Summary
Join Docker, a remote-first company experiencing exponential growth, as a Senior GRC Analyst. Reporting to the Compliance Manager, you will play a key role in executing our SOC 2 readiness assessment and external audit. This cross-functional role involves collaborating with IT, Security, and Compliance leadership to strategize assessments, identify risks, and establish controls. You will also conduct third-party supplier security assessments and manage customer due diligence questionnaires. This position requires a minimum of 2 years of IT audit experience and 3 years in compliance. Docker offers a dynamic work environment and various benefits.
Requirements
- Minimum 2 years of IT external or internal audit experience
- Minimum 3 years of work experience in compliance or related field
- Bachelorβs degree in business, information systems, computer science, or relevant educational or professional experience
- Experience performing vendor due diligence
- Experience with information security principles/practices
- Experience with privacy principles/practices
- Experience with software development practices
- Passionate about security, privacy, and compliance
- Self-motivated, quick learner, fast researcher
- Have experience with and are comfortable with a remote working environment
Responsibilities
- Plan internal audits from start to finish, perform gap assessments and advice on gap closure, collect and review evidence, present evidence to auditors to make the case for compliance, and assist with interactions with external auditors
- Establish strong partnerships with front line business partners and other stakeholders to ensure security program, policy and procedures are effective
- Support the Compliance team in ensuring compliance with industry standards and privacy regulations
- Serve as an advisor to engineering, IT, and business process teams to assist them in supporting compliance efforts
- Draft policies and best practices that will be consumed by the entire organization
- Maintain knowledge of certifications and controls such as SOC 2, ISO 27001 / ISO 27018, NIST 900-53, FedRAMP, IT SOX
- Evaluate vendors against compliance and security standards
- Assist in building out a risk and compliance control framework based on industry leading standards
- Perform risk analysis for systems, processes, third-party tools/applications and configurations
- Stay up to date on the latest cyber security best practices
- Advise on control design and build key partnership with control owners
- Document walkthroughs for all controls deemed ready in the current testing sprint
- Perform testing of all controls deemed ready in the current testing sprint
- Manage updates to the SOC 2 Jira Board to ensure accurate status is displayed
- Become familiar with Drata
- Coordinate feedback and address comments for draft policies
- Complete vendor due diligence for new vendors onboarded
- Provide feedback for the compliance roadmap
- Implement additional automated testing within Drata
- Create documented processes and procedures for Compliance team
- Help with implementation of vendor solution
- Complete walkthroughs for all SOC 2 controls
- Complete testing for all SOC 2 controls
- Gather evidence for SOC 2 Type 1 engagement
- Set up audit software to prepare for future audits
- Perform gap analysis of NIST framework to prepare for DockerFed
- Partner with Finance to determine scope for SOX audit
Preferred Qualifications
- Public Accounting/Big 4 Consulting Experience
- Technical information security experience
- Experience with automating security monitoring functions using scripting
- Industry relevant certifications such as CISSP, CISA, etc
Benefits
- Freedom & flexibility; fit your work around your life
- Home office setup; we want you comfortable while you work
- 16 weeks of paid Parental leave
- Technology stipend equivalent to $100 net/month
- PTO plan that encourages you to take time to do the things you enjoy
- Quarterly, company-wide hackathons
- Training stipend for conferences, courses and classes
- Equity; we are a growing start-up and want all employees to have a share in the success of the company
- Docker Swag
- Medical benefits, retirement and holidays vary by country
Disclaimer: Please check that the job is real before you apply. Applying might take you to another website that we don't own. Please be aware that any actions taken during the application process are solely your responsibility, and we bear no responsibility for any outcomes.