Logo
City and County of Denver

Data Protection Governance, Risk, and Compliance Analyst

City and County of Denver, Denver, Colorado, United States, 80285


About Our JobWho We Are

With competitive pay, great benefits, and endless opportunities, working for the City and County of Denver means seeing yourself working with purpose — for you, and those who benefit from your passion, skills and expertise. Join our diverse, inclusive and talented workforce of more than 11,000 team members who are at the heart of what makes Denver, Denver.We value diversity of ethnicity, race, socioeconomic status, sexual identity, gender, religion, language, ability, and experience and exemplify this through the makeup of our team at all levels. You'll be right at home here if you cultivate strong relationships and push yourself, your work, the people around you and Denver to the next level.The Technology Services Department (TS) of the City and County of Denver use state-of-the-art technologies and methodologies to deliver and improve the systems, applications, and operations to our customers. Technology Services supports the people, agencies, and ideas that make the City and County of Denver a world-class city.What We Offer

The City and County of Denver offers a competitive salary commensurate with education and experience. The salary range for this position is $70,765.00 - $116,762.00/year, based on education and experience. We also offer generous benefits for full-time employees which includes but is not limited to:A guaranteed life-long monthly pension, once vested after 5 years of service457B Retirement plan132 hours of PTO earned within first year + 11 paid holidays, 1 personal holiday and 1 volunteer day per yearCompetitive medical, dental and vision plans effective within 1 month of start dateLocation

The City and County of Denver supports a hybrid workplace model. Employees work where needed, at a job site several days a week and off-site as needed. Employees must work within the state of Colorado on their off-site days.What You’ll Do

The City and County of Denver (CCD) is seeking a Data Protection Governance, Risk, Compliance (GRC) Analyst holistically, ensuring risk and vulnerabilities are viewed not only from a system security standpoint, although from the lens of the end user and application. In this role, you will be a key stakeholder in the CCD GRC Team.Specifically, you will focus on managing the CCD Technology Services (TS) Vendor Risk Assessment Program and provision and monitor cybersecurity completion for City & County of Denver Employees. Ensuring all new and existing Citywide Technology vendors are assessed through our initial and annual risk assessment monitoring. You will evaluate all requests for risk assessment and determine necessary reviews and assessments. You will work with vendors and various stakeholders within CCD for vendor risk assessment completion. You will also communicate all applicable assessment conclusions such as specific compliance or contract language needs and approvals and denials related to the vendor risk assessment. You will manage an annual risk assessment monitoring which will include assessing vendors for risk and conducting a high-level monitoring of the vendors. The selected candidate will also determine the training needs of CCD employees based on identified user behavior and risk. You will work with HR workday learning folks to ensure training is provided to all applicable CCD employees. Training completion will be monitored and follow up will occur with employees who do not complete training timely. You will also support other GRC activities such as approval/denial of third-party file share utilization, and other governance, risk, and compliance activities such as assessing for risk, ensuring compliance with various regulatory requirements and working on projects such as the role-based access control project.Responsibilities

Utilize ServiceNow to manage Vendor Risk AssessmentsUtilize ServiceNow to approve third party file share permission requestsRespond to and organize responses to third party risk assessment requests from CCD.Review & select training material and manage training completion.Perform other related duties as assigned.What You’ll Bring

1-3 years of experience working in data protection and/or governance, risk, compliance. Years of experience can supplement education requirements.Knowledge and experience with application and compliance of the following regulations is preferred:

US Department of Commerce, National Institute of Standards and Technology (NIST), Cybersecurity and Privacy FrameworksPayment Card Industry Data Security Standard (PCI-DSS)US Department of Health and Human Services, Health Insurance Portability and Accountability Act (HIPAA)US Department of Justice, Federal Bureau of Investigation, Criminal Justice Information Services Security (CJIS) Policy

Minimum Qualifications

Education Requirement: Bachelor's Degree in Information Technology or a related field based on a specific position(s).Experience Requirement: Two years of experience with data protection, governance, risk assessment, and compliance with information technology systems.Education and Experience Equivalency: One (1) year of the appropriate type and level of experience may be substituted for each required year of post-high school education.Additional appropriate education may be substituted for the minimum experience requirements.Must obtain Criminal Justice Information Services (CJIS) clearance within the probationary period.Application Deadline

This position is expected to stay open until October 14th. Please submit your application as soon as possible.About Everything Else

Job Profile : CI3432 IT Data Protection Analyst AssociateTo view the full job profile including position specifications, physical demands, and probationary period, click

here .Position Type : UnlimitedPosition Salary Range : $70,765.00 - $116,762.00Starting Pay : Based on education and experienceAgency : Technology ServicesThe City and County of Denver provides equal employment opportunities to all employees and applicants for employment without regard to race, color, religion, national origin, sex, sexual orientation, gender identity, national origin, disability, genetic information, age, or any other status protected under federal, state, and/or local law.It is your right to access oral or written language assistance, sign language interpretation, real-time captioning via CART, or disability-related accommodations. To request any of these services at no cost to you, please contact

Jobs@Denvergov.org

with three business days’ notice.Applicants for employment with the City and County of Denver must have valid work authorization that does not require sponsorship of a visa for employment authorization in the U.S.For information about right to work, click

here

for English or

here

for Spanish.

#J-18808-Ljbffr