You are on page 1of 2

Job Specification

Job Title: Information


Security, Risk, and
Governance Analyst-Mid
career

Function: IT - IRC

FLSA Status:

Role: Professional

Job Code:

Job Family: Information


Security, Risk & Compliance
Management

Grade:

Last Updated: 9/03/2014

Job Summary
This role supports the programs of ITS (Information Technology Services) Governance Risk & Compliance which include
risk management, compliance management, audits & assessments, client inquiries, and security awareness. This position
is specifically responsible for working with Information Security Risk & Compliance (IRC), ITS and other Firm leaders to
understand technology and operational risks related to our internal technology solutions and to ensure that the
appropriate controls are in place to address those risks as well as to comply with relevant laws, regulations, and industry
standards. This role will have a special emphasis on SAP governance and compliance.
Illustrative Duties and Responsibilities
1.

Assist with SAP governance and compliance activities.

2.

Helps identify potential security exposures that currently exist or may pose potential threats to Deloittes networks
or systems. Notifies leadership of potential or existing threats and assists in the development of risk mitigating
strategies. Process Policy and Standard Exceptions once acceptable mitigating controls have been defined and
documented. Maintains database with exception documentation, including mitigating security controls, necessary
approvals, and exception duration.

Assist with IT security practices through the operation and continual monitoring of specific business processes and
reporting on identified metrics to IRC and ITS leadership on a timely basis.

4.

Identifies task owners and negotiate dates for remediation to be complete; tracks progress on remediation of
identified risks and vulnerabilities and provide appropriate reporting to all constituents.

5.

Assist with development and implementation of security policies and procedures (e.g., user log-on and
authentication rules, security auditing procedures, etc.).

6.

Helps implement Security Awareness activities that align with the organizations strategy.

7.

Assist with development and implementation of compliance verification and audit preparedness activities.

8.

Provides project support for assigned security function. This includes assisting with security design and preparing
security documentation for internal process as well as internal/external audits and assessments.

9.

Performs other job-related duties as assigned.

Required Technical Skills


Strong background in audits and compliance. Good knowledge of SAP security concept is required, including
understanding user, role, and authorization approach pertaining to ERP, BI, Portal, HANA and SAP GRC Tool
environments. Prior experience in SAP Security implementations would be a plus. In addition, one or more specialties in
the following applications or classes of tools would be a plus: Microsoft Office skills, industry security frameworks,
Deloittes policies, standards, and security practices, operations, and design.
Required Licenses, Certifications, and Other Requirements

Job Specification
Education & Experience
Bachelors Degree; 3 years of relevant experience

Please see Career Guide for Leveling Descriptors/Behavioral Competencies (Currently under revision/development as
part of this project. This will cover areas such as Leadership, Communications, Work Complexity, Problem Solving, etc. )

You might also like