Security GRC Analyst

Turnitin Logo

Turnitin

๐Ÿ“Remote - United Kingdom

Summary

Join Turnitin's Security & Compliance team as an experienced Security GRC Analyst with Cloud/AWS skills. Ensure information and cloud systems comply with regulatory frameworks, industry standards, and internal policies. Collaborate with various departments, monitor compliance, conduct assessments, and mitigate risks. Demonstrate strong analytical skills, attention to detail, effective communication, and a commitment to continuous learning. This role involves hands-on work, critical thinking, and finding innovative compliance solutions. The position reports to the GRC Information Security Manager and offers a remote-centric work culture with a comprehensive well-being package. Turnitin is a global organization with team members in over 35 countries.

Requirements

  • Cloud Infrastructure with general knowledge of AWS services such as CloudFormation, Serverless, AWS Config, CloudTrail, IAM, and JSON
  • Basic scripting
  • Bachelorโ€™s degree in Computer Science, Information Security, or a related field (or equivalent experience)
  • 3+ years of experience in a role related to Information Security
  • 1+ years AWS Cloud Services and basic scripting
  • Professional certification such as CCSK, AWS Cloud Practitioner, or other related industry certification
  • Familiarity with cybersecurity frameworks and regulatory standards such as NIST, SOC 2, TX-RAMP, and PCI DSS
  • Familiarity of risk management and security best practices
  • Experience with assessing security controls, risk mitigation strategies, and audit procedures
  • Understanding of concepts related to AWS Cloud Infrastructure and security
  • Experience conducting security impact analysis for system changes
  • Experience conducting periodic internal security reviews or risk assessments to ensure that compliance procedures and technical configurations are followed
  • Experience conducting third-party risk assessments
  • Contract review experience for security requirements
  • Highly organized and proactive individual capable of managing multiple responsibilities and delivering results

Responsibilities

  • Maintain compliance tracking capabilities to help ensure adherence with Turnitinโ€™s security program and industry standards such as NIST CSF, NIST 800-53, SOC 2, TX-RAMP and PCI DSS
  • Conduct risk and compliance assessments, audits, and risk evaluations to identify potential risk and compliance gaps
  • Lead preparation and audit activities required to maintain our SOC 2 Type 2
  • Collaborate with internal teams and external auditors for audit and compliance reviews
  • Collaborate with sales and customer support teams to respond to security questionnaires and security posture questions from customers
  • Support TPRM Program and conduct third-party risk assessments
  • Complete user access reviews
  • Administration of GRC platform
  • Participate in the development and documentation of security policy, standards and processes to align with company information security strategy
  • Provide security awareness and phishing training for employees and promote a culture of security and compliance
  • Coordinate phish testing
  • Collaborate with DevOps, IT, Legal, Engineering, People Team, and other departments to ensure security control and policy requirements are integrated into systems and business processes
  • Automate manual compliance tasks and improve team processes
  • Leverage AWS and Wiz for continuous monitoring
  • Measure effectiveness vs just implementation

Preferred Qualifications

  • Experience running SOC 2 audits or NIST based authorizations
  • Experience using Jira and Confluence for project and task management
  • Hands-on experience with Wiz, KnowBe4, and Hyperproof
  • Experience conducting third-party risk assessments
  • Demonstrated knowledge of security assessment of cloud technology and services (AWS)
  • Entry level cybersecurity certification such as Security+, GIAC GSEC, or ISC2 Certified in Cybersecurity

Benefits

  • Health Care Coverage*
  • Education Reimbursement*
  • Competitive Paid Time Off
  • 4 Self-Care Days per year
  • National Holidays*
  • 2 Founder Days + Juneteenth Observed
  • Paid Volunteer Time*
  • Charitable contribution match*
  • Monthly Wellness or Home Office Reimbursement/*
  • Access to Modern Health (mental health platform)
  • Parental Leave*
  • Retirement Plan with match/contribution*
  • Remote First Culture

Share this job:

Disclaimer: Please check that the job is real before you apply. Applying might take you to another website that we don't own. Please be aware that any actions taken during the application process are solely your responsibility, and we bear no responsibility for any outcomes.

Similar Remote Jobs