GRC Analyst at BlackLine (Greater LA Area, CA or Remote)
Get to Know Us:
It's fun to work in a company where people truly believe in what they're doing!
At Blackline, we're committed to bringing passion and customer focus to the business of enterprise applications.
Since being founded in 2001, BlackLine has become a leading provider of cloud software that automates and controls the entire financial close process. Our vision is to modernize the finance and accounting function to enable greater operational effectiveness and agility, and we are committed to delivering innovative solutions and services to empower accounting and finance leaders around the world to achieve Modern Finance.
Being a best-in-class SaaS Company, we understand that bringing in new ideas and innovative technology is mission critical. At BlackLine we are always working with new, cutting edge technology that encourages our teams to learn something new and expand their creativity and technical skillset that will accelerate their careers.
Work, Play and Grow at BlackLine!
Make Your Mark:
The GRC Analyst will support Information Security Governance, Risk Management, and Compliance (GRC) workflows, validate adherence to information security standards, coordinate audit and regulatory compliance projects, facilitate information security awareness initiatives, help maintain standards, policies, and policies that govern information security program for the company.
You'll Get To:
- Contribute to the ongoing development the Information Security GRC activities, strategy, and roadmap.
- Assist with operating IT Risk Assessment, Vendor Management, and Risk Management programs.
- Evaluate design and implementation of security controls and build out automated operating effectiveness control monitoring capabilities.
- Support internal and external audits across security compliance programs (ISO 27001, ISO 27017, ISO 27018, ISO 27701, SOC 1, SOC 2, etc.).
- Collect and maintain evidence of compliance with information security policies and regulatory requirements (i.e. GDPR, CCPA, SOX, HIPAA, etc.).
- Coordinate written responses from customers and prospects on Information Security controls and regulatory compliance.
- Review and update information security policies, procedures, standards, and other InfoSec documentation.
- Assist in maintaining Information Security GRC documentation repository.
- Support vendor due diligence, security assessments and review processes.
What You'll Bring:
- 3+ years of experience
- Bachelor's degree in related field (Technology or Business-related)
- Understanding of technical aspects of information security.
- Working knowledge of common IT technologies and processes.
- Understanding of common Information Security and Information Technology frameworks and standards, such as, COBIT, CSA, NIST 800-53, SOC 1, SOC 2 and ISO 27000 series.
- Thorough understanding of risk management principles and methodologies.
- Ability to transform abstract regulatory requirements into cohesive compliance actions.
- Strong communication skills including ability to present technical subjects to non-technical audiences.
- Strong work ethic, attention to detail, and organizational skills.
- Ability to multi-task and manage priorities in a fast-paced environment.
- Ability to collaborate in a team setting and moderate conversations involving cross-functional groups.
- Conceptual understanding of software development methodologies.
- Proficient with the Microsoft office suite; presentation and report development skills.
- Working knowledge of PII, PHI, financial data regulations, data residency requirements, and international regulatory aspects pertaining to sensitive information (i.e. GDPR, CCPA, HIPAA, NYDFS 500, CPS 234, etc.)
- General knowledge of tools services commonly employed within InfoSec is a plus (DLP, IDS/IPS, SIEM, CASB, etc.).
- Experience with application security, SaaS, or cloud security is a plus.
We're Even More Excited If You Have:
- Certifications highly desired (CISA, CIA, CISM, CISSP, CRISC, etc.)
Thrive at BlackLine Because You Are Joining:
- A technology-based company with a sense of adventure and a vision for the future. Every door at BlackLine is open. Just bring your brains, your problem-solving skills, and be part of a winning team at the world's most trusted name in Finance Automation!
- A culture that is kind, open, and accepting. It's a place where people can embrace what makes them unique, and the mix of cultural backgrounds and varying interests cultivates diverse thought and perspectives.
- A culture where BlackLiner's continued growth and learning is empowered. BlackLine offers a wide variety of professional development seminars and inclusive affinity groups to celebrate and support our diversity.
BlackLine is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to sex, gender identity or expression, race, age, religious creed, national origin, physical or mental disability, ancestry, color, marital status, sexual orientation, military or veteran status, status as a victim of domestic violence, sexual assault or stalking, medical condition, genetic information, or any other protected class or category recognized by applicable equal employment opportunity or other similar laws.
BlackLine recognizes that the ways we work and the workplace itself has shifted. We innovate in a workplace that optimizes a combination of virtual and in-person interactions to maximize collaboration and nurture our culture. Candidates who live within a reasonable commute to one of our offices will work in the office at least 2 days a week.
USD $87,200.00 - USD $123,900.00
Pay Transparency Statement:
Placement within this range depends upon several factors, including the applicant's prior relevant job experience, skill set, and geographic location. In addition to base pay, BlackLine also offers short-term and long-term incentive programs, based on eligibility, along with a robust offering of benefit and wellness plans.