Senior Security Analyst
Apex Systems · Woonsocket, RI · 3 wk ago
Contract
About the Role
We are seeking a Senior Security Analyst to support our team with an increased volume of SOX compliance work. This position involves strengthening IT General Controls (ITGCs), remediating Separation of Duties (SoD) issues, and driving remediation efforts to completion. The ideal candidate will work independently after onboarding and facilitate collaboration between compliance, risk, technical, and business teams.
Responsibilities
- Support SOX workflows and drive remediation efforts.
- Remediate Separation of Duties (SoD) issues and strengthen IT General Controls (ITGCs).
- Collaborate with control owners, internal cyber teams, technical engineering teams, and business stakeholders.
- Facilitate discussions between compliance, risk, technical, and business teams to keep remediation efforts moving toward closure.
- Understand and evaluate the sufficiency of compensating controls.
- Ask meaningful technical questions during remediation meetings to guide solutions.
Requirements
- Experience with SOX compliance is required.
- Experience working within a large enterprise environment with numerous systems in scope for SOX.
- A technical background is preferred over a traditional audit background. Examples include experience in a Security Operations Center (SOC), Incident Response, Security Engineering, IAM, Access Administration, or Cloud Security.
- Demonstrated ability to communicate effectively with business stakeholders, technical teams, control owners, and compliance personnel.
Skills
- Strong understanding of Identity & Access Management (IAM) principles, including access administration, identity governance, user provisioning, and access controls.
- Knowledge of cloud platforms (AWS, Azure, GCP) and cloud security concepts.
- Ability to participate in technical remediation discussions and understand proposed solutions.
Qualifications
- Experience with both SOX and SOC (SOC 1/SOC 2).
- An educational background such as an MIS degree or a Computer Science minor.
- Certifications such as CRISC, CISA, CISM, or CISSP are considered valuable. Cloud security certifications are a bonus.
- A desire to move into a GRC-focused career path.
Benefits
- Medical, dental, vision, life, disability, and other supplemental insurance plans.
- Employee Stock Purchase Program (ESPP).
- 401K program with company match after 12 months of tenure.
- Health Savings Account (HSA) on the HDHP plan.
- SupportLinc Employee Assistance Program (EAP) with up to 8 free counseling sessions.
- Corporate discount savings program and other discounts.
- On-demand training program and access to certification prep, technical and leadership courses/books/seminars after 6+ months of tenure.
- Certification discounts and perks for associations including CompTIA and IIBA.
- Dedicated customer service team for benefits and resources, and a certified Career Coach.