HRTMS Job Description Management
| IT - Gov Analyst J o b D e s c r i p t i o n | | |
THE DETAILS
| Job Code: | 11349 | Grade: | 20S | Status: | Exempt | | | |
POSITION AND PURPOSE
| The governance, risk, and compliance (GRC) governance analyst assist with IT and Security governance, risk, and compliance policies, processes, technologies, and assessments. Reporting to the IT GRC Manager, the analyst provides assurance for adherence to company policies and procedures, and contributes to activities related to the development, implementation, compliance, and adherence to the organization's IT policies and assessment activities. This position works closely with the Golden 1 Information Security teams for security reviews and evidence collection activities that align with internal and external auditing requirements as well as any security investigations and incidents. This position will also be responsible for the reporting, tracking and verification of IT Change Management procedures and Business Continuity and Disaster Recovery (BCDR) testing processes. The ideal candidate is technical and possesses at least five years of experience in IT governance, compliance, or risk management. The position requires a diverse background to understand a variety of systems, including new technologies and legacy systems considered business critical. |
WHO WE ARE
| Golden 1 Credit Union is among the top credit unions in the country. As a member-owned, not-for-profit cooperative, Golden 1 is guided by the credit union philosophy of “people helping people.” We are committed to empowering our members and uplifting our communities as we create a more equitable and financially inclusive California. We welcome all who embrace our Core Values. |
WHO YOU ARE
| You are a highly analytical and detail-oriented governance, risk, and compliance professional with a passion for strengthening controls, managing risk, and driving regulatory compliance. You excel at coordinating audits, assessing control environments, analyzing data, and partnering across teams to improve processes and mitigate risk. You are an effective communicator who balances regulatory requirements with business needs, builds strong stakeholder relationships, and promotes a culture of accountability, security, and continuous improvement. |
• | Manage the reporting requirements for Golden 1’s IT GRC program, ensuring IT activities, processes, and procedures meet defined requirements, policies, and regulations. Manage assessments and gap analyses of Golden 1’s IT control environment against industry and regulatory governance frameworks (i.e., NIST Cyber Security Framework, ISO 27001, SOC 1/2, COBIT, ITIL, Sarbanes-Oxley, and CCPA/GDPR). | • | Apply GRC expertise across key lines of business, including products, practices, and procedures. Coordinate and track IT related audits activities including scope, timelines, evidence gathering, and remediation task outcomes. Ensure Golden 1’s IT teams maintain up-to-date configuration documentation for systems and processes. Provide guidance, evaluation, and advocacy on audit responses for the department. | • | Maintain oversight in a GRC-related platform. | • | Produce metrics, reports, and dashboards as applicable. Execute Golden 1’s IT strategy for dealing with increasing number of audits, compliance checks and external assessment processes. | • | Oversee the management of system user access reviews including data collection and follow-up with system owner approvals and timely submissions as required. | • | Identify strengths and weaknesses in the GRC program as they relate to privacy, security, business resiliency and compliance frameworks. | • | Support third-party risk assessments and manage third-party risk and remediation activities. Ensures proper reporting and response to alleged violations of company rules, regulations, policies, procedures, and standards of conduct by initiating and cooperating in investigative procedures. | • | Work with auditors as appropriate to keep audit focus in scope and remediation delivery commitments. Maintain excellent relationships with audit entities and provide a consistent perspective that continually puts Golden 1 in its best light. | • | Facilitate Business Continuity/Disaster Recovery Planning and Testing exercises. | • | Support the development of strategies to address GRC awareness and training for all stakeholders and provide on-site guidance and instructions to other IT teams as needed. | • | Maintain and enforce confidentiality regarding information being processed, stored, or accessed by the system. | • | Perform other duties as assigned. |
• | Develop and maintain an understanding of the pertinent regulatory requirements and risks inherent to job responsibilities, establish, and maintain control activities that mitigate those risks consistent with the Credit Union’s risk appetite, and ensure operational integrity and compliance with applicable regulations. |
EDUCATION: | • | Bachelor’s Degree in Business Administration, Accounting, Management Information Systems or Computer Science preferred | • | Master’s Degree in Business Administration or other related area preferred | | | |
EXPERIENCE: | • | 5+ years in cybersecurity as a practitioner and with at least two to three plus years exposure with various security frameworks, experience in a technology risk, security, or compliance role preferably in a financial institution required | • | Detailed understanding of risk management and controls assurance required | • | Strong understanding of information security controls and standards such as ISO 27001/2, NIST, CSF, and related frameworks required | • | Thorough understanding of various regulatory requirements and laws such as, but not limited to PCI, SOX, HIPAA, HITRUST, GDPR and GLBA required | • | Experience in a role balanced between business stakeholders and a central technology service organization required | | | |
KNOWLEDGE/SKILLS: | • | Must have strong written skills, communication skills, and possess the ability to building trust and relationships with senior executives. This diversified position requires a strong ability to multitask. | • | Strong analytical, problem solving, and decision making skills to effectively understand and resolve complex strategies and issues. | • | Must have good interpersonal skills and the ability to interact with employees at all levels of responsibility within the organization. | | | |
LICENSES AND CERITIFCATIONS: | • | CISSP required | • | CRISC required | • | CGEIT required | • | GRCP required | • | Project Management Professional (PMP) preferred | • | Portfolio Management Professional (PfMP) preferred | • | Certified Business Analyst Professional (CBAP) preferred | | | |
CORE COMPETENCIES: | • | Solves Problems Proactively - Tackles complex issues independently | • | Innovates and Applies Insights - Suggests improvements | • | Delivers Results with Agility - Maintains quality during change | • | Collaborates Across Teams - Works effectively with peers | • | Influences and Persuades - Shares expertise to guide others | | | |
ORGANIZATIONAL CONTACTS AND RELATIONSHIPS
| INTERNAL: | All levels of staff and management, including Senior Management | EXTERNAL: | Members, vendors, suppliers, government agencies, credit union industry associations and peers at other financial institutions. | | | |
WORKING CONDITIONS
| Work time includes weekend and after-hours time, based on organizational needs. This position works in-office where working conditions, lighting, temperature, audio, and workspace are all sufficient. |
PHYSICAL REQUIREMENTS
| Work requires the ability to constantly operate a computer and the ability to read, type, and communicate. Work may require the ability to move work-related supplies weighing up to 10-15 pounds. |
DISCLAIMER/INTENT AND FUNCTION OF JOB DESCRIPTIONS
| The above information on this description has been designed to indicate the general nature and level of work performed by team members within this classification. Because the nature of positions and job functions can change over time, this job description is not designed to contain or be interpreted as a comprehensive inventory of all essential functions, duties, responsibilities and qualifications requirements of team members assigned to this job. Job duties may be changed or modified in the Credit Union’s discretion. The Credit Union will keep team members updated on key functions, duties, and requirements of their position by communications from the Credit Union and by updating the job description from time to time. Any team member with questions about the nature of their job duties is encouraged to consult with their supervisor. |
DECLARATION/ACKNOWLEDGEMENT
| This job description outlines the essential functions and physical/mental requirements necessary to perform this role. Reasonable accommodations may be made to enable individuals with disabilities to perform these essential functions. |
|