Dublin, California, US
Text size
aA+ aA-
Click here to print

Lead, Security Analysis

Country : USA USA

State : California

County : Alameda County

Town : Dublin

Category : Logistics

Contract type : Permanent

Availability : Full time

Job description

Welcome to Ross Stores, Inc., where our differences make us stronger... At Ross and dd's, inclusion is a way of life. We care about our Associates and the communities we serve and we value their differences. We are committed to building diverse teams and an inclusive culture. We respect and celebrate the diversity of backgrounds, identities, and ideas of those who work and shop with us. Come join us as we continue our diversity, equality and inclusion journey!GENERAL PURPOSE:
The Lead IT Risk Analyst is the senior member of the IT Risk Management group responsible for leading and executing IT risk management and governance processes within the organization. This includes performing risk assessments, tracking mitigation efforts and developing risk metrics and risk reports. This position is also responsible for leading security risk related projects and enhancing programs, such as third party risk assessments, insider threat management, updating security policies and standards and executing security awareness programs.
- Provides subject matter expertise in all aspects of risk management including performing risk assessments to proactively identify current and future security issues/vulnerabilities and recommend remediation strategies.
- Leads insider risk programs by identifying improvements and establishing supporting processes across the enterprise.
- Identifies and implements improvements to enhance the IT Risk Management program through optimization of processes, solutions, policies, procedures KPIs and other techniques.
- Performs third party risk management and reviews of contracts and agreements to ensure necessary security controls have been included as part of services and capabilities for the protection of company assets.
- Develops standards to support vendor selection and RFP process and participates in product and vendor selection process to provide subject matter expertise on Information security risk and compliance.
- Maintains risk register and develops IT Risk Management metrics and reports. Collaborates with IT Compliance Manager, Secure SDLC Manager, Information Security, and IT groups to gather and analyze metrics.
- Leads information security awareness programs by regularly conducting exercise to educate employees of information security and best practices.
- Monitors current and proposed laws, regulations, industry standards, and ethical requirements related to information security and privacy.
- Analysis / Judgment
- Team Work
- Communication
- Customer Service
- Drive for Results
- Interpersonal Effectiveness
- Technical Competence and Expertise
- Business Acumen
- Five years of experience within Information Technology with at least 3 in Security and/or Risk Management.
- Bachelor degree preferred or equivalent combination of education and relevant experience
- Strong understanding of security governance, compliance and risk management principles
- Proficient in Microsoft Word, Excel, Powerpoint
- Excellent analytical, organizational and communication skills
- Strong Project Management skills
- CISSP (Certified Information Systems Security Professional)
- CRISC (Certified in Risk and Information Systems Control (CRISC)
- Working knowledge of UNIX and Windows
- Firewalls, VPN, PKI, IPS
- Oracle, MS SQL
- Virtualization Security
- Software programming skills
- Job requires ability to work in an office environment, primarily on a computer.
- Requires sitting, standing, walking, hearing, talking on the telephone, attending in-person meetings, typing, and working with paper/files, etc.
- Consistent timeliness and regular attendance.
- Vision requirements: Ability to see information in print and/or electronically.
- This role requires regular in-office presence, including to engage in in-person team interaction, meetings and collaboration, client support, mentoring, coaching, and/or feedback. However, this role can perform duties effectively using a combination of in-office and remote work.
This job description is a summary of the primary duties and responsibilities of the job and position. It is not intended to be a comprehensive or all-inclusive listing of duties and responsibilities. Contents are subject to change at management's discretion.
Ross is an equal employment opportunity employer. We consider individuals for employment or promotion according to their skills, abilities and experience. We believe that it is an essential part of the Company's overall commitment to attract, hire and develop a strong, talented and diverse workforce. Ross is committed to complying with all applicable laws prohibiting discrimination based on race, color, religious creed, age, national origin, ancestry, physical, mental or developmental disability, sex (which includes pregnancy, childbirth, breastfeeding and medical conditions related to pregnancy, childbirth or breastfeeding), veteran status, military status, marital or registered domestic partnership status, medical condition (including cancer or genetic characteristics), genetic information, gender, gender identity, gender expression, sexual orientation, as well as any other category protected by federal, state or local laws.
Click here to print

Fashion Jobs

Website reserved for fashion, luxury and beauty industry professionals.