Talent.com
Risk Management Analyst

Risk Management Analyst

CubicWellington, New Zealand
23 days ago
Job description

OverviewBusiness Unit : Cubic Transportation SystemsCompany Details : When you join Cubic, you become part of a company that creates and delivers technology solutions in transportation to make people's lives easier by simplifying their daily journeys, and defense capabilities to help promote mission success and safety for those who serve their nation.

Led by our talented teams around the world, Cubic is committed to solving global issues through innovation and service to our customers and partners.

We have a top-tier portfolio of businesses, including Cubic Transportation Systems (CTS) and Cubic Defense (CD).

Explore more on Cubic.com.Job Details : Cubic Transportation Systems (CTS) is a global leader in intelligent transportation solutions, specializing in technologies that make public transit more efficient, accessible, and user-friendly.

A significant feature is providing Fare and Payment card services to government and municipal customers across the globe.Job Summary : As Member of the Cubic information security team, you will provide security compliance support for production transaction processing environments.

Evaluate posture of security controls and operating environment to ensure compliance with organization security policies and controls.

Plans and prepares the scope of IT compliance evaluation programs across the organization and isolates potential risks or liabilities and develop mitigation plans.

Partners with external auditors to coordinate and facilitate PCI-DSS, ISO

  • , etc. compliance / audit efforts.

This position typically works under limited supervision and direction.

Candidates for this position will regularly exercise discretionary and substantial decision-making authority.RESPONSIBILITIESResponsibilitiesPerform as the recognized Subject Matter Expert on Security Risk Assessment methodology, policy, strategy and processes.Facilitate all security audit operations, including scheduling, vendor coordination, program, and stakeholder coordination.Responsible for coordination with the Internal / External Auditors and Information Technology teams to successfully complete periodic audits.

Works independently to schedule and conduct control walk through meetings and address follow up procedures to ensure all stakeholders understand duties and responsibilitiesLead the design and control reviews and assessments to support continuous compliance with security policies and standardsManage security review processes for all solutions to ensure they their design and implementation meets compliance requirements – including : PCI-DSS, ISO

  • , SOC 1 & SOC 2 and other regional requirements like the Australian Essential 8 and New Zealand NZ-ISM.
  • Document and actively communicate any areas where the solutions and processes are not fully compliant.Identify and report significant information security risks associated with applications, development, networking, data centers, Cloud and physical IT infrastructure, vendors and other third parties.Identify stakeholders in remediation of compliance gaps and actively escalate issues to them in a constructive manner that helps them understand the actions required.

    Work to gain acceptance of responsibility and track progress towards remediation.

    Actively manage escalation as needed if solutions are not resolved in a timely manner.Work with system operators and security subject matter experts to communicate system compliance gaps and develop acceptable remediation plans.Capture compliance gaps and remediation plans in the OneTrust GRC system.

    Plans, reviews, and performs (as needed) controls monitoring around complex customer facing systems using the One Trust.Liaise / engage with Cubic customers and Security Teams to build positive relationships and outcomesSupports efforts to educate Security Management and Security Team Members in compliant IT processes and controls.

    Prepare and maintain process and control documentationAid in the development of solutions to problems identified during audits and translates these solutions into practical recommendations.

    Partner with Operations and Engineering Teams to ensure timely and acceptable remediation of issues.Follow up on recommendations and appraises corrective actions taken to improve deficient conditions.

    To the greatest extent possible, ensure all Corporate Standards, SDLC, Change Management, and risk governance protocols are followed.Review vendor contracts and SOC reports to evaluate the impact on the company's controls.

    Coordinates with third party vendors where appropriate.General Duties and Responsibilities : General Duties and ResponsibilitiesReliably demonstrate accountability for work assignments and proactive communications about issues and status.

    A strong history of proactively identifying effective solutions for challenges.Able to reliably demonstrate ethical behavior and accurate communications even when complex factors are involved.Able to operate in a professional manner, even in tense or continuous settings.Comply with Cubic's Quality Management SystemComply with Cubic\'s quality, health, safety, and security policies.Support the company's strategic objectives and collaborate across departments.Comply with Cubic Human Resources ProceduresSKILLS / EXPERIENCE / KNOWLEDGEEssential : Strong written and oral communication skills in English, with capability to use Microsoft Office solutions.

    Ability to effectively and openly collaborate with team members clients, IT management, staff, and business units in a cross functional and matrixed IT organizationComfortable working with staff at all levels and in other geographical locations within the organizationFamiliarity with PCI DSS 4, ISO

  • , and or SOC I / II requirements and audits.Expert level experience collaborating with stakeholders and solution providers in a cross functional and matrixed IT organization.
  • Able to adapt style efforts to persuade in delivering messages that relate to the wider business.

    Is frequently called on to advise others on complex matters and may be accountable through team for delivery of business targets.Exhibits advanced wide- ranging experience, using in- depth professional knowledge, acumen, concepts and company objectives to develop, resolve complex models and procedures.

    Provides solutions to issues in creative and effective ways.

    Understands the interrelationships of different disciplines.

    Directs the application of existing principles and guides development of new policies and ideas.Understands and works on complex issues where analysis of situations or data requires an in-depth evaluation of variable factors.

    Determines methods and procedures on new assignments.

    Exercises judgment in selecting methods, evaluating, adapting complex techniques and evaluation criteria for obtaining results.Desirable : Deep understanding of security risks and threats as they relate to the company's operating environments.QUALIFICATIONSQualificationsEssential : Minimum 8 years' experience in services or IT systems in a mission critical setting.University degree in Computer Science, Engineering, or other technical fields, or Business Administration with relevant IT work experience.At least 5 years' experience working in IT security and / or Payment Card processing systems.

    Strong understanding of technical concepts, as well as demonstrated ability to understand complex internally developed systems.The candidate must reside within commuting distance from CTS offices in Wellington NZ, and be able to periodically travel within the region.DesirableRelevant security or IT compliance certification in one or more areas, such as CISA, CRISC, CCSK, CCISSP, GIAC, PCI-ISA / QSA or equivalent.Knowledge of or willingness to learn information security best practices as it pertains to Open Payments, Mobility as a Service, data classifications, Microsoft Azure, AWS (or similar) cloud security and infrastructure, Web infrastructure security (Applications and APIs), Network security tools (IDS / IPS, firewalls, etc.), Encryption technology and implementation, Database security, Operating system security and hardening, vulnerability assessment tools and writing risk mitigation plans according to the assessment, and SIEM and FIM solutions.Condition of Employment : Successful outcome of a National Police CheckThe description provided above is not intended to be an exhaustive list of all job duties, responsibilities and requirements.

    Duties, responsibilities and requirements may change over time and according to business need.

    #LI-DM1Worker Type : Employee

    #J-

  • Ljbffr
  • Create a job alert for this search

    Analyst • Wellington, New Zealand

    Related jobs
    • Promoted
    Senior Risk Analyst

    Senior Risk Analyst

    KPMG New ZealandWorkFromHome, Wellington, New Zealand
    KPMG is one of the most trusted and respected global professional services firms.Through depth of expertise, clarity of insight and strength of purpose we help our clients solve complex challenges,...Show moreLast updated: 2 days ago
    • Promoted
    Risk and Assurance Manager

    Risk and Assurance Manager

    KPMG New ZealandWorkFromHome, Wellington, New Zealand
    KPMG is one of the most trusted and respected global professional services firms.Through depth of expertise, clarity of insight and strength of purpose we help our clients solve complex problems, s...Show moreLast updated: 18 days ago
    • Promoted
    Risk Management Analyst

    Risk Management Analyst

    CubicWellington, Wellington, New Zealand
    Business Unit : Cubic Transportation Systems.Company Details : When you join Cubic, you become part of a company that creates and delivers technology solutions in transportation to make people’s live...Show moreLast updated: 26 days ago
    • Promoted
    Senior Technology Risk Management Analyst

    Senior Technology Risk Management Analyst

    New Zealand GovernmentWellington, Wellington, New Zealand
    Mō tēnei tūranga mahi | About this role • Career development opportunities • A chance to help shape how we manage risk • Work that keeps MSD's technology environment strong and resilientBring structur...Show moreLast updated: 4 days ago
    • Promoted
    Security Analyst

    Security Analyst

    Cubic CorporationWellington, Wellington, New Zealand
    As a member of the Cubic Information Security Team, you will be responsible for supporting efforts to monitor security for Cubic systems and assist in the analysis and response to incidents.The suc...Show moreLast updated: 22 days ago
    • Promoted
    Senior Technology Risk Management Analyst

    Senior Technology Risk Management Analyst

    Ministry of Social DevelopmentWellington, Wellington, New Zealand
    Press Tab to Move to Skip to Content Link.Select how often (in days) to receive an alert : .Senior Technology Risk Management Analyst. A chance to help shape how we manage risk.Work that keeps MSD’s t...Show moreLast updated: 6 days ago
    • Promoted
    Group Risk Manager, Technology & Data

    Group Risk Manager, Technology & Data

    New Zealand GovernmentWellington, Wellington, New Zealand
    Group Risk Manager, Technology & Data at Accident Compensation Corporation, Wellington## Mō tēnei tūranga mahi | About this roleACC exists to support people - we help prevent injuries and get New Z...Show moreLast updated: 1 day ago
    • Promoted
    Manager - Cyber Security - Risk Management or Technology Audit

    Manager - Cyber Security - Risk Management or Technology Audit

    Ernst & Young Advisory Services Sdn BhdWellington, Wellington, New Zealand
    Other locations : Primary Location Only.At EY, we’re all in to shape your future with confidence.We’ll help you succeed in a globally connected powerhouse of diverse teams and take your career where...Show moreLast updated: 22 days ago
    • Promoted
    Regional Risk Manager - Central

    Regional Risk Manager - Central

    WaikatodhbnewsroomWorkFromHome, Wellington, New Zealand
    The role leads Line 2 risk management activities across your region, ensuring risks are identified, assessed, and managed in line with Health NZ's risk management policy and framework and within ri...Show moreLast updated: 14 days ago
    • Promoted
    Risk Management Analyst

    Risk Management Analyst

    Cubic CorporationWellington, Wellington, New Zealand
    As Member of the Cubic information security team, you will provide security compliance support for production transaction processing environments. Evaluate posture of security controls and operating...Show moreLast updated: 22 days ago
    • Promoted
    • New!
    Senior Risk Analyst

    Senior Risk Analyst

    Kpmg New ZealandWellington, New Zealand
    KPMG is one of the most trusted and respected global professional services firms.Through depth of expertise, clarity of insight and strength of purpose we help our clients solve complex challenges,...Show moreLast updated: 22 hours ago
    • Promoted
    Software Architect

    Software Architect

    Aviat NetworksLower Hutt, Wellington, New Zealand
    The embedded software architect is an experienced software developer who is responsible for making high-level design choices and decisions for software projects. The architect translates requirement...Show moreLast updated: 30+ days ago
    • Promoted
    Risk and Change Manager - Infrastructure

    Risk and Change Manager - Infrastructure

    KiwiRailWellington, Wellington, New Zealand
    Risk and Change Manager - Infrastructure.Lead and embed effective risk management and change control practices.Permanent, Auckland, Wellington. At KiwiRail, we connect New Zealanders sustainably, po...Show moreLast updated: 15 days ago
    • Promoted
    Solution Architect

    Solution Architect

    FederatoWorkFromHome, New Zealand
    Federato is on a mission to defend the right to efficient, equitable insurance for all.We enable insurers to provide affordable coverage to people and organizations facing today’s challenges, inclu...Show moreLast updated: 22 days ago
    • Promoted
    IT Risk and Compliance Analyst - Datam

    IT Risk and Compliance Analyst - Datam

    NZ PostWellington, Wellington, New Zealand
    Be among the first 25 applicants.Get AI-powered advice on this job and more exclusive features.At Datam, you’ll get the best of both worlds – the backing of NZ Post and the freedom of a nimble, ind...Show moreLast updated: 1 day ago
    • Promoted
    Project Director

    Project Director

    MWH TreatmentWorkFromHome, New Zealand
    We are looking to strengthen our Delivery team with a Project Director based at Testwood with hybrid working available.You will report directly to the Regional Operations Director and you will have...Show moreLast updated: 11 days ago
    • Promoted
    Senior Technology Risk Management Analyst

    Senior Technology Risk Management Analyst

    Ministry Of Social DevelopmentWellington, New Zealand
    Press Tab to Move to Skip to Content Link.Select how often (in days) to receive an alert : .Senior Technology Risk Management Analyst. A chance to help shape how we manage risk.Work that keeps MSD's t...Show moreLast updated: 5 days ago
    • Promoted
    Risk Assurance Manager

    Risk Assurance Manager

    Consult RecruitmentWellington, Wellington, New Zealand
    This respected global consultancy is known for empowering organisations through insight-driven strategies and a people-first culture. Our Client values integrity, innovation, and impact, delivering ...Show moreLast updated: 1 day ago
    • Promoted
    Analyst - Loan Management

    Analyst - Loan Management

    QuaestoradvisorsNew Zealand
    Manage a portfolio of construction loans for New Zealand Housing Projects under the Kiwi-Build program.Responsible for monthly valuation of all assigned investments. Be prepared to take lead on aggr...Show moreLast updated: 22 days ago
    • Promoted
    Regional Risk Manager - Central

    Regional Risk Manager - Central

    New Zealand GovernmentWellington, Wellington, New Zealand
    Mō tēnei tūranga mahi | About this role • Central based • Permanent, Full TimeHealth New Zealand | Te Whatu Ora is the country's largest employer, delivering universal public healthcare to 5 million ...Show moreLast updated: 14 days ago