7 days ago

Cybersecurity GRC - Compliance Analyst

Trimble Inc.

Hybrid
Full Time
$102,000
Hybrid

Job Overview

Job TitleCybersecurity GRC - Compliance Analyst
Job TypeFull Time
CategoryCommerce
Experience5 Years
DegreeMaster
Offered Salary$102,000
LocationHybrid

Who's the hiring manager?

Sign up to PitchMeAI to discover the hiring manager's details for this job. We will also write them an intro email for you.

Uncover Hiring Manager

Job Description

About Trimble Inc.

Trimble is transforming the way the world works by delivering products and services that connect the physical and digital worlds. Core technologies in positioning, modeling, connectivity, and data analytics enable customers to improve productivity, quality, safety, and sustainability. From purpose-built products to enterprise lifecycle solutions, Trimble software, hardware, and services are transforming a broad range of industries such as agriculture, construction, geospatial, and transportation and logistics.

To improve integrity between physical and digital worlds, Governance, Risk, and Compliance (GRC) facilitates the integrated collection of capabilities necessary to support connected performance. GRC doesn't burden the business; it supports and improves it by adding value through establishing efficiencies, centralizing policy, and creating metrics to reduce risk to maintain Trimble brand equity. GRC resides within the corporate Trimble Cybersecurity team.

To be considered for this position, you must be familiar with security frameworks and security control auditing, specifically SOC 1 & 2 and NIST 800-171, inclusive of ISO 27001, ISO 27701, ISO 42001. Experience with risk assessments and scoring, conducting gap analysis, internal audits, and external audit coordination is also essential. Flexibility to work 6 months project-based and 6 months audit is required.

This Opportunity

As a Cybersecurity GRC - Compliance Analyst, you are a self-motivated, mildly technical but versatile individual contributor looking to join a diverse and collaborative international cybersecurity team for a large dynamic publicly traded company. You will be responsible for helping to ensure Trimble’s product portfolio maintains compliance with an array of frameworks (SOC 1 & 2, NIST 800-171, ISO 27001, ISO 27701 & ISO 42001). You will be a crucial member of our organization, working to achieve our customers' expectations in the area of Compliance & Audit.

The role requires an individual who works well independently and as part of a global team by adding value through process optimization and managing a diverse portfolio of Trimble products seeking compliance with existing and new standards & frameworks.

Key Responsibilities & Outcomes

Operational
  • Perform SOC 1 & 2, NIST 800-171, ISO 27001, ISO 27701, and ISO 42001 gap analysis and recommend process, procedural, documentation, and tooling recommendations to remediate.
  • Improve Compliance and certification scope efficiency via review and enhancements of the Trimble Common Control Framework.
  • Perform ISO 27001 & ISO27701 Internal Audits.
  • Perform SOC 1 & 2, NIST 800-171 Internal & External Audits.
  • Contribute to annual policy revisions and maintenance of the Integrated Management System (IMS).
  • Constantly coordinate with key business stakeholders and the external auditor.
  • Present metrics derived from the IMS, audit results, trends in risk, and corrective action plans to senior leadership.
  • Contribute to the creation of processes and procedures that increase efficiency of the overall compliance program across all standards and frameworks.
  • Collaborate with Cybersecurity team members and Trimble businesses across various geographies.
  • Contribute to risk management processes to ensure business risk posture is properly calculated and proactively managed.
  • Produce and analyze information that will accurately demonstrate the risk posture of each business and drive actions to reduce and manage technical risks.
  • Be able to understand and communicate technical risks to a broad set of stakeholders, adjusting delivery to the audience.
Communication

The Trimble Cybersecurity team serves the entire organization. Trimble is divided into several Business focused Sectors and Divisions. This role will communicate with:

  • Cybersecurity, IT, and GRC teams
  • Trimble leadership
  • Divisional & Sector Cybersecurity representatives
  • Software development staff
  • Other global functions (Human Resources, Legal as required)

No communication with Trimble customers is required.

Skills / Competencies

  • Working knowledge of SOC 1 & 2, NIST 800-171, ISO 27001, ISO 27701 & ISO 42001.
  • Designing audit controls spanning SOC 1 & 2, NIST 800-171, ISO 27001, ISO 27701 & ISO 42001.
  • Ability to write policy and interpret complex business changes as they arise.
  • Comprehensive understanding of risk management standards and guidelines.
  • General IT knowledge (networking, cloud computing, software development).
  • General knowledge in Data Privacy (GDPR, CCPA and other regulations).
  • A passion for user-centric information that is clear and actionable, attention to detail focused on delivering accurate and creative metrics.
  • Ability to make effective, timely decisions with clear reasoning.
  • Ability to quickly establish a broad understanding of an issue with limited available information and outline the steps required to bring it to a successful conclusion.
  • Excellent organizational and presentation skills.
  • Effective communication skills (verbal and written) and time management skills.
  • Flexible approach to working in a changing environment and can work well under pressure with dynamically changing priorities.
  • Ability to work as part of a collaborative global team, prepared to remain resilient to complete tasks to conclusion.

Qualifications / Experience

  • Preferably a relevant degree in Data Science, Computer Science or Engineering (Software or Electrical).
  • Current general security certifications (e.g., SEC+, GSEC) encouraged but not required.
  • ISO 27001 Certified Internal / Lead Auditor and/or equivalent experience.
  • 2 years experience working with SOC 1 & 2, NIST 800-171, ISO 27001, ISO 27701.
  • Proficiency in English (written and oral).
  • 2 years experience in a risk management role, information security role, or systems engineer/administrator role in a large, international software company.
  • Hands-on experience with business and GRC tools such as Jira Service Desk.
  • Demonstrated experience in collecting information from disparate data sources and formulating into reports that can be presented to various audiences.
  • Intermediate level experience with Windows and Linux/Unix operating systems.
  • Intermediate level cloud knowledge within AWS, Azure, and GCP.
  • Intermediate level scripting knowledge and experience of Splunk and creating queries.
  • Experience of using AI to reduce manual process and procedure.
  • Excellent analytical, problem-solving, and decision-making skills.

Key skills/competency

  • Security Frameworks
  • Compliance Auditing
  • Risk Management
  • Gap Analysis
  • Internal Audit
  • External Audit Coordination
  • Policy Development
  • Data Privacy Regulations
  • Cloud Security (AWS, Azure, GCP)
  • GRC Tools (Jira Service Desk)

Tags:

Cybersecurity Compliance Analyst
GRC
compliance
audit
risk management
gap analysis
policy
internal audit
external audit
ISO 27001
NIST 800-171
SOC 1
SOC 2
AWS
Azure
GCP
Jira Service Desk
Splunk
Windows
Linux/Unix
AI

Share Job:

How to Get Hired at Trimble Inc.

  • Research Trimble Inc.'s culture: Study their mission, values (Belong, Innovate, Grow), recent news, and employee testimonials on LinkedIn and Glassdoor.
  • Tailor your resume: Highlight GRC, compliance, and audit experience, specifically with SOC 1 & 2, NIST 800-171, ISO 27001, ISO 27701, and ISO 42001.
  • Showcase relevant experience: Emphasize your ability to perform gap analysis, internal/external audits, and contribute to risk management processes.
  • Prepare for technical questions: Be ready to discuss security frameworks, GRC tools like Jira Service Desk, and general IT/cloud knowledge (AWS, Azure, GCP).
  • Demonstrate collaborative skills: Prepare examples of working effectively in global teams and communicating complex technical risks to diverse stakeholders.

Frequently Asked Questions

Find answers to common questions about this job opportunity

Explore similar opportunities that match your background