Talent.com
Risk Management Analyst
Risk Management AnalystCubic • Wellington, Wellington, New Zealand
Risk Management Analyst

Risk Management Analyst

Cubic • Wellington, Wellington, New Zealand
30+ days ago
Job description

Overview

Business Unit : Cubic Transportation Systems

Company Details : When you join Cubic, you become part of a company that creates and delivers technology solutions in transportation to make people’s lives easier by simplifying their daily journeys, and defense capabilities to help promote mission success and safety for those who serve their nation. Led by our talented teams around the world, Cubic is committed to solving global issues through innovation and service to our customers and partners. We have a top-tier portfolio of businesses, including Cubic Transportation Systems (CTS) and Cubic Defense (CD). Explore more on Cubic.com.

Job Details : Cubic Transportation Systems (CTS) is a global leader in intelligent transportation solutions, specializing in technologies that make public transit more efficient, accessible, and user-friendly. A significant feature is providing Fare and Payment card services to government and municipal customers across the globe.

Job Summary : As Member of the Cubic information security team, you will provide security compliance support for production transaction processing environments. Evaluate posture of security controls and operating environment to ensure compliance with organization security policies and controls. Plans and prepares the scope of IT compliance evaluation programs across the organization and isolates potential risks or liabilities and develop mitigation plans. Partners with external auditors to coordinate and facilitate PCI-DSS, ISO 27001, etc. compliance / audit efforts. This position typically works under limited supervision and direction. Candidates for this position will regularly exercise discretionary and substantial decision-making authority.

RESPONSIBILITIES

Responsibilities

  • Perform as the recognized Subject Matter Expert on Security Risk Assessment methodology, policy, strategy and processes.
  • Facilitate all security audit operations, including scheduling, vendor coordination, program, and stakeholder coordination.
  • Responsible for coordination with the Internal / External Auditors and Information Technology teams to successfully complete periodic audits. Works independently to schedule and conduct control walk through meetings and address follow up procedures to ensure all stakeholders understand duties and responsibilities
  • Lead the design and control reviews and assessments to support continuous compliance with security policies and standards
  • Manage security review processes for all solutions to ensure they their design and implementation meets compliance requirements – including : PCI-DSS, ISO 27001, SOC 1 & SOC 2 and other regional requirements like the Australian Essential 8 and New Zealand NZ-ISM. Document and actively communicate any areas where the solutions and processes are not fully compliant.
  • Identify and report significant information security risks associated with applications, development, networking, data centers, Cloud and physical IT infrastructure, vendors and other third parties.
  • Identify stakeholders in remediation of compliance gaps and actively escalate issues to them in a constructive manner that helps them understand the actions required. Work to gain acceptance of responsibility and track progress towards remediation. Actively manage escalation as needed if solutions are not resolved in a timely manner.
  • Work with system operators and security subject matter experts to communicate system compliance gaps and develop acceptable remediation plans.
  • Capture compliance gaps and remediation plans in the OneTrust GRC system. Plans, reviews, and performs (as needed) controls monitoring around complex customer facing systems using the One Trust.
  • Liaise / engage with Cubic customers and Security Teams to build positive relationships and outcomes
  • Supports efforts to educate Security Management and Security Team Members in compliant IT processes and controls. Prepare and maintain process and control documentation
  • Aid in the development of solutions to problems identified during audits and translates these solutions into practical recommendations. Partner with Operations and Engineering Teams to ensure timely and acceptable remediation of issues.
  • Follow up on recommendations and appraises corrective actions taken to improve deficient conditions. To the greatest extent possible, ensure all Corporate Standards, SDLC, Change Management, and risk governance protocols are followed.
  • Review vendor contracts and SOC reports to evaluate the impact on the company’s controls. Coordinates with third party vendors where appropriate.

General Duties and Responsibilities :

General Duties and Responsibilities

  • Reliably demonstrate accountability for work assignments and proactive communications about issues and status. A strong history of proactively identifying effective solutions for challenges.
  • Able to reliably demonstrate ethical behavior and accurate communications even when complex factors are involved.
  • Able to operate in a professional manner, even in tense or continuous settings.
  • Comply with Cubic’s Quality Management System
  • Comply with Cubic\'s quality, health, safety, and security policies.
  • Support the company's strategic objectives and collaborate across departments.
  • Comply with Cubic Human Resources Procedures
  • SKILLS / EXPERIENCE / KNOWLEDGE

    Essential :

  • Strong written and oral communication skills in English, with capability to use Microsoft Office solutions. Ability to effectively and openly collaborate with team members clients, IT management, staff, and business units in a cross functional and matrixed IT organization
  • Comfortable working with staff at all levels and in other geographical locations within the organization
  • Familiarity with PCI DSS 4, ISO , and or SOC I / II requirements and audits.
  • Expert level experience collaborating with stakeholders and solution providers in a cross functional and matrixed IT organization. Able to adapt style efforts to persuade in delivering messages that relate to the wider business. Is frequently called on to advise others on complex matters and may be accountable through team for delivery of business targets.
  • Exhibits advanced wide- ranging experience, using in- depth professional knowledge, acumen, concepts and company objectives to develop, resolve complex models and procedures. Provides solutions to issues in creative and effective ways. Understands the interrelationships of different disciplines. Directs the application of existing principles and guides development of new policies and ideas.
  • Understands and works on complex issues where analysis of situations or data requires an in-depth evaluation of variable factors. Determines methods and procedures on new assignments. Exercises judgment in selecting methods, evaluating, adapting complex techniques and evaluation criteria for obtaining results.
  • Desirable :

  • Deep understanding of security risks and threats as they relate to the company’s operating environments.
  • QUALIFICATIONS

    Qualifications

    Essential :

  • Minimum 8 years’ experience in services or IT systems in a mission critical setting.
  • University degree in Computer Science, Engineering, or other technical fields, or Business Administration with relevant IT work experience.
  • At least 5 years’ experience working in IT security and / or Payment Card processing systems. Strong understanding of technical concepts, as well as demonstrated ability to understand complex internally developed systems.
  • The candidate must reside within commuting distance from CTS offices in Wellington NZ, and be able to periodically travel within the region.
  • Desirable

  • Relevant security or IT compliance certification in one or more areas, such as CISA, CRISC, CCSK, CCISSP, GIAC, PCI-ISA / QSA or equivalent.
  • Knowledge of or willingness to learn information security best practices as it pertains to Open Payments, Mobility as a Service, data classifications, Microsoft Azure, AWS (or similar) cloud security and infrastructure, Web infrastructure security (Applications and APIs), Network security tools (IDS / IPS, firewalls, etc.), Encryption technology and implementation, Database security, Operating system security and hardening, vulnerability assessment tools and writing risk mitigation plans according to the assessment, and SIEM and FIM solutions.
  • Condition of Employment :

    Successful outcome of a National Police Check

    The description provided above is not intended to be an exhaustive list of all job duties, responsibilities and requirements. Duties, responsibilities and requirements may change over time and according to business need.

    #LI-DM1

    Worker Type : Employee

    #J-18808-Ljbffr

    Create a job alert for this search

    Analyst • Wellington, Wellington, New Zealand

    Related jobs
    Manager Line One Risk

    Manager Line One Risk

    Kiwibank • Wellington, New Zealand
    Manager Line One Risk – Kiwibank.Six month fixed term opportunity - covering parental leave.At Kiwibank, we're passionate about supporting Kiwi to thrive. As our Line One Risk Manager, you'll be at ...Show more
    Last updated: 2 days ago • Promoted
    Trade Remedies Analyst

    Trade Remedies Analyst

    New Zealand Ministry Of Economic Development • Wellington, Wellington, New Zealand
    Select how often (in days) to receive an alert : .Gain experience working on high profile trade investigations.Apply your analytical skills to complex economic, legal, and policy issues.Contribute to...Show more
    Last updated: 11 days ago • Promoted
    Business Change Lead

    Business Change Lead

    New Zealand Ministry Of Economic Development • Wellington, Wellington, New Zealand
    Select how often (in days) to receive an alert : .Discover a career with purpose at MBIE.New Year, new opportunity | start date in January • • • •. Support Immigration New Zealand (INZ) to successfully d...Show more
    Last updated: 11 days ago • Promoted
    Geospatial Analyst

    Geospatial Analyst

    Ministry for Primary Industries • Wellington, Wellington, New Zealand
    Geospatial Analyst – Ministry for Primary Industries (MPI).Your opportunity to join the Geospatial team in the Data & Information group at MPI. BTIS F : $85,928 to $100,351 depending on skills and ex...Show more
    Last updated: 2 hours ago • Promoted • New!
    Risk Targeting Analyst

    Risk Targeting Analyst

    New Zealand Ministry Of Economic Development • Wellington, Wellington, New Zealand
    Select how often (in days) to receive an alert : .Discover a career with purpose at MBIE.Analyse and mitigate immigration risks using data-driven insights. Inform the design of targeting rules and pro...Show more
    Last updated: 11 days ago • Promoted
    HSO - GS - D365 F&O Finance Functional Architect 12+ Years - Remote

    HSO - GS - D365 F&O Finance Functional Architect 12+ Years - Remote

    HSO Enterprise Solutions GmbH • WorkFromHome, Wellington, New Zealand
    HSO is seeking an experienced D365 F&O Finance Functional Architect to lead and manage implementations of Microsoft Dynamics 365 for Finance and Operations. This remote role offers the opportunity t...Show more
    Last updated: 2 hours ago • Promoted • New!
    Team Manager National Monitoring & Intelligence

    Team Manager National Monitoring & Intelligence

    Ministry for Primary Industries (MPI) • Lower Hutt, Wellington, New Zealand
    Team Manager National Monitoring & Intelligence.General Salary Range C - $119,376 to $139,700 depending on skills and experience. About the Role - Kōrero mō te tūranga.Lead a team that turns informa...Show more
    Last updated: 2 hours ago • Promoted • New!
    Senior Px Analyst (Nfr Op Res)

    Senior Px Analyst (Nfr Op Res)

    Australia And New Zealand Banking Group Limited • Wellington, New Zealand
    Select how often (in days) to receive an alert : .Senior PX Analyst (NFR Op Res).Department : NZ Strategic Execution Project Delivery. Location : Auckland or Wellington.Kia Hanga I Te Ao, E Ora Ai, E Tu...Show more
    Last updated: 16 days ago • Promoted
    Senior Analyst - National Asset Management

    Senior Analyst - National Asset Management

    Kainga Ora - Homes And Communities • Wellington, New Zealand
    Senior Analyst - National Asset Management.From dashboards to deep analysis—help us unlock effective monitoring and smarter decisions on asset performance. Flexible on Auckland / Wellington / Christchu...Show more
    Last updated: 1 hour ago • Promoted • New!
    Compliance And Risk Analyst

    Compliance And Risk Analyst

    Craigs Investment Partners Limited • New Zealand
    We have a full time, permanent opportunity for an Analyst to join our Compliance and Risk team based at our Head office in Tauranga. Compliance & Risk perform the critical function within Craigs Inv...Show more
    Last updated: 30+ days ago • Promoted
    Manager Risk Rules

    Manager Risk Rules

    Ministry Of Business, Innovation And Employment • Wellington, New Zealand
    Discover a career with purpose at MBIE.Be at the forefront of immigration risk targeting and rule deployment.Lead a team of technical specialists delivering high-impact solutions.Collaborate across...Show more
    Last updated: 9 days ago • Promoted
    Change Manager

    Change Manager

    nzpolice • Wellington, Wellington, New Zealand
    Based at Police National Headquarters, Wellington CBD.Stand at the stern of the canoe and feel the spray of the future biting at your face. As a Change Manager within the Delivery Capability team, y...Show more
    Last updated: 2 hours ago • Promoted • New!
    Release Manager - Digital Applications & Product

    Release Manager - Digital Applications & Product

    Kiwi Health Jobs • WorkFromHome, New Zealand
    Release Manager - Digital Applications & Product.Health New Zealand | Te Whatu Ora is the country's largest employer, delivering universal public healthcare to 5 million New Zealanders.We provide e...Show more
    Last updated: 2 hours ago • Promoted • New!
    Organization Transformation - Senior Analyst / Manager

    Organization Transformation - Senior Analyst / Manager

    Pwc New Zealand • Wellington, New Zealand
    It's a great time to be joining PwC New Zealand - a community of solvers that lead with the heart and live by our values. Join us and make a meaningful impact while working with cutting-edge tech.Ng...Show more
    Last updated: 30+ days ago • Promoted
    Manager Risk Targeting Analysis

    Manager Risk Targeting Analysis

    New Zealand Ministry Of Economic Development • Wellington, Wellington, New Zealand
    Select how often (in days) to receive an alert : .Discover a career with purpose at MBIE.Shape the future of immigration risk targeting through data, intelligence and insight.Lead a high-performing t...Show more
    Last updated: 11 days ago • Promoted
    Quality Systems Project Manager - Planning, Funding and Outcomes

    Quality Systems Project Manager - Planning, Funding and Outcomes

    Waikatodhbnewsroom • WorkFromHome, New Zealand
    Quality Systems Project Manager - Planning, Funding and Outcomes.All Locations | Permanent, full-time | Multiple Positions Available. Lead projects that improve patient safety and quality of care ac...Show more
    Last updated: 2 hours ago • Promoted • New!
    Analyst

    Analyst

    New Zealand Government • Wellington, New Zealand
    New Zealand Police is working with the community to keep New Zealanders safe.With over 16,000 staff, we provide policing services 24 hours a day. We operate by land, sea and air, manage over 860,000...Show more
    Last updated: 30+ days ago • Promoted
    Manager Risk Rules

    Manager Risk Rules

    New Zealand Ministry Of Economic Development • Wellington, Wellington, New Zealand
    Select how often (in days) to receive an alert : .Be at the forefront of immigration risk targeting and rule deployment.Lead a team of technical specialists delivering high-impact solutions.Collabora...Show more
    Last updated: 11 days ago • Promoted