Security Governance Risk & Compliance Analyst at Commerce | TX | Rezi

Security Governance Risk & Compliance Analyst at Commerce

Security Governance Risk & Compliance Analyst

Commerce · TX

2 months ago

Security Governance Risk & Compliance Analyst

Commerce · TX

2 months ago
Resume preview

Impress employers and recruiters.
Choose from hundreds of resume examples.

Target Resume Now

About the Role

Commerce is seeking a Senior Security Governance Risk and Compliance Analyst to support compliance programs and implement risk improvement processes. This role is crucial for maintaining Information Security leadership in the e-commerce space and protecting data.

Responsibilities

  • Function as a frontline representative of Information Security, leading by example with diplomacy, firmness, fairness, flexibility, and consistency in deploying industry-standard information security best practices and applicable laws, regulations, and policies.
  • Manage third-party risk assessments using a risk-based framework, from onboarding due diligence to continuous monitoring, leveraging platforms like OneTrust, SafeBase, or similar.
  • Partner with fraud operations and data science to model and detect threats such as account takeovers, payment abuse, promo fraud, and affiliate misbehavior.
  • Understand fraud detection platforms, e.g., eHawk, Recorded Future, etc.
  • Maintain metrics and reporting that tie fraud risk to potential loss or customer impact in real terms.
  • Demonstrate understanding of BC GRC Office strategic vision, be a self-starter, and take responsibility for actions promoting this strategic vision.
  • Provide support and guidance regarding best practice, regulatory, and legal compliance, including PCI, GDPR, ISO 27001, NIST, and SOX.
  • Assist in evaluating the design and operating effectiveness of the BC Integrated Secure Controls Framework (BC SCF) built from Industry Standards such as NIST, ISO 27001, PCI DSS around technology controls, including, but not limited to Software Development Lifecycle (SDLC), Logical Security, Data interfaces, availability/redundancy, and Cyber / Info security.
  • Prepare supporting evidence and document test plans that clearly describe the audit procedures performed, results of testing, and conclusions reached for various processes.
  • Create technology diagrams detailing the systems and their dependencies during the audit process.
  • Assist with the Department’s data collection and analytics efforts and Internal Audit report preparation.
  • Assist in the development and tracking of control recommendations for corrective action/improvement.
  • Work with Internal Audit leadership to identify and continuously improve departmental practices.
  • Monitor and demonstrate compliance with organizational policies and practices, as evidenced by strong quality assurance results, and strong performance within standards and related metrics.
  • Stay abreast of current issues and obtain continuing education and training.
  • Participate in special projects and perform other duties as requested.
  • Interact with all levels of management to provide effective risk and control advice, maintaining active communication to enhance risk and control awareness and manage expectations.
  • Provide data analysis support for ongoing compliance monitoring.
  • Maintain up-to-date knowledge about audit controls and techniques.
  • Utilize innovative ideas and tools to enhance operational effectiveness.
  • Evaluate and recommend improvements to business practices, processes, and controls.

Requirements

  • 5-6 years of relevant experience in a technology environment.
  • Experience with translating business requirements into project implementation plans and validation, including user acceptance testing.
  • Knowledge of network-based services, client/server applications, cloud-based and virtualized environments, mobile applications, enterprise systems and infrastructure, network architecture, and security infrastructure.
  • Passion about process improvement and removing friction from systems.
  • Direct experience with audit and compliance frameworks, e.g., ISO 27001, 2007:2017, PCI, etc.
  • Background in IT hardware/software concepts and processes used within the business, covering Core security concepts, Cloud-based services, Windows and Linux operating systems, and Open-source ecosystem (databases, applications, etc.).
  • Experience with auditors and the evidence collection process.
  • Experience with the design and testing of IT security controls in a managed hosting and/or Software-as-a-Service environment.
  • Experience in building relationships across business functions, locations, and technical stakeholders.
  • Self-direction, attention to detail with a passion to solve practical problems while dealing with a number of variables.
  • Ability to present ideas/solutions and communicate clearly, concisely, and accurately with others at all levels of the organization.
  • Experience in reading the culture of a company, adjusting your style and adapting as needed.
  • Collaborative, upbeat work ethic where you both take ownership and have fun.
  • Able to meet deliverables and drive your work to completion within specified timelines.
  • Great verbal and written communication skills.

Skills

  • Information Security
  • Risk Management
  • Compliance
  • Third-party risk assessments
  • OneTrust
  • SafeBase
  • Fraud detection
  • PCI
  • GDPR
  • ISO 27001
  • NIST
  • SOX
  • NIST
  • ISO 27001
  • PCI DSS
  • SDLC
  • Logical Security
  • Data interfaces
  • Cybersecurity
  • IT controls
  • Data analysis
  • Network security
  • Cloud security
  • SaaS security

Location

  • Remote
  • Hybrid

Work Type

  • Hybrid

Experience Level

  • Senior
  • 5-6 years

Salary/Compensations

  • $49,729.00 - $84,100.00

About the Company

  • Commerce is the parent company of BigCommerce, Feedonomics, and Makeswift, operating an open, AI-driven commerce ecosystem.
  • The company's mission is to empower businesses to innovate, grow, and thrive by connecting tools and systems that power growth.
  • Commerce believes in harnessing AI responsibly to unlock new possibilities and help businesses solve complex commerce challenges.
  • The company is committed to being a leader in Information Security in the e-commerce space.
  • Commerce is a group of clever, committed, curious people, unleashing talent in all they do.
  • They believe in the power of togetherness, striving at the edge of what’s possible, impacting the lives of billions of people for the better.
  • The company culture emphasizes doing extraordinary things through dedication, collaboration, and inspiration.

Equal Opportunity

  • Commerce believes that celebrating the unique histories, perspectives and abilities of every employee makes a difference for our company, our customers and our community.
  • We are an equal opportunity employer and the inclusive atmosphere we build together will make room for every person to contribute, grow and thrive.
  • We are committed to creating an inclusive and accessible hiring experience for all candidates.
  • If you require accommodations or adjustments at any stage of the recruitment process, please let us know and we will work with you to meet your needs.