Senior IT Risk and Compliance Analyst

1 Month ago • 4 Years +

About the job

SummaryBy Outscal

Morningstar seeks a Senior IT Risk and Compliance Analyst to support compliance obligations (SOX, SOC2, PCI-DSS, SEC). You'll gather evidence for audits, monitor compliance, identify security findings, and liaise with third-party auditors. 4+ years' experience in risk & compliance or IT auditing with proven expertise in SOX, SOC2, PCI-DSS, GDPR, and IT audits is essential.

Role:

The Senior IT Risk and Compliance Analyst will assist in supporting Morningstar’s compliance related responsibilities. This individual will help current and future compliance obligations are met, assist in identifying and following up on information security findings, gather evidence required for internal and external audits, and provide level 2 support for analysts responding customer RFPs and due diligence questionnaires.

Location: Bucharest, Romania

Responsibilities:

  • Assist in supporting Morningstar’s current and future compliance related responsibilities (SOX, SOC2, PCI-DSS, SEC, etc.) 
  • Gather evidence required for internal and external audits 
  • Monitor and enforce compliance to information security and compliance policies and standards 
  • Assist with documenting and regularly reviewing security policies, processes and procedure 
  • Execute audit tests; identify issues and areas for improvement in security policy compliance 
  • Identify and follow up on information security findings to ensure they are properly remediated 
  • Liaise with third party audit personnel as required 

 

Requirements 

  • A bachelor’s degree and 4+ years’ experience in a risk and compliance or I.T. auditor role 
  • Familiarity with common compliance standards (SOX, SOC2, PCI-DSS, GDPR etc.) and experience working directly with internal or external auditors for at least one of the listed standards 
  • 1+ years experience in customer facing role directly responding to customer information security and compliance concerns 
  • Familiarity with IT audits and risk assessments 
  • Familiarity with security frameworks (ISO 27001, NIST, etc.) and general security concepts 
  • Strong organizational skills and the ability to multitask and switch priorities with short notice 
  • Strong business analysis, research and analytical skills 
  • Excellent communication skills 
  • Availability to work off business hours as required 

 

315_Sustainalytics SRL Legal Entity

Morningstar’s hybrid work environment gives you the opportunity to work remotely and collaborate in-person each week. We’ve found that we’re at our best when we’re purposely together on a regular basis, at least three days each week. A range of other benefits are also available to enhance flexibility as needs change. No matter where you are, you’ll have tools and resources to engage meaningfully with your global colleagues.

Maharashtra, India (Hybrid)

Bucharest, Romania (Hybrid)

Maharashtra, India (Hybrid)

Illinois, United States (Hybrid)

Illinois, United States (Hybrid)

Ontario, Canada (Hybrid)

North Holland, Netherlands (Hybrid)

Bucharest, Romania (Hybrid)

Illinois, United States (Hybrid)

View All Jobs

Similar Jobs

MatchGroup - Security Compliance Analyst

Seoul, South Korea (Hybrid)

OKX - Senior Compliance Analyst, Sanctions Advisory

California, United States (On-Site)

OKX - Senior Compliance Analyst, KYC

California, United States (On-Site)

OKX - Compliance Analyst, Market Surveillance

New York, United States (On-Site)

Head Digital Works - Senior Risk and Compliance Analyst

Telangana, India (On-Site)

scaleai - Security Compliance Analyst

California, United States (On-Site)

WebMD - Compliance Analyst

New Jersey, United States (On-Site)

OKX - Senior Compliance Analyst, Token Listing

County Dublin, Ireland (On-Site)

Similar Skill Jobs

Aristocrat Gaming - Payout & Risk Operator

New Hampshire, United States (Hybrid)

DraftKings - Product Manager I (Golf)

England, United Kingdom (On-Site)

Activision - FP&A Manager, World of Warcraft and Diablo

England, United Kingdom (Hybrid)

wmeimg - Guest Services Representative-Processing

North Carolina, United States (On-Site)

Tencent - 3A射击端游资深关卡策划

Shanghai, China (On-Site)

Outscal - Product Operations

Delhi, India (On-Site)

Tencent - Game Client Development intern 103344

New South Wales, Australia (On-Site)

Tencent - Senior Product Solution Architect - Tencent Cloud EdgeOne

Federal Territory Of Kuala Lumpur, Malaysia (On-Site)

Jobs in Bucharest, Bucharest, Romania

PwC - Business Process Specialist (with French)

Bucharest, Romania (On-Site)

PwC - Business Support Specialist with German

Bucharest, Romania (On-Site)

Amber - Senior Financial Analyst

Bucharest, Romania (Hybrid)

EveryMatrix - Senior Accountant

Bucharest, Romania (Hybrid)

Veeam Software - Director, Web Development

Bucharest, Romania (On-Site)

Veeam Software - Inside Sales Representative, UK & Ireland

Bucharest, Romania (On-Site)

Veeam Software - Inside Sales Representative, Nordics

Bucharest, Romania (On-Site)

Software Engineering Jobs

Aristocrat Gaming - Payout & Risk Operator

New Hampshire, United States (Hybrid)

Scientific Games  - Package Assembly Tech II

Georgia, United States (On-Site)

Activision - Lead Network Programmer

Masovian Voivodeship, Poland (On-Site)

Warner Bros. Games - Staff Data Engineer- C360, Hyderabad

Telangana, India (Hybrid)

Warner Bros. Games - Data Engineer II - C360, Hyderabad

Telangana, India (Hybrid)

Aristocrat Gaming - QA Manual (Pasino)

Masovian Voivodeship, Poland (Hybrid)

Aristocrat Gaming - QA Manual (Pasino)

Lesser Poland Voivodeship, Poland (Hybrid)

DraftKings - Software Engineering Manager

Massachusetts, United States (On-Site)

Level Up Your Career in Game Development!

Transform Your Passion into Profession with Our Comprehensive Courses for Aspiring Game Developers.

Job Common Plug