Logo
SiriusXM Radio, Inc.

Lead Analyst, Governance, Risk, and Compliance

SiriusXM Radio, Inc., Lawrenceville, New Jersey, United States,


Who We Are:SiriusXM and its brands (Pandora, SiriusXM Media, AdsWizz, Simplecast, and SiriusXM Connect) are leading a new era of audio entertainment and services by delivering the most compelling subscription and ad-supported audio entertainment experience for listeners -- in the car, at home, and anywhere on the go with connected devices.How you'll make an impact:The Lead Governance, Risk, and Compliance Analyst is a key member within SiriusXM's Governance, Risk, and Compliance team. This individual contributor will be responsible for managing the day-to-day execution of compliance assessment workstreams (PCI-DSS, SOC 2, ISO27001) as well as assisting in maturing and maintaining SiriusXM's Risk Management program.What you'll do:You will be the Lead GRC contact on assigned compliance assessment workstreams responsible for working directly with external assessors to assist in providing needed evidence, as well as tracking and reporting project progress against timeline to GRC Director.Partner with internal stakeholders to help interpret audit requirements into practical terms to help best identify the corresponding processes and evidence that satisfy these requirements.Work with internal stakeholders and external assessors on control findings, including control remediation and identification of compensating controls.Help maintain and mature the organization's risk management program, which will entail working with stakeholders to identify, document, and track risk in accordance with the organization's risk management strategy.Assist in the completion of security questionnaires from prospective and current customers.What you'll need:5+ years' experience in the GRC, audit, or risk management space.The ideal candidate will have experience managing security assessments (SOC1/SOC2, ISO27001, PCI-DSS), either as an external assessor or in an internal capacity.Solid grasp on information security control design and execution, as well as familiarity with compensating controls/ control remediation.Experience with documenting and tracking security risks.Must have strong communication skills, especially the ability to take ambiguous audit requirements and put them into actionable steps for non-technical control owners.Problem solving mindset - Able to assess a situation, identify potential resolutions, and propose them to management.Must have legal right to work in the U.S.Our goal at SiriusXM is to provide and maintain a work environment that fosters mutual respect, professionalism and cooperation. SiriusXM is an equal opportunity employer that does not discriminate on the basis of actual or perceived race, creed, color, religion, national origin, ancestry, alienage or citizenship status, age, disability or handicap, sex, gender identity, marital status, familial status, veteran status, sexual orientation or any other characteristic protected by applicable federal, state or local laws.

#J-18808-Ljbffr