Location: Canada, ON, WaterlooApply Now
OpenText is seeking a highly motivated, collaborative, technically experienced and well-organized Lead Security Compliance Analyst for IT Compliance (ITC) with the ability to understand various compliance requirements, effectively interpret and communicate the requirements to internal teams, and lead efforts to produce actionable plans to meet the compliance requirements. ITC Team, part of Global Information Security (GIS) is currently focused on, but not limited to SOC1, SOC2, PCI, HIPAA, ISO 27001, SOX. In this role, you will be involved in supporting the ITC function in maintaining the OpenText ISO27001 program. This role will be instrumental in all aspects of the ISO 27001 program lifecycle.
You are great at:
• Provide subject matter expertise for ISO 27001 compliance standard.
• Participates in, or potentially leads, ISO 27001 gap assessment, compliance readiness, and compliance monitoring activities including but not limited to coordination of ISMS activities. internal audit, and surveillance and certification audits
• Collaborates with technology and business stakeholders along with other Compliance team members to facilitate remediation and execution of corrective action plans.
• Coordinates, or potentially leads, delivery of audit milestones to ensure audit timelines stay on target by escalating and identifying roadblocks.
• Assists in, or potentially leads, the identification of business process improvements and partners with technology and business stakeholders to identify pragmatic approaches to compliance readiness and testing.
• Collaborates cross-functionally with technology and business stakeholders to drive, track, and resolve all aspects of compliance readiness and audit execution.
• Interfaces with internal and external auditors for periodic audit activities
• Conducts various IT Compliance controls validation and implementation activities
• Participates in continuous improvement initiatives.
• Develops metrics and dashboards for reporting on assigned compliance programs
• Provides coaching and mentorship to more junior team members
• Provides input into industry best practices for managing compliance in today’s landscape.
What it takes:
• 5+ years of experience in IT audit and/or compliance, with a concentration on ISO 27001, specifically experience leading a Cloud Service Provider through ISO 27001 certification process
• Must have ISO27001 Lead Implementer / Auditor certification
• Experience leading control assessments and audit activities.
• Familiar with Information Security principles, knowledge of IT processes (e.g. Change Management, Incident Management, Risk Management, Network and System Administration),
• Bachelor’s Degree in Information Technology, Business or related vocations.
• Exposure to PCI, HIPAA/HITRUST, SOC 2 is a plus
• Big four audit firm experience a plus.
• Experience with GRC Tools is a plus
• Strong technical, analytical, interpersonal, communication and writing skills.
• Ability to work both independently and within a global team environment
• Self-starter, quick-learner, and pro-active problem-solving skills.
• Effective organization, follow-up and time management skills.
• Demonstrated strength in working in a high change environment.
• Ability to develop and foster strong relationships with technology and business stakeholders.
• Effective team collaboration plus the ability to coach and mentor others.
• Strong personal characteristics as demonstrated by the following: achievement-oriented, self-controlled, self-confident, flexible, approachable, and dedicated.
At OpenText we understand and value diversity in our employees and are proud to be an Equal Opportunity Employer. We hire the best talent regardless of sex, national origin, disability or race. If you require accommodation at any time during the recruitment process please email firstname.lastname@example.org.