Summary
Tailored Brands, Inc. is a specialty retailer whose Information Security team supports the company’s technology, data security, and privacy needs. The Governance, Risk & Compliance Analyst will monitor, report, assess, and mitigate security and privacy risks, while supporting compliance controls, third-party risk management, privacy assessments, and regulatory requests.
Responsibilities
- Participate in developing and maintaining policies, procedures, standards, and guidelines
- Collaborate with business and technology stakeholders to ensure that systems, processes, services, and data adhere to industry standard best practices for data security and privacy
- Support the third-party risk assessment process, in close collaboration with legal, procurement, and business stakeholders
- Maintain strong oversight of third parties, vendors and business partners to safeguard against undue risk presented by external entities. Escalate to security management and business unit leads when points of weakness are discovered
- Collect data surveys and facilitate risk assessments for all third-party and internal solutions that may process or store data
- Liaison with auditors, both internal and external, to maintain and implement controls for compliance and privacy laws
- Collaborate with business owners and technical SMEs in the identification, evaluation, treatment, and monitoring of security and privacy risks
- Maintain oversight in a GRC-related platform
- Coordinate responses to Data Subject Access Requests from Consumer and Employees in support of the company regulatory compliance program
- Conduct Privacy Impact Assessments
Skills
- • Bachelor's degree in Computer Science, Management Information Systems, Engineering, or other relevant field; or equivalent combination of education and experience required
- • 2+ years of experience as a GRC Analyst, Information Security Risk and Compliance Analyst, privacy analyst or comparable role
- • Experience with third-party assessments and cloud risk assessment methodologies
- • Familiarity with some or all the following types of tools: OneTrust, ServiceNow, Jira
- • Working knowledge of industry best practices and frameworks
- • Project management and time management skills
- • Self-motivated with ability to not only work in group/individual setting, but able to drive action and make decisions independently with little to no direction
- • The ability to communicate effectively with people at all levels
- • Must be a confident communicator and presenter
- • Must possess excellent organizational and planning skills
- • Strong interpersonal skills, written and verbal communication
- • Ability to sit and work at a computer keyboard for extended periods of time
- • Ability to stoop, kneel, bend at the waist, and reach daily
- • Able to lift and move up to 25 pounds occasionally
- • Must utilize visual acuity, speech and hearing, hand and eye coordination and manual dexterity necessary to operate a computer and office equipment
- • Hours regularly 40 hours per week, as work dictates, from our Houston, TX corporate location or a remote location
- • Preferred experience with cloud computing, online services, web and enterprise applications, and data analytics
- • Preferred experience with data discovery, data mapping, authorization, and access management, and pseudonymization technologies
- • Familiarity with General Data Protection Regulation (GDPR), California Consumer Privacy Act (CCPA), Statement on Standard for Attestation Engagements No. 18 (SSAE18), System and Organization Controls 2 (SOC 2), International Organization for Standardization (ISO), National Institute of Standards and Technology (NIST), Payment Card Industry (PCI), Sarbanes-Oxley Act (SOX), preferred but not required
Qualifications
Must Haves
- • Bachelor's degree in Computer Science, Management Information Systems, Engineering, or other relevant field; or equivalent combination of education and experience required
- • 2+ years of experience as a GRC Analyst, Information Security Risk and Compliance Analyst, privacy analyst or comparable role
- • Experience with third-party assessments and cloud risk assessment methodologies
- • Familiarity with some or all the following types of tools: OneTrust, ServiceNow, Jira
- • Working knowledge of industry best practices and frameworks
- • Project management and time management skills
- • Self-motivated with ability to not only work in group/individual setting, but able to drive action and make decisions independently with little to no direction
- • The ability to communicate effectively with people at all levels
- • Must be a confident communicator and presenter
- • Must possess excellent organizational and planning skills
- • Strong interpersonal skills, written and verbal communication
- • Ability to sit and work at a computer keyboard for extended periods of time
- • Ability to stoop, kneel, bend at the waist, and reach daily
- • Able to lift and move up to 25 pounds occasionally
- • Must utilize visual acuity, speech and hearing, hand and eye coordination and manual dexterity necessary to operate a computer and office equipment
- • Hours regularly 40 hours per week, as work dictates, from our Houston, TX corporate location or a remote location
Nice to Haves
- • Preferred experience with cloud computing, online services, web and enterprise applications, and data analytics
- • Preferred experience with data discovery, data mapping, authorization, and access management, and pseudonymization technologies
- • Familiarity with General Data Protection Regulation (GDPR), California Consumer Privacy Act (CCPA), Statement on Standard for Attestation Engagements No. 18 (SSAE18), System and Organization Controls 2 (SOC 2), International Organization for Standardization (ISO), National Institute of Standards and Technology (NIST), Payment Card Industry (PCI), Sarbanes-Oxley Act (SOX), preferred but not required
Benefits
- Flexible work opportunities, including remote and hybrid options
- Small, empowered teams that have fun delivering real value for our customers
- Medical, prescription, dental, vision, savings accounts, wellbeing program, life/disability, commuter, accidental insurance, legal services, and 401k
- Bereavement, paid holidays, floating holidays, vacation pay, sick leave, adoption assistance, and employee discounts
- Work-life resources and programs offering services for every stage of life to help manage day-to-day needs
- Summer Fridays from Memorial Day to Labor Day
- Holiday Early Departure: close out early the business day before a company observed holiday