At a Glance
- Tasks: Lead security compliance efforts and assess risks in a dynamic tech environment.
- Company: Join Cubic, a leader in innovative transportation solutions.
- Benefits: Competitive salary, inclusive culture, and opportunities for professional growth.
- Other info: Collaborative team atmosphere with a focus on innovation and problem-solving.
- Why this job: Make a real impact on global transportation technology while enhancing your skills.
- Qualifications: Experience in IT security and compliance, with strong communication skills.
The predicted salary is between 55000 - 65000 £ per year.
When you join Cubic, you become part of a company that creates and delivers technology solutions in transportation to make people’s lives easier by simplifying their daily journeys, and defense capabilities to help promote mission success and safety for those who serve their nation. Cubic Transportation Systems (CTS) is a global leader in intelligent transportation solutions, specializing in technologies that make public transit more efficient, accessible, and user-friendly.
As a member of the Cubic information security team, you will provide security compliance support for production transaction processing environments. You will evaluate the posture of security controls and operating environment to ensure compliance with organisation security policies and controls. You will plan and prepare the scope of IT compliance evaluation programs across the organisation, isolate potential risks or liabilities, and develop mitigation plans. You will partner with external auditors to coordinate and facilitate PCI-DSS, ISO 27001, etc. compliance/audit efforts.
Essential Job Duties and Responsibilities:
- Perform as the recognized Subject Matter Expert on Security Risk Assessment methodology, policy, strategy and processes.
- Facilitate all security audit operations, including scheduling, vendor coordination, program, and stakeholder coordination.
- Responsible for coordination with the Internal/External Auditors and Information Technology teams to successfully complete periodic audits.
- Lead the design and control reviews and assessments to support continuous compliance with security policies and standards.
- Manage security review processes for all solutions to ensure their design and implementation meets compliance requirements – including PCI-DSS, ISO 27001, SOC 1 & SOC 2 and other regional requirements.
- Document and actively communicate any areas where the solutions and processes are not fully compliant.
- Identify and report significant information security risks associated with applications, development, networking, data centres, Cloud and physical IT infrastructure, vendors and other third parties.
- Identify stakeholders in remediation of compliance gaps and actively escalate issues to them in a constructive manner.
- Work with system operators and security subject matter experts to communicate system compliance gaps and develop acceptable remediation plans.
- Capture compliance gaps and remediation plans in the OneTrust GRC system.
- Liaise with Cubic customers and Security Teams to build positive relationships and outcomes.
- Support efforts to educate Security Management and Security Team Members in compliant IT processes and controls.
- Prepare and maintain process and control documentation.
- Aid in the development of solutions to problems identified during audits and translate these solutions into practical recommendations.
- Follow up on recommendations and appraise corrective actions taken to improve deficient conditions.
- Review vendor contracts and SOC reports to evaluate the impact on the company’s controls.
General Duties and Responsibilities:
- Reliably demonstrate accountability for work assignments and proactive communications about issues and status.
- A strong history of proactively identifying effective solutions for challenges.
- Able to operate in a professional manner, even in tense or continuous settings.
- Comply with Cubic’s Quality Management System.
- Comply with Cubic's quality, health, safety, and security policies.
- Support the company's strategic objectives and collaborate across departments.
Skills/Experience/Knowledge:
- Essential: Strong written and oral communication skills in English, with capability to use Microsoft Office solutions.
- Ability to effectively and openly collaborate with team members, clients, IT management, staff, and business units in a cross-functional and matrixed IT organisation.
- Familiarity with PCI DSS 4, ISO 27001-2022, and/or SOC I/II requirements and audits.
- Expert level experience collaborating with stakeholders and solution providers in a cross-functional and matrixed IT organisation.
- Exhibits advanced wide-ranging experience, using in-depth professional knowledge, acumen, concepts and company objectives to develop, resolve complex models and procedures.
- Understands and works on complex issues where analysis of situations or data requires an in-depth evaluation of variable factors.
Qualifications:
- Essential: Experience in services or IT systems in a mission-critical setting.
- University degree in Computer Science, Engineering, or other technical fields, or Business Administration with relevant IT work experience.
- Experience working in IT security and/or Payment Card processing systems.
We are committed to creating an inclusive workplace and welcome applications from people of all backgrounds. We do not discriminate based on any protected characteristic under applicable law.
Senior Risk Management Analyst employer: Cubic
Cubic is an exceptional employer that fosters a culture of innovation and collaboration, making it a prime choice for professionals in the transportation technology sector. With a commitment to employee growth, Cubic offers extensive training opportunities and encourages team members to engage in meaningful projects that impact global transportation solutions. Located conveniently for commuting, the company promotes a supportive work environment where diverse perspectives are valued, ensuring that every employee can contribute to the mission of simplifying journeys for people worldwide.
StudySmarter Expert Advice🤫
We think this is how you could land Senior Risk Management Analyst
✨Join Compliance Communities
Get involved in compliance and risk communities — both online and offline. Look for forums, LinkedIn groups, or even local meetups where compliance pros hang out. You never know who might drop a job opportunity your way!
✨Attend Industry Conferences
Keep an eye out for compliance and risk management conferences and workshops in your area. These events are a goldmine for networking, and they often have job boards or recruiters on-site looking for new talent. Plus, it’s a chance to learn what's trending in the field.
✨Leverage Your University Career Services
If you’ve recently graduated or are still studying, head over to your university's career services. Many companies, including those in compliance, actively recruit fresh talent through these services, so make sure you tap into that resource.
✨Showcase Your Knowledge Online
Start writing articles or blog posts about compliance topics that interest you. Share them on platforms like LinkedIn to demonstrate your knowledge and passion. This not only builds your presence in the field but can also catch the attention of companies like Cubic looking for candidates who are engaged and informed.
We think you need these skills to ace Senior Risk Management Analyst
Some tips for your application 🫡
Show Your Understanding of Compliance:In the compliance-risk field, it's super important to showcase your understanding of regulations and risk management frameworks. Highlight any relevant coursework, certifications (like ICA or AML), or even projects that demonstrate your knowledge and commitment to this area. We want to see how you can navigate this complex landscape!
Quantify Your Achievements:When detailing your experience, try to quantify your achievements. For example, if you've previously worked on a project that improved compliance metrics or reduced risk exposure, give us the numbers! This data-driven approach really stands out to hiring managers in compliance-risk roles.
Tailor Your CV to Reflect Relevant Skills:Make sure your CV highlights skills that are particularly relevant to compliance, like attention to detail, analytical thinking, and report writing. Ensure these are easy to spot – consider using bullet points to break down your responsibilities and achievements for maximum impact!
Craft a Motivating Cover Letter:In your cover letter, let us know why you’re excited about the compliance-risk role at Cubic. Share what motivates you about compliance, and how you believe you can contribute to our mission. This is your chance to showcase not only your skills but also your passion for this important field!
How to prepare for a job interview at Cubic
✨Master the Regulations
Brush up on key compliance regulations relevant to the industry you're applying to. Familiarising yourself with specific laws and frameworks used in your field will give you an edge during technical questions. Show that you’re not just aware of them but can also apply them—think real-life scenarios!
✨Show Your Analytical Skills
Compliance roles really focus on analytical skills, so be prepared for case studies or situational questions during the interview. We've got to demonstrate how we approach risk assessments or compliance audits, possibly drawing on examples from past experiences or university projects. Bring some thoughtful case scenarios to discuss!
✨Know Your Tools
Get comfortable with commonly used compliance software and tools. Familiarity with platforms like RSA or MetricStream can really impress during your interview, as it shows you're ready to hit the ground running. If you’ve had any experience with them, make sure to highlight that!
✨Align with Company Culture
Since it's a full-time position, show your long-term commitment and interest in the company’s mission and values. Dive into how your ethics and professional philosophy align with Cubic’s stance on compliance. A shared vision can really resonate with interviewers looking for fit as much as skill!