IT Governance, Risk and Compliance Analyst
No longer listedWho We Are
At Newrez, we bring big thinkers and caring doers together to make home happen. We’re a team built on heart and hustle, united by a commitment to show up for our customers, our communities, and each other. We believe that when our people thrive, homeowners thrive - and that’s why we invest in your growth, wellbeing, and ability to make an impact.
Every day, we work to exceed the expectations of our residential mortgage borrowers and business partners through superior service, simple processes, and clear communication. We do this by empowering our employees, encouraging innovative solutions and recognizing great performance.
POSITION SUMMARY:
This position is a SME (subject matter expert) contributor as a part of the Information Security group. This individual must have broad knowledge of security related auditing methodology. This role is a mix of Security Analyst and Auditor. The individual is responsible for Security related tasks including the day-to-day administration of the different information security controls and reviews, creation of new processes and facilitating ongoing audits.
DESCRIPTION:
Essential Functions, Duties, and Responsibilities
- Support IT compliance program: Assist in developing, implementing, and executing the Company’s IT compliance program.
- Identify SOX/SOC/Regulatory issues: Determine the proper root cause and provide guidance on potential remediation actions.
- Identify and address audit concerns: Recognize existing or potential issues and conduct further research, as necessary.
- Examples include Segregation of Duties (SoD) concerns, improvements to processes, and evidence of approval.
- Collaborate with cross-functional teams: Interface with various departments, consultants, and vendors to participate in SOX/SOC audits and recommendations meetings.
- Liaison with auditors: Facilitate communication with external and internal auditors, acting as a liaison between auditors and the IT department.
- Align policies and procedures: Provide input to align IT and Security policies, standards, and procedures with compliance requirements.
- Support compliance with laws and regulations: Assist process owners, control owners, control performers, and compliance coordinators in ensuring controls are well-defined and compliant with applicable laws and regulations.
- Continuous monitoring: Experience in building control testing and evidence collection to efficiently collect and analyze the effectiveness of controls.
- Evaluate security and controls: Assess the security and controls of various on-premises and cloud-based technologies.
- Create documentation as needed and ensure it reflects a high level of quality.
- Ability to effectively and accurately convey information to others.
- Performs related duties as assigned by management.
Qualifications and Education Requirements:
- Bachelor's degree in computer science, information assurance, MIS or related field, or equivalent industry experience
- Holds or is working toward one or more of the following: CISSP, CISA, CRISC, CGEIT, or GRCP
- At least 3+ years' experience in cybersecurity or audit and exposure with various security frameworks.
- Experience and understanding of various regulatory requirements and laws, including but not limited to: SOX, FFIEC and GLBA. Additional experience in one or more of the following: ISO 2700X, ITIL, or NIST.
Skills, Abilities, and Knowledge:
- Knowledge of IT controls and governance frameworks: Demonstrate a fundamental understanding of general computer control areas, IT governance frameworks, and Sarbanes-Oxley.
- Experience with internal controls design and implementation: Possess fundamental experience in designing and implementing a system of internal controls, preferably within a large-scale management-led SOX organization.
Work Environment and Physical Requirements:
- Working on-site at assigned office location.
- Regular and punctual attendance adhering to schedule established by leadership.
- Flexibility to work occasional adjusted work schedules, overtime, and evening and/or weekend hours to meet deadlines or as business needs demand.
- Working in a cubicle hub, maintaining focus on phone calls in a noisy environment within earshot of multiple other conversations.
- Sedentary work in a stationary position at a cubicle for prolonged periods of time.
- Constant repetitive motions required for operating a computer, such as typing and managing phone calls.
- Constantly communicating effectively verbally in English, including accurately exchanging information with others following identification of correct procedures.
Additional Information:
While this description is intended to be an accurate reflection of the position’s requirements, it in no way implies/states that these are the only job responsibilities. Management reserves the right to modify, add or remove duties and request other duties, as necessary.
All employees are required to have smart phones that meet Company security standards with the ability to install apps such as Microsoft Authenticator. Employment will be contingent on this requirement.
Why Newrez
We’re a great place to work because we invest in what matters: your career, your community, your wellbeing, and your future. Our total rewards package is designed to support your whole self.
Company Benefits:
We offer benefits, programs, and perks that support you in every aspect of your life.
Medical, dental, and vision insurance
Health Savings Account with employer contribution
401(k) Retirement plan with employer match
Paid Maternity Leave/Parental Bonding Leave/Caregiver Leave
Adoption Assistance
Tuition & Certification reimbursement
Employee Mortgage Loan Program
The Newrez Employee Emergency and Disaster Fund is a program to support our team members experiencing hardships
Newrez NOW:
Through Newrez NOW, our Corporate Social Responsibility program, you’ll have opportunities to give back, lead, and make a difference.
1 company-paid Volunteer Time Off day (with over 40,000 volunteer hours contributed since our inception)
Matching Gifts Program - dollar-for-dollar up to $1,000
Access to grants, nonprofit resources, and volunteer opportunities
More than $6,000,000 donated since 2020
1 in 5 employees participates in at least one Employee Resource Group (ERG)
Equal Employment Opportunity
We're proud to be an equal opportunity employer- and celebrate our employees' differences, including race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, and Veteran status. Different makes us better.