GRC Risk Analyst at GoFundMe | Torre

GRC Risk Analyst

Emma highlights
This highlight was written by Emma’s AI. Ask Emma to edit it.
Full-time
Compensation
USD95k - 130k/year
location_on
Remote (anywhere)
Posted about 3 years ago

Responsibilities


GoFundMe is a global community of over 100 million people with the common purpose of helping one another. In 2022, GoFundMe joined together with Classy, a leading nonprofit fundraising software company. Together, GoFundMe and Classy have empowered people and organizations to raise more than $25 billion since 2010. Our vision is to become the most helpful place in the world. The GoFundMe team is searching for our next GRC Analyst. As a member of the CISO team, the GRC Analyst will be responsible for uplifting and bolstering the day-to-day operations. This includes delving into all aspects of enhanced due diligence, abiding by regulatory, contractual, and card network (PCI) requirements, as well as creating processes for new and existing products. Responsibilities: - Technical and audit experience in cloud environments, web site security and operational processes - Practical knowledge of configuring operating systems, user access for applications and servers, anti-virus, network, or cloud infrastructure - Maintain strong working relationships with technology and business teams - Coordinate external auditor requests and facilitate meetings with IT and Security teams and control owners - Owning responsibilities around identified gaps, issues, or problems to see them through for remediation, alerting leadership, & proposing solutions - Working with colleagues across the organization, third-party service providers, and external users - Coordinate with application owners, business managers and IT administrators to complete user access reviews of identified applications and infrastructure, in accordance with policies - Conduct detailed control reviews for IT applications, infrastructure reviews, transition management and product releases - Communication across all levels of an audit to ensure consistency in reaching the audit's goals, and note potential opportunities, risks, or complications - Collaborating with leadership to revise and establish SOP guides to help ensure guidance is current - Creating and delivering training to educate teams on responsibilities and security matters - Collaborating with business units on implementation of controls/processes and providing guidance to support enhancements or meeting requirements - Performing ad hoc projects to support compliance and team initiatives