Class Code:
AF40
General Nature of Work

Manages and coordinates professional work examining, evaluating, and/or monitoring conformity with laws, regulations, privacy or other business standards. Supervises others in licensure and permit compliance activities.

Guidelines for Class Use/Distinguishing Characteristics

This class is intended for advanced-level management of professional compliance activities in a state agency. May manage compliance activities in a unit or department. Manages compliance activities of considerable complexity in a larger state agency or directs compliance activities in a smaller state agency.

Examples of Work

Works with management to develop and implement a governance, risk, and compliance (GRC) strategy that aligns the business, information technology and governance domains. Plans, organizes and directs regulatory enforcement activities to ensure that all applicable statutes, rules, and regulations are met. Provides mentorship, guidance, and relevant technical training to other Information security staff and other departments. Assesses the maturity of existing discrete compliance and risk management programs to support scope definition of the GRC program. Assists in the vendor selection process and development of the agency’s GRC platform. Work with Information security and other staff to establish processes, standards and baseline thresholds for measurement, monitoring, reporting, mitigation and remediation of identified risks. Monitors and suggests improvements to the GRC program. Understands the agency’s response plan for risks and threats, and supports the remediation and response process by reporting necessary information and materials to the agency’s management. Collaborates across the agency to facilitate proactive alignment between internal and external security requirements and processes and technology to administer GRC . Performs research in GRC technology, processes updates, and best practices, and advises management on adoption to improve GRC capabilities. Develops reports and dashboards to present the level of controls compliance and the current IT risk posture.

Knowledge, Skills and Abilities

Knowledge of applicable internal and/or external regulatory policies, standards, procedures and controls. Knowledge of governance, risk and compliance (GRC) program management. Understanding of risk assessment process, monitoring, and reporting.

Minimum Requirements

A bachelor’s degree and relevant experience

Fed Category:
E2
Band:
09
Salary:
Minimum:
$83,219.00
Midpoint:
$118,596.00
Maximum:
$153,973.00
BACK