Senior IT Risk and Compliance Analyst

2 Months ago • 4 Years + • Cyber Security

About the job

Job Description

Morningstar seeks a Senior IT Risk and Compliance Analyst to support compliance obligations (SOX, SOC2, PCI-DSS, SEC). You'll gather evidence for audits, monitor compliance, identify security findings, and liaise with third-party auditors. 4+ years' experience in risk & compliance or IT auditing with proven expertise in SOX, SOC2, PCI-DSS, GDPR, and IT audits is essential.
Must have:
  • Compliance Standards
  • IT Auditing
  • Risk & Compliance
  • Security Frameworks
Good to have:
  • Customer Facing
  • Business Analysis
  • Security Policies
  • Audit Tests
Perks:
  • Hybrid Work
  • Global Colleagues
Not hearing back from companies?
Unlock the secrets to a successful job application and accelerate your journey to your next opportunity.

Role:

The Senior IT Risk and Compliance Analyst will assist in supporting Morningstar’s compliance related responsibilities. This individual will help current and future compliance obligations are met, assist in identifying and following up on information security findings, gather evidence required for internal and external audits, and provide level 2 support for analysts responding customer RFPs and due diligence questionnaires.

Location: Bucharest, Romania

Responsibilities:

  • Assist in supporting Morningstar’s current and future compliance related responsibilities (SOX, SOC2, PCI-DSS, SEC, etc.) 
  • Gather evidence required for internal and external audits 
  • Monitor and enforce compliance to information security and compliance policies and standards 
  • Assist with documenting and regularly reviewing security policies, processes and procedure 
  • Execute audit tests; identify issues and areas for improvement in security policy compliance 
  • Identify and follow up on information security findings to ensure they are properly remediated 
  • Liaise with third party audit personnel as required 

 

Requirements 

  • A bachelor’s degree and 4+ years’ experience in a risk and compliance or I.T. auditor role 
  • Familiarity with common compliance standards (SOX, SOC2, PCI-DSS, GDPR etc.) and experience working directly with internal or external auditors for at least one of the listed standards 
  • 1+ years experience in customer facing role directly responding to customer information security and compliance concerns 
  • Familiarity with IT audits and risk assessments 
  • Familiarity with security frameworks (ISO 27001, NIST, etc.) and general security concepts 
  • Strong organizational skills and the ability to multitask and switch priorities with short notice 
  • Strong business analysis, research and analytical skills 
  • Excellent communication skills 
  • Availability to work off business hours as required 

 

315_Sustainalytics SRL Legal Entity

Morningstar’s hybrid work environment gives you the opportunity to work remotely and collaborate in-person each week. We’ve found that we’re at our best when we’re purposely together on a regular basis, at least three days each week. A range of other benefits are also available to enhance flexibility as needs change. No matter where you are, you’ll have tools and resources to engage meaningfully with your global colleagues.

View Full Job Description

Add your resume

80%

Upload your resume, increase your shortlisting chances by 80%

About The Company

Singapore (Hybrid)

New Delhi, Delhi, India (Hybrid)

Chicago, Illinois, United States (Hybrid)

Mumbai, Maharashtra, India (On-Site)

New Delhi, Delhi, India (Hybrid)

Mumbai, Maharashtra, India (Hybrid)

Chicago, Illinois, United States (Hybrid)

Chicago, Illinois, United States (Hybrid)

Bucharest, Bucharest, Romania (Hybrid)

View All Jobs

Get notified when new jobs are added by Morning Star

Similar Jobs

Electronic Arts - Videogame Tester - Italian

Electronic Arts, Spain (On-Site)

Playtech - Engineering Manager

Playtech, Bulgaria (On_site)

Playtech - Trainer

Playtech, Bulgaria (On-Site)

Infoblox - Manager, Enterprise Support

Infoblox, India (On-Site)

Granicus - SOC Analyst II

Granicus, India (Remote)

CrowdStrike - Vulnerability Researcher (Remote, IND)

CrowdStrike, India (Remote)

Get notifed when new similar jobs are uploaded

Similar Skill Jobs

Next Level Business Services - Senior Java Developer

Next Level Business Services, United States (On-Site)

Ubisoft - Senior Producer

Ubisoft, Canada (On-Site)

Paypal - Senior Data Scientist - MMM

Paypal, India (Hybrid)

Playtika - Spine Animator

Playtika, Israel (On-Site)

Futurum Technology  - IT Sales Partner Scandinavia

Futurum Technology , (On-Site)

N-iX - Senior Data Engineer (#2324)

N-iX, Ukraine (Remote)

NinjaVan - Internship (IT)

NinjaVan, Malaysia (On-Site)

PwC - Senior Associate-Oracle SCM

PwC, India (On-Site)

Intrepid Studios,  Inc  - Senior Producer

Intrepid Studios, Inc , Canada (On-Site)

Niantic - Software Engineer, Mobile Native AR Mapping

Niantic, United States (Hybrid)

Get notifed when new similar jobs are uploaded

Jobs in Bucharest, Bucharest, Romania

Global Step - Game Tester

Global Step, Romania (Hybrid)

Nagarro - Senior Engineer

Nagarro, Romania (On-Site)

Playtech - English Dealer

Playtech, Romania (On_site)

Luxoft - Senior IT Application Owner

Luxoft, Romania (Hybrid)

Amazon - QA Specialist Lead, Amazon Games

Amazon, Romania (On-Site)

Limbic Entertainment - Technical Artist

Limbic Entertainment, Romania (Hybrid)

Playnetic - Engineering Team Lead

Playnetic, Romania (Remote)

Get notifed when new similar jobs are uploaded

Cyber Security Jobs

PwC - IT Audit Analyst

PwC, Sri Lanka (On-Site)

ION - IT Internal Auditor, Italy

ION, Italy (Hybrid)

Nintendo - Security Engineer

Nintendo, United States (Hybrid)

Intel Corporation - Principal System Security Architect

Intel Corporation, United States (On-Site)

Varonis  - Cloud Security Architect

Varonis , United Kingdom (On-Site)

Rank group - Group Information Security Risk Analyst

Rank group, United Kingdom (On-Site)

Fortra - Cloud Security Engineer

Fortra, United Kingdom (On-Site)

Get notifed when new similar jobs are uploaded