- Company Name
- Sandisk
- Job Title
- Information Security Analyst 4
- Job Description
-
**Information Security Analyst 4**
**Role Summary**
Advances Information Security Governance, Risk Management, and Compliance (GRC) with a focus on Generative AI (GenAI) security risk assessment and governance. Leads responsible GenAI initiatives, mitigates technical and regulatory risks, and ensures alignment with organizational security standards.
**Expectations**
Operationalize enterprise-wide GenAI governance, de-risk high-risk use cases, implement risk management frameworks (e.g., ISO 27001, NIST CSF 2.0), and integrate security practices into cross-functional workflows.
**Key Responsibilities**
- Manage Responsible GenAI program intake, coordination, and vendor/platform use-case assessments.
- Conduct technical risk assessments for GenAI, evaluating data sensitivity, access controls, and model interfaces. Recommend mitigation strategies.
- Collaborate with Legal, procurement, and IT to enforce privacy, licensing, and governance requirements.
- Develop and refine GenAI governance policies, risk management frameworks, and procedures.
- Support audits and compliance by generating risk metrics and aligning with regulatory standards.
- Embed enterprise risk management into procurement, vendor, and IT workflows.
**Required Skills**
- Expertise in GRC frameworks (e.g., ISO 27001, NIST CSF 2.0), risk assessments, and SANS/OWASP/CSA AI security methodologies.
- Knowledge of GenAI risks (e.g., prompt injection, data leakage) and responsible AI principles.
- Experience with AI governance standards (e.g., ISO 42001/42005, NIST AI RMF).
- Strong cross-functional collaboration and stakeholder communication skills.
**Required Education & Certifications**
- Bachelor’s degree in Information Security, Computer Science, or related field (4+ years GRC/Information Security experience).
- Certifications: CISSP, CISM, CRISC, GSNA (or equivalent) preferred. Technical certifications (GCIH, GPEN, CEH, OSCP) desirable.