Randstad Information Security Risk Analyst in Atlanta, Georgia

The Information Security Risk Analyst is a highly visible, people engaging role on the Randstad Enterprise Risk and Security Team who will work closely with a cross-functional group of risk stakeholders to plan and execute security roadmap initiatives and deliver security services to stakeholders and Operating Companies located throughout Randstad USA. An ideal candidate for this role will be a rising, mid-level security practitioner with effective interpersonal communication skills, proven expertise in threat and vulnerability management, and a clearly demonstrated technical acumen to identify and analyze risks, evolving threats, and vulnerabilities and produce business enabling risk mitigation solutions. The Information Security Risk Analyst will be responsible for executing and overseeing tasks to help mature Randstad’s threat detection and threat management capabilities. This key team member will also be responsible for administering the IT vendor security risk management program and called upon to participate and provide input to help execute the agenda of the organization’s global Data Privacy and Information Security (DPIS) Community.

The Information Security Risk Analyst’s primary responsibilities will include, but not be limited to the following:

Threat and Vulnerability Management

  • Execute tasks and help mature threat monitoring and vulnerability management capabilities and processes, including, but not limited to the following:

  • Endpoint Protection and Data Loss Prevention (DLP) alert monitoring and risk mitigation planning

  • Patch management process planning and task execution oversight

  • Penetration Testing and Application Vulnerability Scanning remediation planning

  • Review results from internal and external vulnerability scans and drive risk remediation planning

  • Analyze security-related incident tickets submitted by IT, business, and field stakeholders and propose appropriate risk mitigation solutions

  • Assist with the execution of the Security Incident Response Process and recurring incident response training exercises

  • Participate in the IT change management meetings and provide subject matter expertise on security-related IT change requests

Risk and Compliance Management

  • Execute the Information Security Risk Assessment Process to ensure appropriate risk treatment and risk mitigation decisions are made to address identified risks.

  • Act as customer-facing liaison and information security subject matter expert to help IT functional teams, internal project teams, business stakeholders, and external partners understand policies and control requirements and effectively implement and manage their risk mitigation safeguards.

  • Plan and execute the tasks necessary to ensure the services provided by key third party vendors, suppliers and business partners do not pose a risk to Randstad’s business operations, including:

  • Administer the Third Party Vendor Security Questionnaire Process

  • Participate in vendor risk remediation discussions and execution

  • Assist with the review of contract agreements, Statement of Works, and other product or service agreement documentation

  • Assist with onsite assessments at vendor sites, as needed

  • Facilitate internal and external audits and assessments. Participate in audit interviews, review findings, lead remediation planning, and document and communicate lessons learned with business and IT stakeholders.

  • Assist with executing the Security Waiver and Exception Process to ensure all authorized deviations from acceptable information protection practices are managed and tracked

  • Assist with the planning and execution of Business Continuity, Disaster Recovery, and other contingency planning activities. As the candidate settles into this role and becomes acclimated to the Randstad business, this responsibility will evolve into full task ownership and accountability to mature Randstad’s contingency planning capabilities

  • Administer the IT crisis communications alert notification solution

Policy and Awareness Management

  • Develop and maintain the implementation life-cycle of information security policies and supporting documentation (i.e. standards, guidelines, etc.) Perform recurring policy refresh to ensure control requirements and policy guidance remains current and applicable

  • Assist in the continuous development, implementation, and ongoing maintenance of the security training and awareness education program. Help create and deliver security and data protection awareness training content to end users

  • Assist with the planning and execution of the employee phishing defense training campaigns

Continuing Professional Development

  • Expand core competencies by assisting other Enterprise Risk and Security (ERS) team members to execute other tasks related to information security, IT risk management, and data protection, as needed

  • Perform occasional travel to other corporate offices (Ft. Lauderdale, FL and Woburn, MA) or field locations to reinforce safe data protection practices and collaborate with other ERS team members

  • Remain current on IT security risk management and data privacy developments, evolving technologies, and trends to reinforce and develop new core competencies

Get to know us and find out " What More Could You Do at https://vimeo.com/user14398035/review/78249279/e899d16cab " at Randstad.

Equal Opportunity Employer: Minorities/Women/Veterans/Disabled.

Equal Opportunity Employer: Race, Color, Religion, Sex, Sexual Orientation, Gender Identity, National Origin, Age, Genetic Information, Disability, Protected Veteran Status, or any other legally protected group status.