DE Jobs

Search from over 2 Million Available Jobs, No Extra Steps, No Extra Forms, Just DirectEmployers

Job Information

Hologic TPRM Analyst 2 CR in Alajuela, Costa Rica

TPRM Analyst 2 CR

Alajuela, Costa Rica

Education:

  • Bachelor’s degree desirable in information technology, Information Security, or relevant field.

  • Applicable certification a plus (Cobit, COSO, etc.)

Experience:

  • A minimum of 0-2 years of experience in the Governance Risk and Compliance fielD

Qualifications

  • Bachelor’s degree desirable in computer science, Information Technology, or a related field.

  • Ability to deliver simple, clear and concise communications to the various communities within the company without using security jargon. This can include different cultures, nationalities, international locations and languages.

  • Experience working across multiple lines of business to design and implement training plans and track organizational progress, development, and metrics.

  • Good verbal and written communication skills with experience briefing corporate executives and professionals.

  • Must have at least a basic understanding of the different concepts of information security and privacy.

Skills, Specialized Knowledge (Desired):

  • Knowledge of security and control frameworks, such as COSO, COBIT, NIST CSF, and/or CIS 18 are a plus.

  • Experience with Shared Assessments and their due diligence questionnaires such as the SIG Core and SIG Lite, is also a plus

Summary of Duties and Responsibilities

  • Conducts comprehensive security assessments and audits.

  • Coordinates the implementation of security controls.

  • Monitors and analyzes controls for gaps and vulnerabilities.

  • Develops risk mitigation strategies.

  • Fosters collaborative partnerships with cross-functional teams, ensuring the seamless integration of best risk management practices.

  • Ensure that Hologic’s Third-Party Risk Management meets all industry regulations, standards, and compliance requirements.

  • Create and implement metrics framework that can effectively measure and communicate the impact of the program.

  • Work with information security awareness lead to develop relevant training and awareness material that is required for a successful company-wide update and deployment of Third-Party Risk Management.

DirectEmployers