06 Aug
|
KAYAK
|
Cambridge
About the role
Kayak is on the lookout for a motivated early-career individual to join its Cyber Governance, Risk, and Compliance (GRC) team. This position is pivotal in assisting with risk assessments, compliance initiatives, policy management, and business continuity strategies. The successful candidate will play a key role in enhancing the GRC program by leveraging automation and data-driven techniques to streamline processes.
Key facts
- Location: Cambridge or Concord, MA (hybrid, requiring in-office presence three days a week)
- Engagement: Full-time
- Compensation: $85,000 - $95,000 annually, with eligibility for bonuses
- Team: Cyber Governance, Risk, and Compliance
What you'll do
- Participate in conducting comprehensive risk assessments to identify and monitor risks across various technology and business operations.
- Aid in the upkeep and revision of policies, standards, and procedures to ensure alignment with established security frameworks.
- Assist in the organization of both internal and external audits by gathering necessary evidence and tracking remediation efforts.
- Contribute to the testing and monitoring of controls to verify their effectiveness and compliance.
- Oversee the management of the risk register and support the tracking of risk treatment initiatives.
- Facilitate customer security evaluations, including the completion of questionnaires and due diligence documentation.
- Support the development, maintenance, and testing of Business Continuity and Disaster Recovery plans to ensure organizational resilience.
- Collaborate with engineering, security,
and business teams to collect relevant information and effectively communicate compliance requirements.
- Engage in efforts to automate GRC processes, focusing on minimizing manual evidence collection tasks.
- Stay updated on changes in regulations and evolving governance practices to ensure the GRC program remains current and effective.
Requirements
- A bachelor's degree in a relevant discipline such as cybersecurity, information systems, computer science, risk management, or business, or equivalent practical experience.
- A foundational understanding of GRC principles, including risk management, compliance frameworks, and audit methodologies.
- Basic knowledge of Business Continuity and Disaster Recovery concepts, including Business Impact Analyses (BIAs) and recovery objectives.
- Familiarity with at least one recognized security or compliance framework, such as NIST Cybersecurity Framework (CSF), SOC 2, or PCI DSS.
- Experience in a GRC, cybersecurity, internal audit, IT risk, or business continuity setting, whether through paid work, academic projects, or volunteer roles.
- Excellent written and verbal communication skills, capable of conveying risk and compliance information to a variety of audiences.
- Strong organizational abilities and the capacity to juggle multiple priorities effectively.
- A curious and analytical mindset, with a genuine enthusiasm for learning and skilled growth.
Nice to have
- Exposure to or a keen interest in GRC process automation, APIs, or engineering methods related to compliance (prior coding experience is not necessary).
- Previous experience with compliance or business continuity platforms such as Drata or RiskConnect would be advantageous.
Skills & tools
- Familiarity with NIST Cybersecurity Framework (CSF)
- Knowledge of SOC 2 compliance
- Understanding of PCI DSS standards
- Awareness of GDPR regulations
- Experience with Drata (preferred but not essential)
- Familiarity with RiskConnect (preferred but not essential)
Practical notes
- This position mandates working from the Cambridge or Concord, MA office three days a week.
- The benefits package includes comprehensive health plans, flexible spending accounts, retirement savings options, life insurance, and parental leave.
- Paid time off encompasses vacation days, sick leave, medical leave, bereavement leave, floating holidays, and designated paid holidays.
- Additional perks consist of up to 20 days per year for remote work, company-sponsored therapy sessions and HeadSpace subscriptions, a company-wide week off each year, no meeting Fridays, paid parental leave, professional development funds, leadership training, access to e-learning resources, travel discounts, employee resource groups, complimentary lunches twice a week, and quarterly social gatherings.
#J-18808-Ljbffr
📌 Associate GRC Analyst (Cambridge)
🏢 KAYAK
📍 Cambridge