Senior IT Compliance Analyst
Job Summary: |
The Senior IT Compliance Analyst will be part of Oklahoma State University's IT Security and Compliance team of experienced professionals working passionately to maintain confidentiality, integrity and availability of the University's information and technology resources. The IT Compliance function within the OSU IT Security department is responsible for providing guidance, support and analysis to IT management regarding policy and legal compliance (PCI, HIPAA, FERPA, GLBA, GDPR, etc.). The team provides written reporting, broad IT project participation, and recommendations for practical application of control concepts and principles where needed. The Senior IT Compliance Analyst:
|
Special Instructions to Applicants |
A resume is required to complete the application process. Educational transcripts may be attached to the application, or mailed to: Oklahoma State University, Attn: Senior IT Compliance Analyst, 101 IT Building, Stillwater, OK 74078. For full consideration, submit application by August 19th, 2018. |
Education & Experience |
|
Position Qualifications: |
Required: Bachelor's degree Combined work experience of at least three (3) years in both: Administering and/or managing Windows and/or Linux servers, Active Directory structures, Oracle or SQL databases, and/or VMware environments. and In IT risk and compliance, IT governance, IT auditing, another IT security related field or information system security focused activities. Must be willing to complete the requirements for the Certified Information Systems Auditor (CISA) or Certified Information Systems Security Professional (CISSP). Knowledge of regulations affecting Higher Education FERPA, HIPAA, GBLA and PCI-DSS, for compliance. Must have excellent analytical and verbal and written communication skills to understand customer objectives, evaluate risks and controls, and accurately document and support work performed and assist with management decision making. Must be able to work in a fast-paced environment and manage multiple projects, at times with conflicting priorities, concurrently. Must be a self-starter who is results-oriented and can effectively organize, plan, control, and prioritize work/projects according to time and resource constraints. Must possess competence to understand and manage work/project obstacles and complexities, including work/project scope, key players, urgency, inherent risks, and business benefits. Knowledge of enterprise security concepts such as patch management, defense in-depth/layered security and an understanding of network and systems administration (TCP/IP, Switch/Hub functions; Network Topologies), including an in-depth knowledge of Windows Server family including MS Exchange 2003/2007/2010/2013 and desktop operating systems (OS) such as Windows 7/8/10. Ability to lift 25 lbs. Preferred: Master's degree in Computer Science, MSIS, MSTM, English, or Technical Writing/Editing Three to five (3-5) years combined work experience: Working in complex information technology environments consisting of multiple technology platforms. and In IT risk and compliance, IT governance, IT auditing or other information security experience including conducting risk assessments/audits/reviews of information systems with the goal of assessing and/or mitigating information security threats/risks within a large university environment. Possess one or more of the following: Security Essentials Certification (GSEC); Certified Information Systems Auditor (CISA); Certified Fraud Examiner (CFE); Microsoft Certified IT Professional (MCITP); Microsoft Certified Technology Specialist (MCTS) Knowledge and understanding of the role of information security in system design/architecture and implementation, including network security, information security audits, security awareness training, and information security risk management. Possess a strong knowledge and understanding of information security compliance and auditing techniques with experience conducting risk assessments and using risk assessment tools. |