Job Description
Job Title: IT - Gov Analyst
Status: Exempt
Reports to: Manager - IT - Governance Risk and Compliance
Department: IT - Governance Risk and Compliance
Job Code: 11349
Pay Range: $92,700.00 - $120,000.00 Annually
Location:
WHO WE ARE:
Golden 1 Credit Union is among the top credit unions in the country. As a member-owned, not-for-profit cooperative, Golden 1 is guided by the credit union philosophy of “people helping people.” We are committed to empowering our members and uplifting our communities as we create a more equitable and financially inclusive California. We welcome all who embrace our Core Values.
WHO YOU ARE:
You are a highly analytical and detail-oriented governance, risk, and compliance professional with a passion for strengthening controls, managing risk, and driving regulatory compliance. You excel at coordinating audits, assessing control environments, analyzing data, and partnering across teams to improve processes and mitigate risk. You are an effective communicator who balances regulatory requirements with business needs, builds strong stakeholder relationships, and promotes a culture of accountability, security, and continuous improvement.
WHAT YOU'LL DO:
• Manage the reporting requirements for Golden 1’s IT GRC program, ensuring IT activities, processes, and procedures meet defined requirements, policies, and regulations. Manage assessments and gap analyses of Golden 1’s IT control environment against industry and regulatory governance frameworks (i.e., NIST Cyber Security Framework, ISO 27001, SOC 1/2, COBIT, ITIL, Sarbanes-Oxley, and CCPA/GDPR).
• Apply GRC expertise across key lines of business, including products, practices, and procedures. Coordinate and track IT related audits activities including scope, timelines, evidence gathering, and remediation task outcomes. Ensure Golden 1’s IT teams maintain up-to-date configuration documentation for systems and processes. Provide guidance, evaluation, and advocacy on audit responses for the department.
• Maintain oversight in a GRC-related platform.
• Produce metrics, reports, and dashboards as applicable. Execute Golden 1’s IT strategy for dealing with increasing number of audits, compliance checks and external assessment processes.
• Oversee the management of system user access reviews including data collection and follow-up with system owner approvals and timely submissions as required.
• Identify strengths and weaknesses in the GRC program as they relate to privacy, security, business resiliency and compliance frameworks.
• Support third-party risk assessments and manage third-party risk and remediation activities. Ensures proper reporting and response to alleged violations of company rules, regulations, policies, procedures, and standards of conduct by initiating and cooperating in investigative procedures.
• Work with auditors as appropriate to keep audit focus in scope and remediation delivery commitments. Maintain excellent relationships with audit entities and provide a consistent perspective that continually puts Golden 1 in its best light.
• Facilitate Business Continuity/Disaster Recovery Planning and Testing exercises.
• Support the development of strategies to address GRC awareness and training for all stakeholders and provide on-site guidance and instructions to other IT teams as needed.
• Maintain and enforce confidentiality regarding information being processed, stored, or accessed by the system.
• Perform other duties as assigned.
QUALIFICIATIONS AND PREFERENCES:
• Bachelor’s Degree in Business Administration, Accounting, Management Information Systems or Computer Science preferred
• Master’s Degree in Business Administration or other related area preferred
• 5+ years in cybersecurity as a practitioner and with at least two to three plus years exposure with various security frameworks, experience in a technology risk, security, or compliance role preferably in a financial institution required
• Detailed understanding of risk management and controls assurance required
• Strong understanding of information security controls and standards such as ISO 27001/2, NIST, CSF, and related frameworks required
• Thorough understanding of various regulatory requirements and laws such as, but not limited to PCI, SOX, HIPAA, HITRUST, GDPR and GLBA required
• Experience in a role balanced between business stakeholders and a central technology service organization required
WHY JOIN US:
Golden 1 Credit Union provides its employees a market-competitive and internally equitable total rewards compensation package through a variety of programs. These programs are designed to attract, motivate, and retain employees that drive and support the achievement of Our Mission, Vision, and Strategic Goals. The Credit Union is committed a total rewards philosophy built on; a comprehensive compensation package, well-being and work-life balance, career development and growth, rewards and recognition, and a commitment to Diversity, Equity and Inclusion. We believe in fostering a workplace where every employee is recognized, valued, and motivated to contribute their best.
Please view the full job description detailing the complete list of duties and expectations for this role by clicking or copying this URL into your browser: https://golden1.jdxpert.com/ShowJob.aspx-EntityID=2&id=2153
DISCLAIMER/INTENT AND FUNCTION OF JOB DESCRIPTIONS:
The above information on this description has been designed to indicate the general nature and level of work performed by team members within this classification. Because the nature of positions and job functions can change over time, this job description is not designed to contain or be interpreted as a comprehensive inventory of all essential functions, duties, responsibilities and qualifications requirements of team members assigned to this job. Job duties may be changed or modified in the Credit Union’s discretion. The Credit Union will keep team members updated on key functions, duties, and requirements of their position by communications from the Credit Union and by updating the job description from time to time. Any team member with questions about the nature of their job duties is encouraged to consult with their supervisor.
#LI-Hybrid