Cybersecurity Compliance Analyst
Cummins Inc. · Columbus, IN · Today
On-siteLegalFull-time
Overview
We are seeking a Cybersecurity Compliance Analyst to join our Systems/Information Technology team at Cummins in Columbus, IN. This role involves leading cybersecurity risk identification and assessment, providing guidance on risk mitigation, and collaborating with various stakeholders.
Responsibilities
- Lead cybersecurity risk identification and assessment efforts, ensuring threats are evaluated and prioritized.
- Provide expert guidance on risk severity, mitigation strategies, and control implementation.
- Serve as a trusted advisor to business and technology stakeholders, influencing secure technology decisions and promoting cybersecurity best practices.
- Apply Cummins cybersecurity policies and data privacy principles to protect critical systems, information, and business operations.
- Leverage industry frameworks like NIST, ISO, ITIL, and COBIT to align security controls with organizational processes and compliance requirements.
- Deliver technical cybersecurity expertise for new and existing technology solutions, ensuring secure design, deployment, and ongoing operations.
- Build and maintain strong cross-functional relationships that drive collaboration, trust, and measurable business value through effective Business Relationship Management practices.
- Coach, mentor, and develop less experienced team members, fostering a culture of continuous learning, accountability, and cybersecurity excellence.
- Review and respond to customer cybersecurity surveys, translating technical information into clear, accurate, customer-appropriate responses.
- Support HIPAA cybersecurity compliance activities, gathering and organizing information related to administrative, physical, and technical safeguards.
- Support PCI DSS compliance activities, coordinating with stakeholders to obtain accurate information and evidence.
- Identify information owners and coordinate across teams to collect required documentation, evidence, and approvals.
- Track and report status for PCI, HIPAA, and customer request activities, preparing compliance summaries and status updates.
- Identify recurring trends, process gaps, and improvement opportunities across compliance response workflows and knowledge management practices.
Requirements
- Action oriented - Taking on new opportunities and tough challenges with a sense of urgency, high energy, and enthusiasm.
- Balances stakeholders - Anticipating and balancing the needs of multiple stakeholders.
- Business insight - Applying knowledge of business and the marketplace to advance the organization’s goals.
- Holds accountability - Holding self and others accountable to meet commitments.
- Manages complexity - Making sense of complex, high quantity, and sometimes contradictory information to effectively solve problems.
- Organizational savvy - Maneuvering comfortably through complex policy, process, and people-related organizational dynamics.
- Persuades - Using compelling arguments to gain the support and commitment of others.
- Resourcefulness - Securing and deploying resources effectively and efficiently.
- Tech savvy - Anticipating and adopting innovations in business-building digital and technology applications.
- Training Delivery - Instructs learners in a manner that engages and adjusts to individual and group needs resulting in knowledge, skills, and abilities that can be applied on the job.
- Cybersecurity Risk Management - Identifies and assesses the potential impact of Cybersecurity risks against established Cybersecurity industry frameworks, regulations, and organizational policies to develop and implement risk mitigation strategies in alignment with business objectives.
- Regulatory Risk Compliance Management - Evaluates the design and effectiveness of controls against established industry frameworks and regulations to assess adherence with legal/regulatory requirements.
Qualifications
- College, university, or equivalent degree in Cybersecurity, Computer Science, or Information Technology, or related subject, or relevant equivalent experience required.
- This position may require licensing for compliance with export controls or sanctions regulations.
Education, Licenses, Certifications
- College, university, or equivalent degree in Cybersecurity, Computer Science, or Information Technology, or related subject, or relevant equivalent experience required.
- This position may require licensing for compliance with export controls or sanctions regulations.