Logo
job logo

Cybersecurity NIST GRC Specialist

COOLSOFT, Columbus, OH, United States


Overview

Cybersecurity NIST GRC Specialist (Jobs in Columbus, OH) Requirement id 157447 Job title Specialist Job location in Columbus, OH Job type Contract Duration 3 Months Compensation DOE Client Info : DPS Notes: Initial Teams interview, followed by in-person interview at 1970 W. Broad Street Columbus. Full-Time Remote PART-TIME position: approximately 10 hours/week. Must be able to attend occasional on-site meetings. Description

Security Analyst to analyze security posture ratings for 61+ Online Driver Training Organizations licensed to operate by the State of Ohio Department of Public Safety. This work can be done at any time, including nights and weekends. This is a fully remote position, and other employment is permitted (candidate must be able to dedicate approximately 10 hours per week analyzing and communicating results). The Client will provide access to the Third-Party Risk Management (TPRM) tool, Bitsight, and the assessment communication tool, OneTrust. Responsibilities

Review initial security assessment provided by online driver training companies at the time of application. Review updated security assessment provided by online driver training companies for submission of changes of security controls. Document and address concerns or clarifications needed for the security assessment review with the online driver education companies. Compare responses against the assessment and industry standards. Review online driver training company annual attestations of compliance. Validate the security assessment is accurately and thoroughly completed. Communicate any deficiencies in annual attestation to the online driver training company and facilitate the accurate completion of the attestation of compliance. Contact and work with Bitsight to configure monitoring parameters. Use Bitsight functionality to direct the findings and remediation recommendations to the online driver training company. Discuss findings with online driver training company. Use OneTrust as the Governance Risk and Compliance (GRC) tool to assess and communicate. Do not assist the online driver training company in determining corrective paths of action. Upon complaint for investigation, including but not limited to, reviewing updated monitoring results to confirm no falsification or other violation has occurred. Run Bitsight reports and provide the information the business needs for administrative action. Communicate with DPS Driver Training Program Office on a consistent basis with status updates. Monitor upcoming changes to the controls and communicate with the Driver Training Program Office with the specifics. May need to provide testimony at administrative hearings. Any testimony is based on processes and expertise on security controls, if needed. Call 502-379-4456 Ext 100 for more details. Please provide Requirement id: 157447 while calling. Qualifications / Requirements

Skills required: Cyber Security, NIST, Vendor Management Experience, GRC. Additional Information

EOE Protected Veterans/Disability

#J-18808-Ljbffr