×
Register Here to Apply for Jobs or Post Jobs. X

Governance Analyst III

Job in Highland, San Bernardino County, California, 92346, USA
Listing for: Sanmanuel Nsn
Full Time position
Listed on 2026-07-24
Job specializations:
  • IT/Tech
    Information Security & Data Protection, Cybersecurity
Salary/Wage Range or Industry Benchmark: 120000 - 150000 USD Yearly USD 120000.00 150000.00 YEAR
Job Description & How to Apply Below
## Governance Analyst IIIApplylocations:
Highland, CAtime type:
Full time posted on:
Posted Todayjob requisition :
R0017399

Under the direction of the Director, Information Security Operations, the Governance Analyst III is responsible for the strategic oversight and leadership of the enterprise's information security and data privacy governance framework. This senior-level position focuses on the development, implementation, and continuous improvement of comprehensive security and privacy policies, standards, baselines, and guidelines to protect enterprise assets, safeguard sensitive and personal data, and ensure the confidentiality, integrity, availability, and appropriate use of information in compliance with applicable privacy regulations.
This role leads high-impact security and privacy initiatives, conducts advanced risk and privacy impact assessments, and drives the adoption of leading practices across the organization. This role requires a deep understanding of information security frameworks, privacy principles (e.g., data minimization, purpose limitation, and protection by design), industry standards, emerging threats, and regulatory requirements (e.g., PCI DSS, CCPA/CPRA, and other applicable privacy laws).
** ESSENTIAL DUTIES AND RESPONSIBILITIES
** 1. Regularly mentors and provides guidance to team members in the development of security and privacy policies, standards, and procedures, ensuring alignment with regulatory requirements and business objectives. Coaches staff on integrating privacy-by-design principles into governance processes and control development.
2. Leads all Payment Card Industry (PCI) efforts, including tracking remediation of control gaps and escalating critical issues to senior management. Acts as a cross-functional lead to ensure compliance readiness. Ensure that cardholder data and other sensitive personal information are handled in accordance with privacy and data protection requirements.
3. Engage with business units to identify security and privacy risks, facilitating risk assessments including Privacy Impact Assessments (PIAs) and Data Protection Impact Assessments (DPIAs) where applicable. Tracks mitigation plans and enhances enterprise risk management capabilities.
4. Leads vendor risk management efforts, including vendor intake and review process.
5. Develops and enhances metrics for Information Security and Privacy risk reporting dashboards, including key risk indicators (KRIs) related to data protection, regulatory compliance, and incident trends that inform executive decision-making and prioritize remediation efforts based on business impact.
6. Leverage specialized knowledge to guide project and operational decisions, clearly communicating security and privacy policies, regulatory requirements, and best practices to stakeholders across the enterprise.
7. Contribute to training and awareness initiatives, promoting security and privacy awareness, secure data handling practices, and compliance obligations among functional leaders, system owners, and employees.
8. Performs other duties as assigned to support the efficient operation of the department, including support for privacy incident response, breach notification coordination, and regulatory inquiries as needed.
** EDUCATIONAL, EXPERIENCE AND QUALIFICATIONS
*** Bachelor’s degree in information security, technology, statistics, mathematics, or related field required.
* Minimum six (6) years of experience in documentation, procedures and/or policies of information technology, information systems, risk management, controls audit, vendor management, data privacy, or information security required.
* Experience with Casino and Tribal government technology and security goals strongly preferred.
* Experience with the following preferred:  + Expertise in regulatory and legal requirements, with the ability to interpret and operationalize laws and standards (e.g., PCI DSS, privacy regulations, and enterprise frameworks)  + Design and governance of enterprise policy architecture, including policy hierarchy, exception management, and alignment to business strategy  + Advanced experience with GRC platforms, including…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary