Governance Analyst II
Listed on 2026-09-13
-
IT/Tech
Information Security & Data Protection, Cybersecurity
Under the direction of the Director, Information Security Operations, the Governance Analyst II is responsible for the development, implementation, and maintenance of policies, standards, baselines, and guidelines to safeguard enterprise assets and ensure the confidentiality, integrity, and availability of information. This position plays a key role in enhancing the enterprise's security posture by evaluating and improving existing security measures, while supporting effective data protection and privacy practices in alignment with applicable regulations and business needs.
This role leads assessments of current practices, identifies gaps, and recommends improvements in alignment with industry standards and emerging risks. The position involves complex projects, coordination with cross-functional teams, and providing guidance on security governance, risk, and compliance, including consideration of privacy principles and regulatory obligations where applicable. This role also assists in the strategic planning of the Information Security program, ensuring its effectiveness through continuous monitoring and reporting to Information Security leadership.
ESSENTIAL DUTIES AND RESPONSIBILITIES- Responsible for creating and reviewing security policies and standards, supporting the management process including regular updates to process flow narratives. Ensures alignment with business objectives, security frameworks, and data protection/privacy requirements where applicable.
- Leads annual Payment Card Industry (PCI) efforts, including tracking remediation of control gaps and escalating critical issues to senior management. Acts as a cross-functional lead to support PCI compliance objectives and ensure readiness for assessments and deliverables, including proper handling of sensitive and regulated data.
- Engages with business units to identify risks and track mitigation plans. Assesses risk management tools, techniques, and procedures to enhance enterprise capabilities, including risks related to the collection, use, and protection of sensitive and personal data.
- Drives the development of metrics that inform executive decision-making for the Information Security risk management reporting dashboard.
- Leverage specialized knowledge to enhance project and operational decisions, and explain policies, standards, practices, and procedures of the job area/department to others within the enterprise.
- Assist in vendor risk management efforts by assisting in vendor intake and review process.
- Contribute to training and awareness initiatives with functional leaders, team leaders, and system owners.
- Performs other duties as assigned to support the efficient operation of the department.
Bachelor's degree in information security, technology, statistics, mathematics, or related field required.
Minimum four (4) years of experience in documentation, procedures and/or policies of information technology, information systems, risk management, controls audit, vendor management, data privacy or information security required.
Experience with Casino and Tribal government technology and security goals strongly preferred.
Experience with the following preferred:
- Applied knowledge of regulatory requirements and industry frameworks (e.g., NIST CSF, ISO 27001, PCI DSS, CCPA/CPRA) and their translation into controls and policies
- Experience in developing and maintaining policy architecture, including standards, baselines, and procedures
- Hands-on experience with GRC platforms to manage risk registers, control libraries, assessments, and remediation tracking
- Experience supporting audits, compliance assessments, and control validation activities
Related, relevant, and/or direct experience may be considered in lieu of minimum educational requirements indicated above.
KNOWLEDGE,SKILLS AND ABILITIES
(KSA)
- Must have strong communication and presentation skills.
- Must understand the value of standards, policy and procedures, operational effectiveness, and high availability.
At the discretion of the San Manuel Tribal Gaming Commission, you may be required to obtain and maintain a gaming license.
Driving ResponsibilitiesRole requires regular commuting between locations. A valid driver's license and vehicle insurance with minimum liability limits is required. Role will not operate or drive Tribe-owned vehicles or patron vehicles.
PHYSICAL REQUIREMENTS / WORKING CONDITIONS - ENVIRONMENT- The physical demands and…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).