Lead ISO 27001 Compliance Analyst

Posted Jan 29

OPENTEXT - THE INFORMATION COMPANY

As the Information Company, our mission at OpenText is to create software solutions and deliver services that redefine the future of digital. Be part of a winning team that leads the way in Enterprise Information Management.

The Opportunity

The Lead Security Compliance Analyst will have the opportunity to impact meaningfully and contribute to the OpenText Compliance Program in accordance with ISO 27001, ISO27017, SOC1/2, HIPAA and SOC2+HITRUST. The Lead Security Compliance Analyst plays a key role in the continued development and maturity of an ever-growing Security Compliance Program that supports the delivery of compliance certifications to support customer security requirements. In this role, you will be involved in managing and sustaining the various compliance programs by working collaboratively with internal teams, SMEs, external customers, vendors, auditors and other stakeholders.

You Are Great At

  • Setting strategic direction for audit readiness, managing compliance programs, driving continuous improvement activities, delivering dashboarding & reporting metrics.
  • Interfacing with auditors, articulating control implementation and impact, and establishing considerations for applying security and compliance concepts to a technical cloud environment. Planning and leading fieldwork with auditors to support ISO27001 control testing
  • Effectively communicating compliance program results, including assessment status, workflow, remediation, and reporting, to a broad audience including peers and senior leaders.
  • Coordinating the overarching annual audit plan with internal and external auditors to support delivery of multiple, simultaneous audits and certifications (both new and existing) within the Open Text portfolio
  • Supporting delivery of audit milestones to ensure audit timelines stay on target by proactively identifying and coordination resolution of roadblocks, compliance risk.
  • Collaborating cross-functionally with technology and business stakeholders to drive, track, and resolve all aspects of compliance readiness and audit execution.
  • Participating in, or potentially leading, gap assessment, compliance readiness, and compliance monitoring activities.
  • Developing metrics and dashboards for reporting on assigned compliance programs

What It Takes

  • 5+ years of experience in IT audit and/or compliance, with a concentration on leading multiple, simultaneous audit engagements for a Cloud Service Provider, encompassing multiple frameworks
  • 2+ years of experience leading ISO27001 Audit and/or implementation work
  • Competency in Compliance Program Management.
  • Experience delivering compliance programs in GCP, AWS, Azure is a plus
  • Detailed understanding of evaluating the design and effectiveness of controls and experience working with auditors/regulators for compliance assessments
  • Experience leading preparation for and/or managing assessment activities (SOC 2, ISO 27001, PCI DSS, HIPAA/HITRUST, SOX, etc.) for assigned cloud services through assessment planning, assessment fieldwork, and final report delivery
  • Experience building certification roadmaps based on customer requirements, compliance documentation, and ensuring that committed assessments are delivered on schedule.
  • Experience with FedRAMP is a plus.
  • Experience with GRC Tools & Compliance Automation is a plus.
  • Strong technical, analytical, interpersonal, communication and writing skills.
  • Ability to work both independently and within a global team environment
  • Demonstrated strength in working in a high change environment.
  • Effective team collaboration plus the ability to coach and mentor others.
  • Strong personal characteristics as demonstrated by the following: Owners mindset, achievement-oriented, self-controlled, self-confident, flexible, approachable, and dedicated.
  • Required industry standard certifications (CISSP, CISA, ISO 27001 Lead Implementer/Auditor) or equivalent
  • Bachelor’s Degree in Information Technology, Business, or related vocations.

For Colorado and New York state residents, this job is expected to pay a minimum of $118,740 USD in addition to a comprehensive and competitive group benefit and healthcare plan. Individual compensation will be determined based on skills and experience comparable to the job requirements.

While OpenText is an Equal Opportunity Employer, our efforts to build an inclusive work environment go beyond simply complying with applicable laws. Our Employment Equity and Diversity Policy provides direction on maintaining a working environment that is inclusive of everyone, regardless of culture, national origin, race, color, gender, gender identification, sexual orientation, family status, age, veteran status, disability, religion, or other basis protected by applicable laws. Should you require accommodations during the selection process, please contact accommodationrequests@opentext.com.