Sr. Security Analyst – Control Design & Implementation Assurance
Jostens Sr. Security Analyst – Control Design & Implementation Assurance
GENERAL DESCRIPTION / PURPOSE OF ROLE
KEY RESPONSIBILITIES / ESSENTIAL FUNCTIONS
GRC Security Assurance – 30%
- Perform independent, risk‑based assessments of IT systems, business applications, cloud services, OT environments, and physical security controls.
- Evaluate security control design, implementation, and operating effectiveness against internal standards and external frameworks (e.g., NIST, ISO 27001, PCI DSS, SOC 2).
- Conduct control walkthroughs, interviews, and evidence reviews to support internal and external audits.
- Provide consulting and advisory support for control assessments and compliance initiatives, including PCI DSS, SOX ITGC, and SOC 2 environments (e.g., readiness, control design, evidence strategies, and gap remediation planning).
- Identify control gaps, design weaknesses, and residual risks; clearly document findings and risk ratings.
- Support remediation validation and follow‑up testing to confirm risk mitigation.
Security Design & Implementation Assurance (GRC‑Led) – 30%
- Perform GRC‑led security design reviews and ensure security requirements are incorporated early in the project lifecycle (e.g., intake, requirements, and solution design).
- Partner with IT, Engineering, OT, Facilities, and business teams during project intake, solution design, implementation, and post‑go‑live phases to assess risk, confirm control requirements, and validate outcomes.
- Assess implementation readiness and control deployment by validating that configurations and procedures align to approved security requirements (e.g., access controls, encryption, logging/monitoring, segmentation) and performing post‑implementation verification where needed.
- Assess solution designs and implementations for foundational areas including:
- Identity & access
- Network access & segmentation
- Secure configuration and Hardening
- Data protection & encryption
- Logging, monitoring & incident readiness
- Physical Access
Risk Management & GRC Integration – 20%
- Perform and facilitate risk assessments for new systems, major enhancements, and material changes.
- Document risks, control gaps, and remediation plans within the enterprise GRC platform.
- Support formal risk treatment and risk acceptance processes with leadership.
- Ensure traceability between risks, controls, audit findings, and remediation actions.
Compliance & Regulatory Support – 10%
- Lead and support consulting, readiness, and assessment activities for SOC 2, PCI DSS, SOX, and other regulatory or customer‑driven environments (e.g., scoping, control mapping, evidence collection, narrative development, and remediation planning).
- Ensure audit‑ready documentation, evidence, and narratives are maintained.
- Serve as a key liaison between Information Security, IT, business stakeholders, and external assessors.
Advisory, Reporting & Continuous Improvement – 10%
- Translate technical security concepts into clear, business‑focused risk statements.
- Prepare audit reports, executive summaries, and risk assessments for leadership.
- Identify systemic control issues and recommend improvements to security standards, patterns, and governance processes.
- Contribute to continuous improvement of Jostens’ security architecture and assurance practices.
SUPERVISION OF OTHERS
- None – Individual Contributor
REQUIRED QUALIFICATIONS
- Minimum 5+ years of experience in Information Security, Security Assurance, GRC, Technology Risk, IT Audit or Risk Management roles.
- Bachelor’s degree in Information Systems, Information Security, Accounting, Business, or a related field (or equivalent experience).
- Experience performing IT control assessments and security reviews across applications, infrastructure, and cloud environments.
- Working knowledge of security frameworks and audit standards (e.g., ISO 27001, SOC 2, PCI DSS, SOX, NIST).
- Experience partnering with project and technical teams to assess security design and implementation.
- Strong ability to document findings, risks, and recommendations in an audit‑ready manner.
- Experience using GRC tools for risk, control, and issue management.
PREFERRED QUALIFICATIONS
- Prior experience in security assurance, technology risk, compliance assessments, or external audit/consulting.
- Prior experience as a business or systems analyst supporting existing systems or implementing new systems.
- Exposure to OT environments and/or physical security controls.
- Professional certifications such as CISA, CISSP, CRISC, or equivalent.
- Experience supporting and advising regulated or customer‑assured environments, including PCI, SOX, and SOC 2 programs.
KEY SKILLS & ATTRIBUTES
- Strong risk‑based mindset with the ability to balance security, business needs, and practicality.
- Ability to operate independently while influencing cross‑functional teams.
- Excellent written and verbal communication skills, including executive‑level reporting.
- Ability to assess complex technical environments without owning day‑to‑day operations.
- Highly organized, detail‑oriented, and audit‑focused.
TRAVEL
- Typical/expected overnight travel: < 5%