IXL Learning, developer of personalized learning products used by millions of people globally, is seeking a GRC Security Analyst to join our growing team. In this role you will oversee and actively participate in IXL’s internal cybersecurity governance and compliance/audit program, serve as the liaison for external audits, drive security awareness training in addition to phishing exercises and cross-train with and support other members of the security team. This role requires a strong understanding of security frameworks and regulatory requirements, risk management frameworks and industry best practices.
#LI-KO1
This is a full-time position in IXL’s San Mateo headquarter office. The work schedule for this role is Monday-Friday in the office with the option to work from home one day per week.
WHAT YOU'LL BE DOING
- Develop and implement GRC strategies, policies, and procedures to ensure compliance with regulatory standards and industry best practices
- Collaborate with cross-functional teams to integrate GRC principles into business processes and systems
- Monitor regulatory changes and industry trends to ensure the organization remains compliance and proactive in addressing emerging risks
- Lead and support the execution of audits, assessments, and compliance activities through validation of adherence to compliance standards
- Support the execution and continual improvement of the company’s information security and privacy programs, with an emphasis on meeting multiple compliances and attestations such as SOC2, PCI-DSS, ISO27001, State/GovRAMP, and GDPR
- Provide support to the Information Security Incident Response team during cyber/privacy incidents
- Support team members on risk management requests and provide subject matter expertise
- Mentor, coach and cross-train security team members, fostering their professional development and growth with-in the organization
- Identify areas of improvement related to third party risk management to drive maturity.
- Promote security awareness within the organization and of security initiatives
- Complete security questionnaires for prospective clients and customers
- Guide security training curriculum and recurring phishing simulations
- Participating in and supporting other security verticals and initiatives including those around security engineering and operations
WHAT WE'RE LOOKING FOR
- A highly technical candidate who isn’t afraid to get their hands dirty and supports outside their known vertical
- Bachelor’s Degree, Information Systems, Computer Science, Information Security or related field
- Certified Information Systems Security Professional (CISSP), Certified Information Security Auditor (CISA), Certified Information Security Manager (CISM) or similar industry certification preferred.
- 5+ years of experience conducting in GRC, risk management, or related fields
- Experience supporting and/or leading audit discussions
- Experience administering IT security controls in an organization
- Strong knowledge of common control frameworks (ISO27001, NIST 800) and attestations/compliances (SOC2, PCI-DSS, State/GovRAMP, GDPR)
- Familiarity working with legal teams and supporting cross-functional privacy programs (i.e. CPRA)
- Proven experience in developing and implementing GRC frameworks, drafting policies and procedures
- Ability to lead and manage projects, including coordinating cross-functional teams and delivering results on time
- Excellent analytical skills with the ability to assess complex risks and develop effective mitigation strategies
- Strong verbal and written communication and time management skills
Our salary ranges are determined by role, level, and location. The base salary range for this full-time position is $120,000 to $160,000 + benefits. The range displayed on each job posting reflects the minimum and maximum target for new hire salaries for the position. Individual pay is determined by work location and additional factors, including job-related skills, experience, and relevant education or training. Your recruiter can share more about the specific salary range for your preferred location during the hiring process.
OUT IXL LEARNING
IXL Learning is the country's largest EdTech company. We reach millions of learners through our diverse range of products. For example:
- 1 in 4 students in the United States uses IXL.com
- Rosetta Stone provides an immersive learning experience for 25 languages
- Wyzant is the nation's largest community of tutors, covering 300+ subjects
- Teachers Pay Teachers (TPT) is a comprehensive marketplace for millions of educator-created resources
Our mission is to create innovative products that will make a real, positive difference for learners and educators and we're looking for passionate, mission-minded people to join us in achieving this goal. We have a unique culture at IXL that fosters collaboration and the open exchange of ideas. We value our team and treat one another with kindness and respect. We approach our work with passion, tenacity, and authenticity. We find it immensely satisfying to develop products that impact the lives of millions and we are eager to have you join our team.
At IXL, we value diversity in age, race, ethnicity, gender, sexual orientation, physical and mental ability, political and religious beliefs, and life experience, and we are proud to promote a work environment where everyone, from any background, can do their best work. IXL Learning is an Equal Opportunity Employer.