It Grc Analyst

State Farm State Farm · Insurance · Bloomington, IL +3 · Technology and UX

The IT GRC Analyst role focuses on ensuring Payment Card Industry Data Security Standard (PCI DSS) compliance for State Farm's systems. This involves assessing, validating, and delivering compliance for in-scope people, processes, and technologies. The role requires hands-on experience with ServiceNow GRC modules, JavaScript, HTML/CSS, and integrations, as well as a strong background in information security and governance, risk, and compliance. Intermediate knowledge of various security domains and PCI DSS is essential. The role also involves collaborating with business and technology teams to address compliance issues and staying current with evolving security topics.

What you'd actually do

  1. Applies defined PCI DSS scoping criteria.
  2. PCI ISA collects and reviews evidence of compliance to validate PCI DSS requirements are met.
  3. Supports the completion of assigned tasks for the annual PCI DSS Report on Compliance.
  4. Drives necessary system and process updates in alignment with PCI DSS scoping & requirements.
  5. Facilitates interaction between the business partner(s), product teams and the PCI C&C Team.

Skills

Required

  • ServiceNow experience (developer, implementation specialist, GRC technical analyst/architect)
  • ServiceNow GRC related modules
  • JavaScript
  • HTML/CSS
  • REST/SOAP integrations
  • ServiceNow UI Actions
  • Technology and/or information security background and/or governance, risk & compliance
  • Infrastructure (physical, virtual & Cloud)
  • Network segmentation
  • Operating system security
  • Encryption and key management
  • Tokenization
  • Anti-virus and malware
  • Secure system development
  • Identity and access management
  • Vulnerability management
  • Physical access controls
  • Penetration testing
  • File integrity monitoring
  • Logging
  • Risk assessments/reviews
  • Information security policy
  • Ability to analyze, collaborate & present solutions (both verbal & written)
  • Intermediate knowledge of PCI DSS compliance & security frameworks
  • Work well under pressure to identify and problem-solve complex situations

Nice to have

  • Security+
  • CISSP
  • GSEC
  • AWS
  • Azure
  • Microsoft
  • CISA
  • CISM
  • PCI ISA
  • PCI QSA
  • Motivated, self-starter
  • Strong communicator
  • Team & individual contributor
  • Worked on a team across multiple time zones

What the JD emphasized

  • Intermediate knowledge of PCI DSS compliance & security frameworks to understand & validate the requirements of protecting customer's payment card data.
  • Work well under pressure to identify and problem-solve complex situations across multiple customer channels and scenarios related to customer cardholder data and applicable PCI DSS Compliance.