Company

CargurusSee more

addressAddressCambridge, MA
type Form of workFull-Time
CategoryInformation Technology

Job description

Working on the Information Security Risk and Compliance team, you will play a critical role in ensuring the confidentiality, integrity, and availability of data assets while complying with regulatory requirements and industry best practices. 

Identifying, classifying, and outlining mitigation plans for risks associated with the handling, storage, and transmission of sensitive data within our organization are core functions of this role.This position requires a deep understanding of data governance principles, data classification methodologies, strong understanding of technology risk management, and regulatory frameworks and compliance standards. 

A well-qualified candidate will be comfortable taking direction from management and be able to work autonomously when given an assignment or project.The candidate must have strong written, verbal communication and organization skills, and a solid understanding of different data storage technologies, regulations around Data Security and risk management. Project management and attention to detail as a must. They are also expected to help mentor junior members of the team. 

Responsibilities: 

Data Classification and Inventory:

  • Develop and maintain a comprehensive inventory of organizational data assets, including their classification levels, sensitivity, and associated risks using our Data Security platform.
  • Implement data classification frameworks and methodologies to categorize data according to its level of sensitivity, criticality, and regulatory requirements.
  • Collaborate with business units and data owners to identify and document data flows, usage patterns, and access controls for classified data.

Risk Assessment and Analysis:

  • Conduct thorough risk assessments of classified data assets to identify potential vulnerabilities, threats, and compliance gaps.
  • Analyze and evaluate the effectiveness of existing controls and security measures in mitigating data-related risks.
  • Develop risk treatment plans and mitigation strategies to address identified vulnerabilities and improve the overall security posture of data assets.

Compliance and Regulatory Alignment:

  • Ensure compliance with relevant data protection regulations, such as GDPR, CCPA, etc., by assessing data handling practices against regulatory requirements.
  • Monitor changes in data protection laws and regulations to ensure ongoing compliance and adapt data classification policies and procedures.
  • Provide guidance and support to business units on regulatory requirements and industry best practices related to data classification and risk management.

Data Protection Controls:

  • Recommend and implement technical controls, encryption mechanisms, access controls, and data loss prevention (DLP) solutions to protect classified data from unauthorized access, disclosure, or misuse.
  • Conduct periodic assessments of data protection controls and security measures to validate their effectiveness and identify areas for improvement.
  • Collaborate with  IT and Security teams to integrate data protection controls into technology systems and infrastructure.

Reporting and Communication:

  • Prepare and present comprehensive risk assessment reports, findings, and recommendations to senior management.
  • Communicate effectively with business units and data owners to raise awareness of data classification requirements, risks, and responsibilities.
  • Collaborate with internal audit teams and external auditors to facilitate data classification reviews and compliance assessments.
  • Work closely with the project team to ensure that deliverables are on time and budget.

Tool Implementation and Maintenance: 

  • Design and architect the implementation of Data Discovery and DLP tools.
  • Coordinate with the vendor account management teams to improve the capabilities of the tools and participate in QBRs.
  • Prepare and present to stakeholders new tool improvements and enhancements.

Qualifications:

  • Bachelor's degree in Information Security, Computer Science, or related field; Master's degree preferred.
  • Relevant certifications such as CISSP, CISM, CRISC, or equivalent are highly desirable.
  • Experience working in an agile development environment.
  • 5+ years of experience in data classification, risk management, or information security.
  • Strong understanding of data classification methodologies, risk assessment frameworks, and regulatory requirements.
  • Experience with data protection technologies, such as encryption, access controls, and data loss prevention (DLP) solutions.
  • Familiarity with relevant data protection regulations, such as GDPR, CCPA, etc.
  • Excellent analytical and problem-solving skills, with the ability to effectively identify and prioritize data-related risks.
  • Strong communication skills, with the ability to convey complex technical concepts to non-technical stakeholders.
  • Strong project management capabilities and holding self and others accountable for their deliverables.
  • Ability to mentor junior team members. 
Refer code: 8979959. Cargurus - The previous day - 2024-04-11 16:12

Cargurus

Cambridge, MA
Popular Senior Data jobs in top cities
Jobs feed

Office Services Administration Coordinator

Disney Cruise Line

Lorida, FL

Practitioner Education Representative

American Specialty Health Incorporated

United States

Product Designer, Onchain

Kraken

United States

Head of Product

Upkeep

United States

Recruitment Coordinator

Grafana Labs

United States

Utility Lead

Nesco Resource

Charlestown, IN

$21.50 •

Software Engineer, Observability

Vercel

United States

Outside Sales Representative

Window Nation

Denver, CO

Up to $673 per week

Registered Nurse Endoscopy .4 FTE Part-Time- Twin Falls

St. Luke's Health System

Twin Falls, ID

Senior Backend Product Software Engineer

Dropbox

United States

Share jobs with friends

Related jobs

Senior Data Security Risk Analyst

Senior Data Scientist

Biospace

Cambridge, MA

4 days ago - seen

Senior Financial and Data Analyst

Oxfam America

Boston, MA

2 weeks ago - seen

Senior Data Analyst

Vinfen

$65,000 a year

Cambridge, MA

3 weeks ago - seen

Senior Data Scientist

Vendelux

$138K - $175K a year

Boston, MA

3 weeks ago - seen

AFNWC - Senior Configuration and CDRL Data Manager

Apogee Engineering, Llc

$106,000 - $176,000 a year

Hanscom AFB, MA

3 weeks ago - seen

Senior Data Warehouse/ETL Developer

Saic Motor

CAMBRIDGE, MA

4 weeks ago - seen

Senior Data warehouse/ETL Developer

Equiliem

Cambridge, MA

4 weeks ago - seen

Senior Data Analyst

Circle

$122,500 - $162,500 a year

Boston, MA

4 weeks ago - seen

Senior Data Architect

Cdm Smith

Boston, MA

4 weeks ago - seen

Senior Analyst, Engineering Services, (Senior Data Manager)

Raytheon

Andover, MA

a month ago - seen

Senior Data Analyst

Grand Circle Llc

$101K - $128K a year

Boston, MA

a month ago - seen

Senior Data Scientist, Statistical Genetics

Valo Health

Boston, MA

a month ago - seen

Senior Data Engineer

Vensure Employer Services

Hopkinton, MA

a month ago - seen

Senior Azure Data Engineer (Remote)

W.b. Mason Company, Inc

$88.1K - $112K a year

Brockton, MA

a month ago - seen

Senior Data Scientist

Om1

$144K - $183K a year

Boston, MA

2 months ago - seen

Senior Data Scientist

Cvs Health

$106,605 - $206,000 a year

Wellesley, MA

2 months ago - seen

Senior Data Scientist

Magna International Inc.

$120K - $152K a year

Lowell, MA

2 months ago - seen