Job Details

ID #45792733
State Virginia
City Richmond
Job type Permanent
Salary USD TBD TBD
Source Federal Reserve Bank
Showed 2022-09-18
Date 2022-09-17
Deadline 2022-11-15
Category Et cetera
Create resume

Controls & Compliance Analyst

Virginia, Richmond, 23173 Richmond USA

Vacancy expired!

Company Federal Reserve Bank of Richmond

When you join the Federal Reserve-the nation's central bank-you'll play a key role, collaborating with leading tech professionals to strengthen and protect our economic, financial and payments systems. We dedicate more than $1 billion to technology each year to support the Federal Reserve and our economy, and we're building a dynamic and diverse team for our future.

Bring your passion and expertise, and we'll provide the opportunities that will challenge you and propel your growth-along with a wide range of benefits and perks that support your health, wealth, and life. In addition to competitive compensation, we offer a comprehensive benefits package that includes tuition assistance, generous paid time off, top-notch health care benefits, child and family care leave, professional development opportunities, a 401(k) match, pension, and more. All brought together in a flexible work environment where you can truly find balance.

Job Summary

Are you passionate about keeping cloud resources compliant and safe in a fast-paced agile environment?

We are looking for a senior-level compliance analyst with a specialty in IT systems and cloud technology.

This is a hands-on position will help shape our policies and standards for public cloud implementations. You will use data and analytics to manage compliance to policies and partner with application development teams on remediation plans.

Principal Duties and Responsibilities:

What you'll do:
  • Perform day-to-day compliance reviews of operational and security controls
  • Develop and update standards, policies, and procedures as well as best practices documentation in line with operational and compliance requirements
  • Develop and oversee processes for collection of artifacts and compliance verification.
  • Develop and oversee the creation of reporting and dashboards to manage compliance to policies and standards.
  • Reviewing documentation for completeness, accuracy, and adherence to control requirements.
  • Support development of processes and procedures to manage operational risk and achieve & maintain compliance
  • Review and ensure that all cloud environments adhere to compliance requirements. (tagging, onboarding, rehydration, encryption, access levels, password settings, etc.)
  • Translate security and technical requirements into business requirements and communicate security and operational risks to different audiences ranging from business leaders to engineers
  • Identify risks and provide guidance regarding remediation of gaps
  • Respond to client security requests, incidents, and other security related questions
  • Oversee processes on development and maintenance of information policies, standards, and procedures to address risk and security compliance requirements
  • Work with IT Leadership to support the execution of strategies and objectives in accordance with IT Compliance frameworks, guidelines, and requirements
  • Advise and train IT process owners on best practices related to IT General Controls, IT security, remediation of any issues and deficiencies
  • Conduct risk assessments of information systems which includes creating asset profiles, evaluating threat likelihood and impact, and identifying mitigating controls to determine inherent and residual risk to systems
  • Support ongoing internal audit reviews to ensure all required documentation is provided
  • Lead the ongoing development, implementation, monitoring, and enforcement of controls to effectively manage risk to the organization.
  • Develop training, newsletters and other educational material that is engaging and promotes adoption of security & compliance best practices
  • Facilitate small teams of members on remediation activities.
  • Perform other related duties as assigned

Position Requirements:
  • Extensive knowledge of general information security best practices and standards such as ISO 27001, COBIT 5, NIST SP 800 series, NIST CSF
  • Solid knowledge/experience in Software development life cycle, DevOps, networks, databases, operating systems, application controls and IT operations
  • Experience with cloud technologies. AWS or Azure certifications a bonus.
  • General understanding of internal audit methodologies and processes
  • Work with GRC and Security teams, Internal Audit, external auditors, IT management and staff to identify feasible implementation of controls and resolutions to manage weaknesses and create opportunities for improvement
  • Ability to create and maintain IT policies & procedures, management, and executive level reports on effectiveness of IT governance controls and exceptions
  • Ability to perform assigned tasks and responsibilities with minimal supervision, which includes planning, executing, and reporting on required compliance tasks within assigned timelines
  • 5+ years of IT experience covering Internal or External IT audit, risk management, vulnerability management, data security, regulatory compliance, vendor management, incident response
  • Bachelor's Degree in Information Systems, Risk Management, Business Administration, or a related field
  • At least one of the following certifications: CGEIT, CISA, CISM, CISSP, CRISC, GCCC, CCSP or CAP.
  • Excellent interpersonal and presentation skills
  • Flexibility to adjust to multiple demands, shifting priorities, ambiguity, and rapid change.
  • Understand and apply risk management techniques in decision making.
  • Ability to work under the direction and guidance in planning details of procedures and methods to attain definite objectives.
  • Excellent interpersonal, negotiation, creativity, attention to detail, and oral and written communications skills.

Additional / Preferred Requirements:
  • Working knowledge of architecture and design of solutions using cloud-based technologies
  • Experience with basic reporting and analytic tools (excel, tableau, quicksight)
  • Basic content development / management experience
  • Knowledge of Agile frameworks & methodology

Educational Requirements
  • Bachelor's Degree or equivalent experience with 6 to 9+ years of relevant work experience.

About the Opportunity

Cloud Compliance provides the security and operational assurance for our products and services to enable applications that drive the Federal Reserve System. We provide the critical technical foundation through the infrastructure that runs business and user computing services. We work as one-team to deliver high-quality, reliable, and modern infrastructure technologies.

Other Requirements and Considerations:
  • A requirement of this position is that the employee must be fully vaccinated against COVID-19; individuals who are unable to be vaccinated due to a medical condition or sincerely held religious belief may request an accommodation from the Bank.
  • Candidates should review the Bank's Employee Code of Conduct to ensure compliance with conflict of interest rules and personal investment restrictions.
  • If you need assistance or an accommodation due to a disability, please notify rich.recruitment@rich.frb.org .
  • Sponsorship is not available for this role. The selected candidate will be subject to a government security investigation and must meet eligibility requirements for access to classified information. Eligibility for this specific position requires U.S. Citizenship or three or more years of Permanent Resident (Green Card) status.
  • Salary offered will be based on the job responsibilities and the individual's knowledge, skills, and experience as defined in the job qualifications.

Full Time / Part Time Full time

Regular / Temporary Regular

Job Exempt (Yes / No) Yes

Job Category Information Technology

Work Shift First (United States of America)

The Federal Reserve Banks believe that diversity and inclusion among our employees is critical to our success as an organization, and we seek to recruit, develop and retain the most talented people from a diverse candidate pool. The Federal Reserve Banks are committed to equal employment opportunity for employees and job applicants in compliance with applicable law and to an environment where employees are valued for their differences.

Privacy Notice

Vacancy expired!

Subscribe Report job