Enterprise Security Policy and Standards Analyst at Comerica
Auburn Hills, MI 48326, USA -
Full Time


Start Date

Immediate

Expiry Date

31 Oct, 25

Salary

0.0

Posted On

31 Jul, 25

Experience

2 year(s) or above

Remote Job

Yes

Telecommute

Yes

Sponsor Visa

No

Skills

Glba, Control Testing, Hipaa, Computer Science, Servicenow, Risk, Information Governance, Information Management, It Governance, Reporting

Industry

Information Technology/IT

Description

ENTERPRISE SECURITY POLICY AND STANDARDS ANALYST

The Enterprise Security Policy and Standards Analyst is focused on the development and ongoing maintenance of Technology and Enterprise Security policies and standards for protecting the confidentiality, integrity, and availability of information at Comerica. The incumbent evaluates the need to establish new technology/information security standards based on risk evaluations, changes in threats, technology updates, business objectives, laws, and/or regulations. This will include monitoring new laws, regulations, and industry standards that may affect how technology and information security is managed at Comerica (e.g., GLBA, FFIEC standards, PCI standards, HIPAA, Privacy laws).
The incumbent will assess gaps with Comerica’s existing technology/information security controls, policies, and standards and make recommendations to management as needed for new and updated standards. This will require working directly with subject matter experts from Enterprise Security, Technology, Enterprise Risk, Legal and other business units within the bank to further assist in the recommendations and document these requirements.
This role will be responsible for interpreting, analyzing, developing, and writing policies and standards from a business and technical perspective. This includes managing the entire lifecycle of which consists of planning research, drafting, approval and publication, and communication of the policies and standards.

POSITION QUALIFICATIONS:

  • Bachelor’s Degree from an accredited university in Information Management, Information Governance, Risk Management, Computer Science, or other relevant disciplines OR HS/GED with 5 years progressive relevant experience
  • 5 years of experience in policy interpretation and development
  • 5 years of experience in the development and analysis of industry best practices
  • 5 years of experience with IT governance, compliance, risk, and audit programs
  • 5 years of experience with GLBA, FFIEC standards, PCI standards, HIPAA, Privacy laws or similar compliance activities such as SOX, PCI, etc.
  • 3 years of experience supporting audits and assessments
  • 2 years of experience in IT security control development, control testing, risk remediation, and reporting
  • 2 years of experience with one or more of the following: MS Office, Qualys, SIEM, Archer, ServiceNow
Responsibilities

Loading...