Fragomen Logo

Fragomen

IT GRC Analyst

Posted Yesterday
Be an Early Applicant
Remote
Hiring Remotely in Corporal, CA
Senior level
Remote
Hiring Remotely in Corporal, CA
Senior level
Support Fragomen's GRC operations by demonstrating security controls to clients and auditors, managing risk documentation and remediation, configuring GRC platforms, supporting ISO/SOC/PCI audits, vendor risk management, and security awareness initiatives.
The summary above was generated by AI

Job Description

Fragomen is seeking a Compliance Analyst to join our talented Compliance Response Team.

A Fragomen career gives you the opportunity to work with a smart, motivated and diverse peer group. Our exclusive focus on immigration means you will practice in an exciting, ever-changing and challenging environment with people who are passionate about immigration. Working in a collegial, team-oriented environment, Fragomen employees learn from the industry's leading experts. Our firm commitment to quality and best practices is supported by technological innovation that benefits our clients and staff.

Fragomen strongly affirms that the demonstration of data privacy and security is critical to meet our obligations to our clients and distinguishes our business offerings in this competitive market. 

The Compliance Analyst will report directly to the Governance, Risk, and Compliance Operations Manager.  

We seek a professional, diligent individual that can keep up with the high demand of client and partner requests that support, identify and demonstrate Fragomen’s security controls. 

A candidate should

  • have thorough knowledge of IT Security controls to include basic understanding of Cybersecurity frameworks such as NIST 800-53, ISO 27001, SOC 2 type 2 and CIS controls. The candidate should have experience collecting evidence from internal stakeholders and presenting them to external auditors.
  • have a strong understanding of cybersecurity risk management, including how to document risks and develop risk treatment plans
  • understand and be able to articulate the relationship between cybersecurity and internal general controls (ITGC), compliance obligations and risk reduction
  • have experience configuring and using common GRC platforms, such as Vanta, Drata, and Apptega
  • have experience drafting IT policies that align with industry best practices
  • understand vendor and third-party risk management processes
  • Have experience with supporting cybersecurity awareness programs 
  • be knowledgeable of the global regulatory landscape and capable of communicating the Firm’s efforts in this area. 
  • be collaborative and team oriented as a member of Fragomen’s Governance, Risk & Compliance (GRC) team which helps make data privacy and security a distinguishing factor in our technological offerings.

A successful candidate will demonstrate these competencies and possess excellent communication skills to communicate our data security, data privacy and compliance efforts to our global partners, senior leadership, and Clients.

Responsibilities will center around demonstrating to Clients Fragomen’s secure operational environment and foundational security policies and principles through the completion of client questionnaires, external certifications, Client audits, RFPs, and technical assessments.

What a Compliance Analyst Does at Fragomen:

Operationalizing Risk Management:

  • Understand industry standard cybersecurity risks and how controls affect them. 
  • Understand how GRC platforms work and how they support Risk Management
  • Develop trusted relationships with senior business partners to gain an in-depth understanding of key business processes, products and services, and influences others to ensure business case and customer satisfaction goals are met.
  • Acquire fundamental knowledge of all Fragomen areas to better understand emerging risks.
    • Support the Service Delivery function to deliver reliable, best-in-class support services in a manner that meets our contractual obligations and delights our customers and clients.
    • Assist with vendor and third-party risk management

IT Compliance

  • Support ISO 27001, SOC 2 type 2 and PCI audits by gathering and documenting how Fragomen is meeting the control objectives identified in these standards
  • Support completing client facing requests demonstrating Fragomen’s security controls to include demonstrating and understanding technical security controls.
  • Work closely with IT internal audit to meet IT security compliance obligations

Assistance in GRC Operations:

  • Collaboratively work with teammates and internal Fragomen teams and take direction from management to resolve assigned Client support work items with both speed and quality.
    • Acquire fundamental knowledge of all Compliance Operations areas to gain comprehensive knowledge of operations and industry standard best practices.
  • Support security awareness programs
  • Collaborate with GRC oriented teams - the Office of Audit and Privacy, the Office of General Counsel, Information Security and Compliance - and legal/client relationship teams to continuously improve and demonstrate the firm’s commitment to data privacy and security.
  • Produce written and verbal communication, that when escalating matters, is summarized, and always clear and concise.
  • Provide ideas and suggestions for department process improvements.

Let’s Talk If You Have:

  • A strong understanding information security and data privacy frameworks and their control objectives including NIST Cyber Security Framework (CSF), NIST 800-53, and CIS
  • Experience supporting ISO27X series, SOC2 and PCI compliance requirements and external audits, including control and evidence documentation
  • Broad knowledge of Data Privacy regulatory landscape including but not limited to GDPR.
  • Experience in risk management and project management, including but not limited to documenting and developing remediation plans.
  • Experience supporting security awareness training
  • Drafting IT Policies that align with industry best practice and cybersecurity frameworks
    • Strong communication skills both written and verbal
    • Outstanding work ethic
  • Minimum of 5 years of experience in the IT Security GRC field based on work history and/or education.
    • Big 4 or large consulting firm experience a major plus

All offers and/or employment contracts are contingent upon the successful completion of the Firm’s pre-employment screening process. This process may include verifying the candidate’s identity, confirming legal authorization to work in the offered position's location, and conducting a comprehensive background check, where permitted by local regulations.

Top Skills

Nist 800-53,Iso 27001,Soc 2,Cis Controls,Nist Csf,Pci,Gdpr,Vanta,Drata,Apptega,Itgc

Similar Jobs

An Hour Ago
Remote or Hybrid
San Francisco, CA, USA
Expert/Leader
Expert/Leader
Artificial Intelligence • Fintech • Payments • Business Intelligence • Financial Services • Generative AI
Lead Financial Crime Compliance for the Americas, manage and scale the FCC team, liaise with regulators, oversee BAU AML activities, support new market/product launches, coordinate audits and remediation, and contribute to global FCC strategy and governance.
An Hour Ago
Remote or Hybrid
San Francisco, CA, USA
Senior level
Senior level
Artificial Intelligence • Fintech • Payments • Business Intelligence • Financial Services • Generative AI
Lead end-to-end insider-threat investigations across AML, sanctions, fraud, and COI; analyze large datasets to detect anomalies; develop intelligence and typologies; advise senior stakeholders; build program policies, procedures, and training across People, Legal, InfoSec, and Operations.
Top Skills: BigQueryData Visualization ToolsPythonSQL
An Hour Ago
Remote or Hybrid
6 Locations
133K-235K Annually
Junior
133K-235K Annually
Junior
Artificial Intelligence • Cloud • Machine Learning • Mobile • Software • Virtual Reality • App development
This role involves developing Android applications, implementing features, performing code reviews, and ensuring a great user experience.
Top Skills: DaggerJavaKotlinRxjava

What you need to know about the Austin Tech Scene

Austin has a diverse and thriving tech ecosystem thanks to home-grown companies like Dell and major campuses for IBM, AMD and Apple. The state’s flagship university, the University of Texas at Austin, is known for its engineering school, and the city is known for its annual South by Southwest tech and media conference. Austin’s tech scene spans many verticals, but it’s particularly known for hardware, including semiconductors, as well as AI, biotechnology and cloud computing. And its food and music scene, low taxes and favorable climate has made the city a destination for tech workers from across the country.

Key Facts About Austin Tech

  • Number of Tech Workers: 180,500; 13.7% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Dell, IBM, AMD, Apple, Alphabet
  • Key Industries: Artificial intelligence, hardware, cloud computing, software, healthtech
  • Funding Landscape: $4.5 billion in VC funding in 2024 (Pitchbook)
  • Notable Investors: Live Oak Ventures, Austin Ventures, Hinge Capital, Gigafund, KdT Ventures, Next Coast Ventures, Silverton Partners
  • Research Centers and Universities: University of Texas, Southwestern University, Texas State University, Center for Complex Quantum Systems, Oden Institute for Computational Engineering and Sciences, Texas Advanced Computing Center

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account