The Senior IT Risk and Compliance Analyst will assist in supporting Morningstar's compliance related responsibilities. This individual will help current and future compliance obligations are met, assist in identifying and following up on information security findings, gather evidence required for internal and external audits, and provide level 2 support for analysts responding customer RFPs and due diligence questionnaires.
Responsibilities:
- Assist in supporting Morningstar's current and future compliance related responsibilities (SOX, SOC2, PCI-DSS, SEC, etc.)
- Gather evidence required for internal and external audits
- Monitor and enforce compliance to information security and compliance policies and standards
- Assist with documenting and regularly reviewing security policies, processes and procedure
- Execute audit tests; identify issues and areas for improvement in security policy compliance
- Identify and follow up on information security findings to ensure they are properly remediated
- Liaise with third party audit personnel as required
Requirements
- A bachelor's degree and 4+ years' experience in a risk and compliance or I.T. auditor role
- Familiarity with common compliance standards (SOX, SOC2, PCI-DSS, GDPR etc.) and experience working directly with internal or external auditors for at least one of the listed standards
- Experience in a customer facing role directly responding to customer information security and compliance concerns
- Familiarity with IT audits and risk assessments
- Familiarity with security frameworks (ISO 27001, NIST, etc.) and general security concepts
- Strong organizational skills and the ability to multitask and switch priorities with short notice
- Strong business analysis, research and analytical skills
- Excellent communication skills
315_Sustainalytics SRL Legal Entity
Morningstar's hybrid work environment gives you the opportunity to work remotely and collaborate in-person each week. We've found that we're at our best when we're purposely together on a regular basis, at least three days each week. A range of other benefits are also available to enhance flexibility as needs change. No matter where you are, you'll have tools and resources to engage meaningfully with your global colleagues.
What We Do
At Morningstar, we believe in building great products in-house in a highly collaborative, agile environment where we focus on technical excellence, the user experience, and continuous improvement. Our technologists represent a range of skills and experience levels, but they all view their work as a craft and push technology’s boundaries.
Why Work With Us
Imagining big things is in our blood -- it's transformed us from a company with just a few employees in 1984 to a leading independent investment research company with a worldwide presence today. As of April 2020, we acquired Sustainalytics to drive long-term meaningful outcomes for investors in the ESG space. Join us on this exciting journey!
Gallery
Morningstar Offices
Hybrid Workspace
Employees engage in a combination of remote and on-site work.