Governance, Risk and Compliance Analyst

 Posted an hour ago
     
2-5 years experience
Apply Now

Please mention DailyRemote when applying

AI Summary

The analyst will collaborate with cross-functional teams to enhance security controls, mitigate risks, and ensure compliance with internal and external requirements. Key duties include executing risk assessments, managing compliance certifications, and overseeing third-party vendor security reviews.

Aderant is a global industry leading software company providing comprehensive business management solutions for law firms and other professional services organizations with a mission to help them run a better business. We are motivated by a collective desire to drive the legal industry to the forefront of innovation. With over 2,500 clients around the world, including 95 of the top AmLaw 100 firms, we are changing the outside perception of the legal sphere; where there was once resistance to modernization, we are creating a culture that embraces new ideas and technology.

At Aderant, the “A” is more than just a letter. It is a representation of how we fulfill our foundational purpose, serving our clients. It embodies our core values and reminds us that to achieve success, every day must start with the “A”. We bring the “A” to life by fostering a culture of innovation, collaboration, and personal growth. We encourage our diverse teams to bring their whole selves to work – ideas, experience, and passion – to drive our mission forward.

Our people are our strength.

Role Description:

Under the guidance and oversight of the Manager, Governance Risk & Compliance the Governance, Risk and Compliance Analyst will work with cross functional teams such as  IT, Cloud Operations, Business Operations, Product Management, Sales, and Software Development to enhance security controls and mitigate risks. You will be responsible for supporting and executing governance, risk, and compliance activities along with participating in projects designed to reduce overall risk to the organization. The ideal candidate is passionate about governance and compliance as it relates to information security technology and the opportunity to play a foundational role in a highly respected team, is self-motivated, and has excellent project management and communication skills.

Responsibilities:

  • Ensure compliance assurance program control requirements are documented, and processes exist to validate the effectiveness of such controls.
  • Collaborate with cross-functional teams to gather and validate compliance artifacts to fulfill internal and external requirements and obligations.
  • Participate in annual and ad-hoc risk assessments with internal stakeholders.
  • Participate in efforts to achieve compliance attestations/certifications such as ISO-27001, SOC 2 and PCI-DSS.
  • Assist in identifying control deficiencies and track remediation efforts.
  • Ensure that third party vendors meet Aderant security and compliance requirements through the collection and review of a combination of assessment questionnaires, artifacts and attestation documents.
  • Support other governance activities such as: business continuity testing, data mapping and disaster recovery exercises.
  • Participate in the coordination and execution of the security awareness training program, including (but not limited to) the creation of security advisories, and the facilitation of training activities and simulated phishing campaigns.
  • Assist in reviewing and updating security and compliance policies and procedures, to ensure they accurately reflect business requirements and align to industry leading security practices.
  • Assists with the formulation of information security metrics and dashboards that demonstrate adherence to defined KPIs.
  • Respond to customer questionnaires pertaining to Aderant security, compliance and related posture; collaborate with other teams as-needed.

Qualifications:

  • 2 to 5 years of relevant experience in an Information Security or GRC role.
  • The ability to identify opportunities to reduce risk, detect and remediate vulnerabilities, and ensure compliance and audit readiness.
  • Experience/understanding with regulatory frameworks and standards, including but not limited to: ISO 27001, ISO 27701, ISO 42001, AIUC, PCI DSS, NIST CSF, CIS Top 20, GDPR and/or CCPA.
  • Basic technical understanding of cloud service platforms (AWS, Azure, etc.).
  • Proficient in Microsoft Suite skills specifically Excel, Power Point, and Teams.
  • Basic understanding and experience using AI tools such as ChatGPT, Claude, MS Copilot, etc.
  • Experience leveraging GRC automation platforms.
  • Strong analytical skills and the ability to understand and document complex business process data flows.
  • Professionalism, attention to detail, strong organizational skills, team-focus, dedication, resourcefulness, and an eagerness to learn.
  • Ability to manage multiple tasks and priorities while demonstrating time management skills and communication skills.
  • Strong communication skills, with the ability to translate basic security concepts for both technical and non-technical stakeholders.

Preferred Qualifications:

  • Supporting certifications (e.g., CC, CGRC, CISA, CCOA, CGEIT, Associate CISSP, etc.)
  • Experience performing DPIAs, Data Mapping, DSRRs and related privacy-focused activities.
  • Supporting an ISO 27701 compliant environment.
  • Experience with curating content and leveraging security awareness training platforms.
  • Experience with managing work through ticketing systems and queues.
  • Experience working with legal industry, SaaS, or enterprise clients on security compliance.

Similar Jobs

See all Remote Legal jobs →

Personalize your Remote Job Search in 3 Easy Steps!

Discover remote opportunities in Compliance Analyst

Answer easy questions

Answer easy questions

200,000+ jobs across 15+ categories

Get your best job matches

Get your best job matches

Only hand-screened, legit jobs

Find a remote job faster

Find a remote job faster

No ads, scams, or junk

I was the first applicant for a remote marketing position that got listed on the company website the same day I applied. Had an interview within 48 hours!

Sarah J. — Sarah J. · Marketing Manager ★★★★★ Verified