OPENTEXT
OpenText is a global leader in information management, where innovation, creativity, and collaboration are the key components of our corporate culture. As a member of our team, you will have the opportunity to partner with the most highly regarded companies in the world, tackle complex issues, and contribute to projects that shape the future of digital transformation.
The Opportunity
Working in the Global Information Security and Privacy team, the Senior Security Compliance Analyst will be expected to understand a wide array of IT security controls, processes, and concepts. The Senior Security Compliance Analyst will provide support for our Security Risk Management methodology and be specifically responsible for executing risk assessments for our product/platforms/services.
The role will have the opportunity to meaningfully contribute to the OpenText Compliance Program in accordance with ISO 27001, ISO 27017, PCI-DSS, SOC1/2/3, HIPAA, SOC2+HITRUST, TISAX, CyberEssentials PLUS, and FedRAMP applying a risk-based approach towards meeting this program.
This is a hands-on role that will require detailed knowledge of security concepts, governance models, commercial platform processing, risk models, security controls, security audits and other common IT and security domain concepts. You will be involved in managing/supporting and sustaining the various compliance programs by working collaboratively with internal teams, SMEs, external customers, vendors, auditors (external & internal) and other stakeholders.
You Are Great At
- Applying security policy and technical controls to risk assessments to Open Text business units to complete product/platform risk assessments
- Analyzing risk assessment results and working with risk owners on mitigation actions
- Participating in, or potentially leading, gap assessment, compliance readiness, and compliance monitoring activities.
- Interfacing with auditors, articulating control implementation and impact, and establishing considerations for applying security and compliance concepts to a technical cloud environment.
- Performing role of trusted advisor with technology and business stakeholders to drive, track, and resolve all aspects of compliance readiness and audit execution.
- Collaborating with other team members to support the delivery of multiple, simultaneous audits and certifications (both new and existing) within the OpenText portfolio
- Supporting the delivery of audit milestones to ensure audit timelines stay on target by proactively identifying, escalating, and coordinating the resolution of roadblocks and compliance risks.
- Effectively communicating compliance activity results, including status, workflow steps, remediation, and reporting, to a broad audience including peers and senior leaders.
- Contributing to metrics and dashboards for reporting on compliance program statuses.
What It Takes
- 2+ years of experience in IT audit/compliance or infosec related roles
- General
- Detailed understanding of evaluating the design and effectiveness of controls and experience working with auditors/regulators for compliance assessments
- Experience with preparation for and/or assisting assessment activities (SOC 1/2/3, ISO 27001, ISO 27017, PCI DSS, HIPAA/HITRUST, SOX, TISAX, Cyber Essentials Plus, FedRAMP, etc.) through planning, fieldwork, and final report delivery
- Experience with leading/assisting multiple, simultaneous audit engagements for a Cloud Service Provider, encompassing multiple frameworks
- Strong technical, analytical, interpersonal, communication and writing skills.
- Strong personal characteristics as demonstrated by the following: owners’ mindset, achievement-oriented, self-controlled, self-confident, flexible, approachable, proactive, resourceful and dedicated.
- Ability to work both independently and within a global team environment
- Demonstrated strength in working in a high change environment.
- Bachelor’s Degree in Information Technology, Business, or related vocations.
- Experience with GCP, AWS, Azure or other Cloud Service Provider is a plus
- Experience with GRC Tools & Compliance Automation is a plus.
- Industry standard certifications (CISSP, CISA, ISO 27001 Lead Implementer/Auditor) or equivalent is a plus
- Experience working on nightshifts is a plus
- Amenable to working the nightshift
OpenText's efforts to build an inclusive work environment go beyond simply complying with applicable laws. Our Employment Equity and Diversity Policy provides direction on maintaining a working environment that is inclusive of everyone, regardless of culture, national origin, race, color, gender, gender identification, sexual orientation, family status, age, veteran status, disability, religion, or other basis protected by applicable laws.
If you need assistance and/or a reasonable accommodation due to a disability during the application or recruiting process, please contact us at
[email protected]. Our proactive approach fosters collaboration, innovation, and personal growth, enriching OpenText's vibrant workplace.
44421