Governance Analyst III
About the role
Under the direction of the Director, Information Security Operations, the Governance Analyst III is responsible for the strategic oversight and leadership of the enterprise's information security and data privacy governance framework. This senior-level position focuses on the development, implementation, and continuous improvement of comprehensive security and privacy policies, standards, baselines, and guidelines to protect enterprise assets, safeguard sensitive and personal data, and ensure the confidentiality, integrity, availability, and appropriate use of information in compliance with applicable privacy regulations. This role leads high-impact security and privacy initiatives, conducts advanced risk and privacy impact assessments, and drives the adoption of leading practices across the organization. This role requires a deep understanding of information security frameworks, privacy principles (e.g., data minimization, purpose limitation, and protection by design), industry standards, emerging threats, and regulatory requirements (e.g., PCI DSS, CCPA/CPRA, and other applicable privacy laws).
Responsibilities
- Regularly mentors and provides guidance to team members in the development of security and privacy policies, standards, and procedures, ensuring alignment with regulatory requirements and business objectives.
- Coaches staff on integrating privacy-by-design principles into governance processes and control development.
- Leads all Payment Card Industry (PCI) efforts, including tracking remediation of control gaps and escalating critical issues to senior management. Acts as a cross-functional lead to ensure compliance readiness.
- Ensure that cardholder data and other sensitive personal information are handled in accordance with privacy and data protection requirements.
- Engage with business units to identify security and privacy risks, facilitating risk assessments including Privacy Impact Assessments (PIAs) and Data Protection Impact Assessments (DPIAs) where applicable. Tracks mitigation plans and enhances enterprise risk management capabilities.
- Leads vendor risk management efforts, including vendor intake and review process.
- Develops and enhances metrics for Information Security and Privacy risk reporting dashboards, including key risk indicators (KRIs) related to data protection, regulatory compliance, and incident trends that inform executive decision-making and prioritize remediation efforts based on business impact.
- Leverage specialized knowledge to guide project and operational decisions, clearly communicating security and privacy policies, regulatory requirements, and best practices to stakeholders across the enterprise.
- Contribute to training and awareness initiatives, promoting security and privacy awareness, secure data handling practices, and compliance obligations among functional leaders, system owners, and employees.
- Performs other duties as assigned to support the efficient operation of the department, including support for privacy incident response, breach notification coordination, and regulatory inquiries as needed.
Qualifications
Bachelor's degree in information security, technology, statistics, mathematics, or related field required. Minimum six (6) years of experience in documentation, procedures and/or policies of information technology, information systems, risk management, controls audit, vendor management, data privacy, or information security required. Experience with Casino and Tribal government technology and security goals strongly preferred.
Preferred Experience
- Expertise in regulatory and legal requirements, with the ability to interpret and operationalize laws and standards (e.g., PCI DSS, privacy regulations, and enterprise frameworks)
- Design and governance of enterprise policy architecture, including policy hierarchy, exception management, and alignment to business strategy
- Advanced experience with GRC platforms, including implementation, optimization, and reporting for enterprise risk, compliance, and control assurance
- Leadership of complex audits, regulatory engagements, and enterprise control assurance programs
- Related, relevant, and/or direct experience may be considered in lieu of minimum educational requirements indicated above
Skills
- Must have strong communication and presentation skills
- Must understand the value of standards, policy and procedures, operational effectiveness, and high availability