Herbalife

Analyst III, GRC

Herbalife  •  Bengaluru, IN (Onsite)  •  21 days ago
Apply
AI can make mistakes so check important info. Chat history is never stored.

Job Description

THE ROLE:

The GRC Analyst III investigates and analyzes potential areas of risk, compliance and exposure to Technology (and Herbalife Nutrition), highlighting and quantifying the risks to help drive business decisions. This role must proactively escalate potential risks, issues and exposure to leadership and be outspoken in seeking mitigation actions. As this role progresses, the GRC Analyst will gain responsibility in designing and defining the risk analysis and serve as an advisor in GTS/DO/Cybersecurity.

HOW YOU WOULD CONTRIBUTE:

  • 6+ years experience on IT governance, risk management, vulnerability management and compliance tools and processes
  • Conduct risk/control/vulnerability analyses using statistical models to determine potential risk and exposure and produce reports to leadership for risk-related decisions.
  • Drive tracking, maintenance and reporting for operational risk register, risk and control matrix, and vulnerability register
  • Prioritize and report on risk/compliance/vulnerabilities discovered along with the remediation timeline(s)
  • Provide risk/compliance/vulnerability/security testing, produce reports and dashboards for management, and drive preventative and mitigation actions.
  • Maintain current knowledge of evolving threat landscape.
  • Collaborate with multiple global teams and SMEs of risk/compliance/vulnerabilities within the environment.
  • Develop relevant training material for Governance Risk and Compliance
  • Coordinate with cross-functional members across technology functions
  • Ensures SOX compliance; tracks deficiencies and drives mitigation actions
  • Acts as internal and external liaison with auditors
  • Design, execute and manage security awareness training and simulated phishing campaigns to assess the organization's susceptibility to attacks
  • Conduct regular reviews of sensitive access permissions and collaborate with technology teams to ensure compliance with internal policies and regulatory requirements
  • Perform comprehensive reviews of existing policies to ensure they are up-to-date and aligned with industry best practices and regulatory requirements
  • Identify and document policy exceptions, and work with relevant stakeholders to assess and mitigate associated risks
  • Develop and implement new policies and procedures to address emerging risks and compliance requirements
  • Identify areas for process improvement within the GRC program and develop strategies to enhance efficiency and effectiveness
  • Collaborate with cross-functional teams to implement process improvements and ensure alignment with organizational goals
  • Provide guidance and support to junior team members, helping them develop their skills and knowledge in GRC
  • Performs additional duties as assigned

WHAT’S SPECIAL ABOUT THE TEAM:

Governance Risk and Compliance is global team collaborating with IT, Cybersecurity, Privacy, Enterprise Risk among other risk teams in the company, to manage technology risks and provide proactive risk solutions. Our vision is to provide risk information to support fact-based decision making, aligned with our enterprise strategy.

SKILLS AND BACKGROUND REQUIRED TO BE SUCCESSFUL:

  • Proficient in related GRC analysis and risk assessment and vulnerability tools
  • Knowledge of application, network and operating system security
  • GRC (governance, risk, and compliance) experience is a must
  • Knowledge of vulnerability scoring systems (CVSS/CMSS)
  • Communication skills to relay results of analysis
  • Ability to build strong relationships across various functions of Technology to be able to preemptively identify and communicate risks
  • Detail oriented, organized, methodical, follow up skills with an analytical thought process.

Certificates / Training:

  • IT, risk and security practices, standards and controls (e.g. COBIT, NIST-CSF, CIS-CSC, C2M2, CSOE, ITIL).
  • Certified Information Systems Auditor (CISA)
  • Certified Information Security Manager (CISM).
  • Certified Cloud Security Professional (CCSP).
  • Certified in Risk and Information System Controls (CRISC).
  • Certified Information Systems Security Professional (CISSP)

Education

Required

  • Bachelor's in Information Technology or equivalent

Preferred

  • Advanced Technical Degree

Qualifications

THE ROLE:

The GRC Analyst III investigates and analyzes potential areas of risk, compliance and exposure to Technology (and Herbalife Nutrition), highlighting and quantifying the risks to help drive business decisions. This role must proactively escalate potential risks, issues and exposure to leadership and be outspoken in seeking mitigation actions. As this role progresses, the GRC Analyst will gain responsibility in designing and defining the risk analysis and serve as an advisor in GTS/DO/Cybersecurity.

HOW YOU WOULD CONTRIBUTE:

  • 6+ years experience on IT governance, risk management, vulnerability management and compliance tools and processes
  • Conduct risk/control/vulnerability analyses using statistical models to determine potential risk and exposure and produce reports to leadership for risk-related decisions.
  • Drive tracking, maintenance and reporting for operational risk register, risk and control matrix, and vulnerability register
  • Prioritize and report on risk/compliance/vulnerabilities discovered along with the remediation timeline(s)
  • Provide risk/compliance/vulnerability/security testing, produce reports and dashboards for management, and drive preventative and mitigation actions.
  • Maintain current knowledge of evolving threat landscape.
  • Collaborate with multiple global teams and SMEs of risk/compliance/vulnerabilities within the environment.
  • Develop relevant training material for Governance Risk and Compliance
  • Coordinate with cross-functional members across technology functions
  • Ensures SOX compliance; tracks deficiencies and drives mitigation actions
  • Acts as internal and external liaison with auditors
  • Design, execute and manage security awareness training and simulated phishing campaigns to assess the organization's susceptibility to attacks
  • Conduct regular reviews of sensitive access permissions and collaborate with technology teams to ensure compliance with internal policies and regulatory requirements
  • Perform comprehensive reviews of existing policies to ensure they are up-to-date and aligned with industry best practices and regulatory requirements
  • Identify and document policy exceptions, and work with relevant stakeholders to assess and mitigate associated risks
  • Develop and implement new policies and procedures to address emerging risks and compliance requirements
  • Identify areas for process improvement within the GRC program and develop strategies to enhance efficiency and effectiveness
  • Collaborate with cross-functional teams to implement process improvements and ensure alignment with organizational goals
  • Provide guidance and support to junior team members, helping them develop their skills and knowledge in GRC
  • Performs additional duties as assigned

WHAT’S SPECIAL ABOUT THE TEAM:

Governance Risk and Compliance is global team collaborating with IT, Cybersecurity, Privacy, Enterprise Risk among other risk teams in the company, to manage technology risks and provide proactive risk solutions. Our vision is to provide risk information to support fact-based decision making, aligned with our enterprise strategy.

SKILLS AND BACKGROUND REQUIRED TO BE SUCCESSFUL:

  • Proficient in related GRC analysis and risk assessment and vulnerability tools
  • Knowledge of application, network and operating system security
  • GRC (governance, risk, and compliance) experience is a must
  • Knowledge of vulnerability scoring systems (CVSS/CMSS)
  • Communication skills to relay results of analysis
  • Ability to build strong relationships across various functions of Technology to be able to preemptively identify and communicate risks
  • Detail oriented, organized, methodical, follow up skills with an analytical thought process.

Certificates / Training:

  • IT, risk and security practices, standards and controls (e.g. COBIT, NIST-CSF, CIS-CSC, C2M2, CSOE, ITIL).
  • Certified Information Systems Auditor (CISA)
  • Certified Information Security Manager (CISM).
  • Certified Cloud Security Professional (CCSP).
  • Certified in Risk and Information System Controls (CRISC).
  • Certified Information Systems Security Professional (CISSP)

Education

Required

  • Bachelor's in Information Technology or equivalent

Preferred

  • Advanced Technical Degree
Herbalife

About Herbalife

Herbalife is a global health and wellness community born to support you in living your best life. For over 40 years and in more than 90 countries, we’ve empowered millions of people to make real changes to their lives with our science-backed products, the support of a coach – what we call an Herbalife Distributor – and the opportunity to build a business. And we’re just getting started.

To us, the best lives are balanced lives. Through our Herbalife Distributors, who foster community, personal growth and business opportunities to help you thrive, we offer a wide range of products designed to help you meet your needs and reach your goals. You bring the will to get started, and we’ll help you every step of the way.

Herbalife's focus on improving communities inspires people to come work for us. Our 11,000+ global employees play a crucial role in realizing Herbalife's passion for helping people.

Herbalife has been recognized with numerous global employer awards, including Achiever’s Elite 8 of the Top 50 Most Engaged 8 Workplaces in 2018 and 2021, Achiever’s Top 50 Most Engaged Workplaces in 2019, and Best Employers for Women by Forbes in 2020.

Herbalife sponsors more than 150 world-class athletes, teams, and events, including Cristiano Ronaldo, the Los Angeles Galaxy soccer team, and 5 National Olympic Committees.

In addition, Herbalife created the Herbalife Nutrition Foundation, our Nutrition for Zero Hunger initiative and partnered with several organizations, including Feed the Children.

Industry
Arts & Entertainment
Company Size
10,000+ employees
Headquarters
Los Angeles, CA
Year Founded
1980
Social Media