Information Security Compliance Analyst - Richmond, VA
Richmond, VA, US, 23222
Brightstar is an innovative, forward-thinking global leader in lottery that builds on our renowned expertise in delivering secure technology and producing reliable, comprehensive solutions for our customers. As a premier pure play global lottery company, our best-in-class lottery operations, retail and digital solutions, and award-winning lottery games enable our customers to achieve their goals, fulfill player needs and distribute meaningful benefits to communities. Brightstar has a well-established local presence and is a trusted partner to governments and regulators around the world, creating value by adhering to the highest standards of service, integrity, and responsibility. Brightstar has approximately 6,000 employees. For more information, please visit www.brightstarlottery.com.
Overview
You develop and execute security controls, defenses, and countermeasures to intercept and prevent internal or external attacks targeting company email, data, e-commerce, and web-based systems. You research attempted or successful efforts to compromise systems security and design effective countermeasures. You maintain hardware, software, and network firewalls and encryption protocols. You administer security policies that control physical and virtual access to systems. You provide clear, timely information to management regarding the business impact of theft, destruction, alteration, or denial of access to information and systems.
Responsibilities
- Monitor the operating environment for compliance with SOC 2+ VA SEC 530 controls, track deviations and remediation activities in a Plan of Action & Milestones (POA&M).
- Coordinate security incident handling, liaise with the Global Cybersecurity Incident Response Team towards containment, root cause determination, and updates to the POA&M.
- Coordinate preparation and execution of external audit activities to ensure evidence completeness, accuracy, and appropriateness. Work closely with the external auditors to ensure scope and testing results are fair and accurate.
- Track to remediation any audit findings and vulnerabilities documented in the POA&M and collaborate with Infrastructure, Application, and Operations teams to design and deploy countermeasures and security enhancements.
- Prepare concise reports and briefings that translate technical findings into business impact and recommended actions.
Qualifications
- Solid understanding of cybersecurity compliance scoping methodologies, control environments, and evidence management.
- Hands-on experience implementing and coordinating with technical teams, the implementation security controls, across a variety of technical, operational, and personnel requirements.
- Ability to investigate incidents, research vulnerabilities, correlate logs and alerts, and clearly communicate findings and recommended actions to technical teams.
- Bachelor’s degree in related field or experience in lieu of a degree
- 2+ years of dedicated related security operations, compliance, or incident response experience required.
- Equivalent military or directly relevant work experience considered.
- Exposure to SOC 2 audits, control testing, evidence collection, and remediation tracking.
- Familiarity with NIST 800-53 control families and mapping to enterprise policies.
- Experience producing executive-level compliance or risk dashboards.
- Professional certifications aligned to information security compliance and governance, such as CISA, CRISC, CAP (NIST RMF), or similar credentials, preferred.
Success Profile
• Leading Complexity
• Leading People
• Leading the Business
• Leading Self
#LI-NA1 #LI-HYBRID
At Brightstar, we consider a wide range of factors in determining compensation, including background, skills, experience, and work location. These factors can cause your compensation to vary. The estimated starting compensation range is $55,631 - $98,467. The actual pay offered may end up being higher or lower. The Company will comply with all local pay requirements and collective bargaining agreements, where applicable.
Base pay is only one part of our Total Rewards program. Sales roles may be eligible for commission payments, while other roles are eligible for discretionary bonuses. In addition, we offer employees a 401(k) Savings Plan with Company contributions, health, dental, and vision insurance, life, accident, and disability insurance, tuition reimbursement, paid time off, wellness programs, and identity theft insurance. Note: programs are subject to eligibility requirements.
All Brightstar employees have a role in information security. Annual training will be assigned and required as appropriate.
Nearest Major Market: Richmond