ₹ 8,00,000 per yearJob Overview:A GRC Analyst assists in managing and ensuring compliance with regulatory requirements and internal policies. Work closely with analysts and other stakeholders to support risk management and compliance activities.Key Responsibilities:Risk AssessmentsConduct risk assessments and validation testing to identify potential security threats.Compliance...
-
Information Security Risk Analyst
6 days ago
Hyderabad, Telangana, India Citratech IT Services Private Limited Full timeJob DescriptionClient's Digital Assets is seeking an experienced Information Security Risk Analyst to support the implementation and ongoing compliance of ISO27001 and SOC2 frameworks. This role will be responsible for conducting risk assessments, identifying control gaps, and collaborating with cross-functional teams to develop and monitor remediation...
-
SAP BASIS Security + GRC
5 days ago
Hyderabad, Telangana, India HGS Full time ₹ 9,00,000 - ₹ 12,00,000 per yearPosition: SAP BASIS Security GRCLocation: Hyderabad, Indore, Bangalore IndiaDuration: Full timeJob description:Design and implement SAP security roles and authorizations across various SAP systems (ECC, BW, S/4HANA, GRC, Fiori, etc.). Perform user provisioning, deprovisioning, and access management. Investigate and resolve SAP security issues, authorization...
-
Principal Consultant, SAP Security/GRC
1 week ago
Hyderabad, Telangana, India Genpact Full timeJob DescriptionReady to build the future with AIAt Genpact, we don't just keep up with technology-we set the pace. AI and digital innovation are redefining industries, and we're leading the charge. Genpact's AI Gigafactory, our industry-first accelerator, is an example of how we're scaling advanced technology solutions to help global enterprises work...
-
Cyber Security Lead Analyst
1 week ago
Hyderabad, Telangana, India Cigna Healthcare Full time US$ 90,000 - US$ 1,20,000 per yearCyber Security Lead Analyst, GRC Developer - HIH - EvernorthPosition Summary:We are seeking a talented and experienced GRC (Governance, Risk and Compliance) Developer to join our team. The current GRC platform is Onspring. As a GRC Developer, you will be responsible for designing, developing, and implementing customized solutions within the Onspring platform...
-
Cyber Security Lead Analyst
1 week ago
Hyderabad, Telangana, India Cigna Healthcare Full time US$ 90,000 - US$ 1,20,000 per yearCyber Security Lead Analyst - HIH - EvernorthPosition Summary:We are seeking a talented and experienced GRC (Governance, Risk and Compliance) Developer to join our team. The current GRC platform is Onspring. As a GRC Developer, you will be responsible for designing, developing, and implementing customized solutions within the Onspring platform to meet...