IS Governance & Compliance Analyst II
- Provided end-to-end service in compliance program management and assurance, ensuring the organization remained aligned with regulatory standards.
- Led assessments and control framework maturity evaluations to identify areas for improvement.
- Communicated compliance initiatives across the enterprise, including SOC 1 Type 2, SOC 2 Type 2, MAR, NY DFS 500, HIPAA, and BANA.
- Managed and maintained the GRC system of record, ensuring effective facilitation of audits and alignment of requests with audit requirements.
- Supported senior management in ensuring compliance with regulatory requirements and internal controls, performing proactive control validations, and assisting with gap analysis
- Supported the development of information security awareness through gamification of training programs and raised awareness of security and audit concepts across the organization
- Created complex reports using Power Bi and applications to communicate critical information to senior leadership
- Collaborated with cross-functional teams to gather evidence, test compliance, and assess adherence to external regulatory, contractual, and internal controls
- Supported the implementation and maintenance of security, privacy, and IT controls frameworks while reviewing and updating IT policies, standards, and procedures
- Facilitated IT audits and assessments, and managed the remediation of any findings.
- Keeping up to date with government and industry standards to proactively identify emerging security standards and governance requirements.
- Conducted periodic internal assessments for security risk and compliance as directed by leadership.