JOB SUMMARY:
The Cybersecurity Governance, Risk, and Compliance (GRC) Analyst plays a vital role in ensuring that Denny’s maintains a robust and effective Cybersecurity program. This role involves managing governance processes, assessing and mitigating risks, and ensuring compliance with relevant regulations and standards. The GRC Analyst collaborates with various stakeholders to implement and maintain security policies, procedures, and controls.
ESSENTIAL FUNCTIONS (Key Responsibilities)
Governance:
- Develop and maintain Cybersecurity policies, standards, and procedures in alignment with industry best practices and regulatory requirements.
- Provide guidance and support to stakeholders on compliance with security policies and standards.
Risk Management:
- Conduct risk assessments and vulnerability assessments to identify and prioritize security risks to the organization's systems, networks, and data.
- Work with stakeholders to develop risk mitigation strategies and action plans.
- Monitor and track remediation efforts to address identified risks.
Compliance Management:
- Ensure compliance with relevant regulations, laws, and industry standards (e.g., CCPA, HIPAA, PCI DSS, SOX).
- Prepare and maintain documentation for compliance certifications and attestations.
- Monitor and assess the effectiveness of security controls through audits, reviews, and assessments.
- Manage third party relationship with PCI
Vendor Risk Management:
- Evaluate the security posture of third-party vendors and service providers.
- Monitor and manage vendor security assessments and due diligence processes
Security Awareness and Training:
- Develop and deliver security awareness training programs to educate employees about security risks and best practices.
- Promote a culture of security awareness and accountability throughout the organization.
EDUCATION & EXPERIENCE REQUIREMENTS:
- Bachelor’s degree in computer science, Information Security, or a related field.
- 2+ years Data Security, Server, or Network Management experience is a plus.
REQUIRED KNOWLDGE & SKILLS
- Advanced certifications (e.g., CISA, CRISC, SSCP, Security+) or the ability to obtain within 6 Months.
- Deep understanding of information security principles, standards, and frameworks (e.g., NIST Cybersecurity Framework, CIS Controls).
- Experience conducting risk assessments, vulnerability assessments, and compliance audits.
- Familiarity with regulatory requirements such as GDPR, CCPA, HIPAA, PCI DSS, and SOX.
- Strong analytical and problem-solving skills with the ability to assess complex security issues and recommend effective solutions.
- Excellent communication and interpersonal skills with the ability to collaborate with cross-functional teams and stakeholders.
- Ability to work independently and manage multiple priorities in a dynamic environment.
Denny's Corporation is committed to providing equal employment opportunity for all persons regardless of age, race, creed, color, national origin, citizenship status, religion, sex, sexual orientation, gender identity, disability, genetic information, military or veteran's status, criminal background, or any other characteristic protected by Federal, State, or local law.
Applicants requiring reasonable accommodation for any part of the application process should contact 864-597-8000. PLEASE DO NOT CONTACT THIS NUMBER TO CHECK THE STATUS OF YOUR APPLICATION.
Denny’s Corporation participates in E-Verify. We will provide the Social Security Administration, and if necessary, the Department of Homeland Security, with information from each new employee’s Form I-9 to confirm work authorization. For more information on E-Verify, please contact the DHS at 888-897-7781 or dhs.gov/e-verify. Please note that we do not use this information to pre-screen job applicants.