IT Compliance Manager
Alameda, CA
Full Time Mid-level / Intermediate USD 140K - 180K
Penumbra
Penumbra is a global healthcare company that is focused on innovating novel technologies to help as many people as possible.
The IT Compliance Manager will oversee Enterprise IT controls, processes, and transactions to ensure all relevant regulatory, legal, and internal compliance guidelines are followed.
Specific Duties and Responsibilities:· Develop the IT General Controls Framework, implement and manage an effective IT controls audit and compliance program for the enterprise across all domains of IT and manage cybersecurity risk to the business. · Ability to self-audit with limited assistance from system or service owners across all IT domains i.e., Network, Cloud, IAM, Data, Application, IoT, IT and Security Operations/ Engineering. · Partner with peer teams and business where necessary. Expected to be self-reliant on security audits, reviews, evidence retrieval. Engage with 3rd party auditors on testing/walk-throughs and address any security gaps. · Create and manage effective action plans in response to audit discoveries and compliance violations.· Partner with system owners on IT services audit outcomes, risk management and compliance reporting. · Advise management on the company’s compliance with laws and regulations through detailed reports. · Develop, and up-keep company IT security policies and procedures. Regularly audit company procedures, practices, and documents to identify possible weaknesses or risks. · Ensure stakeholders are educated on the latest regulations and processes. Resolve business concerns about regulatory and legal compliance. · Maintain positive rapport with IT teams, business, and auditors through effective communications. · Develop, self-audit, manage, and oversee IT Controls across all domains of IT i.e., Network security, Cloud Security, Infrastructure security, End-point security, IAM, Data security, Endpoint security, Application security, IT/ Security operations, ensuring internal and regulatory compliance, working with peer teams to address any gaps and report on compliance. · Adhere to the Company’s Quality Management System (QMS) as well as domestic and global quality system regulations, standards, and procedures. · Understand relevant security, privacy and compliance principles and adhere to the regulations, standards, and procedures that are applicable to the Company. · Ensure other members of the department follow the QMS, regulations, standards, and procedures. · Perform other work-related duties as assigned.
Position Qualifications:· Bachelor's degree in computer science or related field with 10+ years of experience, or equivalent combination of education and experience· 10+ years’ hands-on experience in developing, implementing, and managing enterprise IT audit, governance, and compliance framework is preferred · Ability to develop ITGC framework, implement and manage audit, governance, and compliance across all IT domains i.e., Network, Cloud, IAM, Endpoint, Data, Applications and Operations · Self-reliant and motivated, with expert level understanding of IT technology stack across Network, IAM, Endpoint, Data, Applications is required. · Fully self-reliant, hands-on capability across IT technology stack across Network, Cloud, IAM, Endpoint, Data & Applications. For example: Given the network domain, you will be responsible to access and audit, IT controls, configuration hardening, IAM configurations etc. across routers, switches, WLC’s etc. For example: Given an application domain, you will be responsible for auditing applications security stack, runtime protection, API security etc. · Collaborate with system owners on an ad-hoc basis to seek clarification, review audit data, and rectify any identified gaps. • Expert level knowledge of audit, governance, and compliance frameworks · Expert level knowledge of cybersecurity risk management frameworks · Strong knowledge of technology landscape, regulatory/legal requirements, and procedures · Highly analytical with strong attention to detail. · Strong oral, written, and interpersonal communication skills · Proficiency with MS Word, Excel, and PowerPoint · Excellent organizational skills with ability to prioritize assignments while handling various projects simultaneously
Working Conditions:· General office environment · Willingness and ability to work on site. · Potential exposure to blood-borne pathogens · Requires some lifting and moving of up to 5 pounds · Must be able to move between buildings and floors. · Must be able to remain stationary and use a computer or other standard office equipment, such as a printer or copy machine, for an extensive period of time each day. · Must be able to read, prepare emails, and produce documents and spreadsheets. · Must be able to move within the office and access file cabinets or supplies, as needed. · Must be able to communicate and exchange accurate information with employees at all levels on a daily basis.
Starting Base Salary Is: $140,000/year to $180,000/yearIndividual compensation will vary based on factors such as qualifications, skill level, competencies, work location and shift, and will increase over time based on meeting performance and business needs.
Specific Duties and Responsibilities:· Develop the IT General Controls Framework, implement and manage an effective IT controls audit and compliance program for the enterprise across all domains of IT and manage cybersecurity risk to the business. · Ability to self-audit with limited assistance from system or service owners across all IT domains i.e., Network, Cloud, IAM, Data, Application, IoT, IT and Security Operations/ Engineering. · Partner with peer teams and business where necessary. Expected to be self-reliant on security audits, reviews, evidence retrieval. Engage with 3rd party auditors on testing/walk-throughs and address any security gaps. · Create and manage effective action plans in response to audit discoveries and compliance violations.· Partner with system owners on IT services audit outcomes, risk management and compliance reporting. · Advise management on the company’s compliance with laws and regulations through detailed reports. · Develop, and up-keep company IT security policies and procedures. Regularly audit company procedures, practices, and documents to identify possible weaknesses or risks. · Ensure stakeholders are educated on the latest regulations and processes. Resolve business concerns about regulatory and legal compliance. · Maintain positive rapport with IT teams, business, and auditors through effective communications. · Develop, self-audit, manage, and oversee IT Controls across all domains of IT i.e., Network security, Cloud Security, Infrastructure security, End-point security, IAM, Data security, Endpoint security, Application security, IT/ Security operations, ensuring internal and regulatory compliance, working with peer teams to address any gaps and report on compliance. · Adhere to the Company’s Quality Management System (QMS) as well as domestic and global quality system regulations, standards, and procedures. · Understand relevant security, privacy and compliance principles and adhere to the regulations, standards, and procedures that are applicable to the Company. · Ensure other members of the department follow the QMS, regulations, standards, and procedures. · Perform other work-related duties as assigned.
Position Qualifications:· Bachelor's degree in computer science or related field with 10+ years of experience, or equivalent combination of education and experience· 10+ years’ hands-on experience in developing, implementing, and managing enterprise IT audit, governance, and compliance framework is preferred · Ability to develop ITGC framework, implement and manage audit, governance, and compliance across all IT domains i.e., Network, Cloud, IAM, Endpoint, Data, Applications and Operations · Self-reliant and motivated, with expert level understanding of IT technology stack across Network, IAM, Endpoint, Data, Applications is required. · Fully self-reliant, hands-on capability across IT technology stack across Network, Cloud, IAM, Endpoint, Data & Applications. For example: Given the network domain, you will be responsible to access and audit, IT controls, configuration hardening, IAM configurations etc. across routers, switches, WLC’s etc. For example: Given an application domain, you will be responsible for auditing applications security stack, runtime protection, API security etc. · Collaborate with system owners on an ad-hoc basis to seek clarification, review audit data, and rectify any identified gaps. • Expert level knowledge of audit, governance, and compliance frameworks · Expert level knowledge of cybersecurity risk management frameworks · Strong knowledge of technology landscape, regulatory/legal requirements, and procedures · Highly analytical with strong attention to detail. · Strong oral, written, and interpersonal communication skills · Proficiency with MS Word, Excel, and PowerPoint · Excellent organizational skills with ability to prioritize assignments while handling various projects simultaneously
Working Conditions:· General office environment · Willingness and ability to work on site. · Potential exposure to blood-borne pathogens · Requires some lifting and moving of up to 5 pounds · Must be able to move between buildings and floors. · Must be able to remain stationary and use a computer or other standard office equipment, such as a printer or copy machine, for an extensive period of time each day. · Must be able to read, prepare emails, and produce documents and spreadsheets. · Must be able to move within the office and access file cabinets or supplies, as needed. · Must be able to communicate and exchange accurate information with employees at all levels on a daily basis.
Starting Base Salary Is: $140,000/year to $180,000/yearIndividual compensation will vary based on factors such as qualifications, skill level, competencies, work location and shift, and will increase over time based on meeting performance and business needs.
Job stats:
0
0
0
Categories:
Compliance Jobs
Leadership Jobs
Tags: APIs Application security Audits Cloud Compliance Computer Science Endpoint security Governance IAM IoT Network security Privacy Risk management
Region:
North America
Country:
United States
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.
Senior Cloud Security Engineer jobsSenior Security Analyst jobsInformation System Security Officer jobsInformation Security Manager jobsInformation Security Specialist jobsSenior Cybersecurity Engineer jobsSenior Network Security Engineer jobsSecurity Consultant jobsIT Security Engineer jobsCyber Security Specialist jobsSecurity Specialist jobsSenior Penetration Tester jobsSenior Information Security Analyst jobsSenior Cyber Security Engineer jobsChief Information Security Officer jobsInformation System Security Officer (ISSO) jobsSystems Engineer jobsIT Security Analyst jobsSystems Administrator jobsPrincipal Security Engineer jobsCloud Security Architect jobsSenior Product Security Engineer jobsStaff Security Engineer jobsSecurity Operations Analyst jobsCybersecurity Specialist jobs
Forensics jobsCI/CD jobsKubernetes jobsEncryption jobsSDLC jobsIDS jobsSaaS jobsSplunk jobsEDR jobsIPS jobsBash jobsOWASP jobsRMF jobsSQL jobsTop Secret jobsIntrusion detection jobsCompTIA jobsThreat detection jobsFinance jobsITIL jobsDocker jobsDoDD 8570 jobsCRISC jobsActive Directory jobsVPN jobs
OSCP jobsGIAC jobsBanking jobsTCP/IP jobsUNIX jobsHIPAA jobsTerraform jobsSANS jobsClearance Required jobsSOX jobsIT infrastructure jobsMITRE ATT&CK jobsSOC 2 jobsCISO jobsIndustrial jobsJavaScript jobsDNS jobsCCSP jobsData Analytics jobsJira jobsPolygraph jobsAnsible jobsSOAR jobsSecurity strategy jobsCyber defense jobs