Company

MillerknollSee more

addressAddressRemote - United States
CategoryInformation Technology

Job description

Why join us? 


Our purpose is to design for the good of humankind. It’s the ideal we strive toward each day in everything we do. Being a part of MillerKnoll means being a part of something larger than your work team, or even your brand. We are redefining modern for the 21st century. And our success allows MillerKnoll to support causes that align with our values, so we can build a more sustainable, equitable, and beautiful future for everyone.

Governance, Risk and Compliance AnalystPurpose / Profile

The MillerKnoll Governance, Risk, and Compliance Analyst will work collaboratively with the global cross-functional teams to centrally perform Cybersecurity and Privacy compliance, data governance, and risk management functions. The analyst will have primary responsibility for defining, creating, and managing IT and organizational policies and standards in support of legal and regulatory compliance needs as well as general IT and organizational cybersecurity and privacy practices. This position works closely with the Legal, Digital, Audit, Cybersecurity and Technology teams to help ensure that contractual, policy, control, procedural, legal, and regulatory obligations are effectively defined and implemented.

The analyst must be collaborative and flexible while developing solutions that meet changing cybersecurity and privacy requirements while supporting business function needs. This individual will help grow and mature Risk and Compliance processes to gain efficiencies and effectiveness in collaboration with all departments to ensure an acceptable risk posture for the organization. This position requires a deep understanding of existing data protection laws and regulations, such as the EU-GDPR and CCPA/CPRA, but also be focused on broader implications of protections as a function of information/system lifecycle management and security and privacy by design. The analyst must possess high standards of legal and business ethics and a demonstrated ability to understand technology, independently problem solve, analyze large quantities of data, and clearly summarize and communicate facts.

Essential Functions
  • Review PCI controls and work with control owners to resolve control design.
  • Develops compliance awareness and training for employees
  • Manage the IT policies and procedures lifecycle from development through approval and communication.
  • Identify opportunities to reduce the organization's risk by analyzing controls and processes, then recommend remediation actions and controls.
  • Prioritize and communicate compliance requirements to technical and non-technical audiences.
  • Collaborate with key business partners on remediation strategies and provide guidance to lower/eliminate risk.
  • Conduct Privacy Impact Assessments (PIAs) of the application’s security design for the appropriate security controls, which protect the confidentiality and integrity of Personally Identifiable Information (PII).
  • Support the development of compliance automation to improve business processes.
  • Interpret and apply laws, regulations, policies, standards, or procedures to specific issues.
  • Work cooperatively with applicable organization units in overseeing consumer information access rights.
  • Serve as the information privacy liaison for users of technology systems
  • Conduct ongoing privacy training and awareness activities
  • Monitor systems development and operations for security and privacy compliance
Additional Functions
  • Stay current with compliance news and trends relevant to the business and industry.
  • Participate in providing support for compliance-related incidents.
  • Interface with other business units such as Cybersecurity to communicate program status and overall compliance and training posture.
  • Promote a positive security/compliance culture through knowledge sharing, influences, and conduct.
  • Create and maintain role-specific documentation.
  • Assist with our government, risk, and Compliance projects as time permits.
Knowledge, Skills, and Abilities
  • Knowledge of Payment Card Industry (PCI) data security standards.
  • Knowledge of Personally Identifiable Information (PII) data security standards.
  • Knowledge of Personal Health Information (PHI) data security standards.
  • Knowledge of Risk Management Framework (RMF) requirements.
  • Knowledge of risk/threat assessment.
  • Knowledge of laws, policies, procedures, or governance relevant to Cybersecurity for critical infrastructures.
  • Knowledge of external organizations and academic institutions with a cyber focus (e.g., cyber curriculum/training and Research & Development).
  • Knowledge of controls related to data use, processing, storage, and transmission.
  • Skill in applying confidentiality, integrity, and availability principles.
  • Skill in conducting information searches.
  • Ability to communicate effectively when writing.
  • Ability to apply critical reading/thinking skills.
  • Interpret and apply laws, regulations, policies, standards, or procedures to specific issues.
  • Provide ongoing optimization and problem-solving support.
  • Provide recommendations for possible improvements and upgrades.
  • Ability to tailor technical and planning information to a customer's level of understanding.
  • Ability to work across departments and business units to implement the organization’s privacy principles and programs and align privacy objectives with security objectives.
Qualifications

Education/Experience

  • Bachelor in Information Systems, Cybersecurity, or Business administration
  • 4+ years of relevant experience in Internal Audit, Compliance, or Information Technology

Licenses and Certifications

  • One or more compliance certifications are preferred (e.g., CIPP, CIPM, CIPT, PCIP, QSA, CISA)

Who We Hire?


Simply put, we hire everyone. MillerKnoll is comprised of people of all abilities, gender identities and expressions, ages, ethnicities, sexual orientations, veterans from every branch of military service, and more. Here, you can bring your whole self to work. We’re committed to equal opportunity employment, including veterans and people with disabilities.

A starting compensation range for this role is $77,950.00 - $97,925.00. Relevant salary considerations will include candidate qualifications and experience, other business/organizational needs and market factors . You may also be eligible to receive a geographic premium, annual discretionary incentive and equity awards which are subject to the rules governing these programs. The company offers a full spectrum of benefits including Medical, Prescription Drug, Dental, Vision, Health Savings Account, Dependent Day Care Savings Account, Life Insurance, Disability and Other Insurance Plans, Paid Time Off (including Vacation and Parental Leave), Holidays, 401(k), and Short/Long Term Disability, in addition to other special perks reserved for our associates.

This organization participates in E-Verify Employment Eligibility Verification. In general, MillerKnoll positions are closed within 45 days and are open for applications for a minimum of 5 days. We encourage our prospective candidates to submit their application(s) expediently so as not to miss out on our opportunities. We frequently post new opportunities and encourage prospective candidates to check back often for new postings.

Benefits

Career development, Equity, Flex vacation, Health care, Insurance, Medical leave, Parental leave
Refer code: 8208272. Millerknoll - The previous day - 2024-02-18 06:37

Millerknoll

Remote - United States

Share jobs with friends

Related jobs

Governance, Risk and Compliance Analyst

Compliance & Risk Analyst, Progression

Teco Energy

Lorida, FL

4 days ago - seen

Sr. Information Security Risk & Compliance Analyst

Chg Healthcare

Midvale, UT

4 days ago - seen

Cyber Risk & Compliance, Senior Analyst

Broadridge

Atlanta, GA

5 days ago - seen

Senior Risk & Compliance Analyst

Highmark Health

Remote - Pennsylvania, United States

5 days ago - seen

Compliance Risk Testing Analyst, Assistant Vice President, Hybrid

State Street

Not disclosed

United States

2 weeks ago - seen

Compliance Risk Testing Analyst, Officer, Hybrid

State Street

Not disclosed

Boston, MA

2 weeks ago - seen

Senior Analyst – Controllership Risk, QA & Compliance

General Motors

Detroit, MI

2 weeks ago - seen

Cybersecurity Risk and Compliance Senior Analyst

Assa Abloy

Connecticut, United States

4 weeks ago - seen

Senior Risk & Compliance Analyst

Highmark Health

Sylvania, PA

a month ago - seen

IT Security Analyst III (Governance/Risk/Compliance)

Innova Solutions

New York, NY

a month ago - seen

Governance, Risk & Compliance (GRC) Analyst

Delta Dental Of Missouri

Saint Louis, MO

2 months ago - seen

IT Risk and Compliance Analyst

Atwork Personnel Services

Sacramento, CA

2 months ago - seen

Sr. Analyst, Cyber Security Governance, Risk & Compliance

The Azek Company

Chicago, IL

2 months ago - seen

Supply Chain Risk and Trade Compliance Analyst

Z2Data

$100,000 - $200,000 a year

Remote

2 months ago - seen

IT Risk & Compliance Analyst

Republic Services

Phoenix, AZ

2 months ago - seen

Governance, Compliance, and Risk Analyst - Fintech

Smiley Technologies

Little Rock, AR

2 months ago - seen