Mondelēz International logo
Mondelēz International

We’re a house of incredible brands providing people with the right snack, for the right moment, made the right way.

Sr Analyst, Governance, Risk & Compliance (GRC), Information Security

Security AnalystSecurity AnalystFull TimeRemoteTeam 10,001+Since 2012H1B No SponsorCompany SiteLinkedIn

Location

United States

Posted

10 days ago

Salary

Not specified

risk assessmentrisk managementcompliance testingGRC toolsArcherCISNISTpolicy managementvulnerability managementaccess management

Job Description

Job Description

Are You Ready to Make It Happen at Mondelēz International?

Join our Mission to Lead the Future of Snacking. Make It Uniquely Yours.

As an individual contributor, the successful candidate will be proficient at managing risk assessments of both third parties and internal technologies. In addition, the candidate will be performing compliance activities related to technology assurance areas around access management, vulnerability management and configuration management. Candidate will also demonstrate ability and experience in governance related activities including administrative management of risk and control registers as well as policies and standards.

How you will contribute

Risk Management Responsibilities

  • Execute risk assessment testing supporting the Risk Manager.
  • Document risk assessment results.
  • Support Risk Manager in drafting risk assessment reports.
  • Perform administrative management of risk register (additions/editions/deletions, etc).
  • Document risk acceptance/exemptions that have been approved per the program.
  • Manage quarterly/annual review of risk acceptance/exceptions.
  • Manage risk assessment results in relevant dashboards.
  • Document Issues and Remediation activities for all exceptions noted during risk assessments.

 

Compliance Responsibilities

  • Perform quarterly compliance assurance testing.
  • Document compliance testing results.
  • Maintain Management Action Plan (MAP) catalog with due dates.
  • Manage monthly audit MAPs. Includes the timely communication of open MAPs an escalation as needed of risks to completing MAPs at their agreed delivery dates.
  • Perform administrative activities in GRC Solution for compliance related activities.
  • Provide administrative support for ad-hoc external audits.
  • Provide administrative support for internal audits.
  • Support compliance program reporting activities.
     

Requirements

  • 3 years in Information Security field, with at least 2 years working in GRC.
  • Experience with GRC tools (e.g., Archer).
  • Knowledge of security concepts and methodologies such as risk assessments, risk & controls, policies & standards, enterprise security strategies, network, and cloud security.
  • Knowledge of security frameworks such as CIS and NIST.
  • Excellent written and verbal communications skills, including presentational skills and able to clearly communicate issues to management and other key stakeholders.

No Relocation support available

Business Unit Summary

At Mondelēz International, our purpose is to empower people to snack right by offering the right snack, for the right moment, made the right way. That means delivering a broad range of delicious, high-quality snacks that nourish life's moments, made with sustainable ingredients and packaging that consumers can feel good about.

We have a rich portfolio of strong brands globally and locally including many household names such as Oreo, belVita and LU biscuits; Cadbury Dairy Milk, Milka and Toblerone chocolate; Sour Patch Kids candy and Trident gum. We are proud to hold the top position globally in biscuits, chocolate and candy and the second top position in gum.

Our 80,000 makers and bakers are located in more than 80 countries and we sell our products in over 150 countries around the world. Our people are energized for growth and critical to us living our purpose and values. We are a diverse community that can make things happen—and happen fast.

Mondelēz International is an equal opportunity employer and all qualified applicants will receive consideration for employment without regard to race, color, religion, gender, sexual orientation or preference, gender identity, national origin, disability status, protected veteran status, or any other characteristic protected by law.

Job Type

Regular

Information Security

Technology & Digital

Related Job Pages

More Security Analyst Jobs

CrowdStrike logo

Security Advisor I, Falcon Complete (Remote)

CrowdStrike

CrowdStrike has redefined security with the world’s most advanced cloud-native platform that protects and enables the people, processes and technologies that drive modern enterprise. Tested and proven, the world's largest organizations trust CrowdStrike to stop breaches with unparalleled protection against the most sophisticated cyberattacks. The CrowdStrike culture has been built upon our Core Values since the day we began. We are Fanatical About the Customer, Relentlessly Focused on Innovation and believe that our Limitless Passion drives Unlimited Potential for every CrowdStriker. As a purpose-built remote-first company, we believe cultivating a connected culture for every employee, no matter where they are in the world, is a key ingredient in building a high-performing, diverse team. We don’t have a mission statement. We’re on a mission—to stop breaches. Ready to join a mission that matters?

Security Analyst10 days ago
Full TimeRemoteTeam 5,001-10,000Since 2011H1B Sponsor

The Security Advisor will assess customer Falcon environments against Falcon Complete standards, providing recommendations for improved security posture and creating remediation plans. This role involves direct customer contact to address misalignments, documenting issues, resolving them according to SLAs, and partnering with internal teams for customer satisfaction.

CybersecurityIncident ResponseThreat DetectionWindowsLinuxmacOSSIEMUEBAMDRXDRISO 27001NIST Cybersecurity FrameworkCIS Critical SecurityPCI DSSMITRE ATT&CK
United States
$85K - $120K / year
Full TimeRemoteTeam 1,001-5,000

Faculty are responsible for facilitating student learning by teaching courses and developing course syllabi and lesson plans in accordance with Company requirements. Instructors must organize, revise, and update all course materials, utilizing appropriate online technologies and providing timely feedback on assignments and exams.

CybersecurityIncident ResponsePenetration TestingCISSPCISMCompTIA Security+CySA+CASP+
United States
$1.5K - $2.7K / year
Rhymetec logo

Cyber Security Analyst

Rhymetec

Premium cybersecurity, compliance and privacy services for your business, because security is an essential.

Security Analyst10 days ago
Full TimeRemoteTeam 11-50Since 2015

The Cyber Security Analyst will architect, develop, and implement solutions for clients to achieve, manage, and measure security metrics and compliance requirements, working closely with the team to deliver security objectives. Responsibilities include configuring cloud monitoring alarms, setting up security applications, conducting internal audits, leading incident response processes, and translating various compliance controls into actionable client items.

SOC 2ISO 27001CMMCHIPAAGDPRNIST 800-53AWSAzureGCPDatadogIntrusion Detection SystemsJamfJumpcloudMicrosoft Endpoint ManagerHexnodeCompliance MonitoringRisk AssessmentIncident ResponseBusiness ContinuityDisaster RecoveryVulnerability ManagementAccess ReviewsSaaS SecuritySecurity QuestionnairesPolicy DraftingEvidence CollectionAuditor EngagementCloud SecurityDevOpsIaaS
New York
$53 - $800
BioCatch logo

Threat Analyst

BioCatch

We fight to make banking safer every day.

Security Analyst10 days ago
Full TimeRemoteTeam 201-500Since 2011

The Threat Analyst will maintain strong relationships with customers, providing subject matter expertise to maximize value from Company solutions and drive fraud detection rates while minimizing friction for genuine users. Key tasks include educating customers, deploying tactical rules for acute attacks, and acting as the voice of the customer to influence internal product strategy.

SQLPythonRData AnalysisStatisticsFraud DetectionBehavioral AnalyticsPresentation SkillsCustomer Engagement
United States
$110K - $135K / year