Kura Sushi USA is a publicly traded U.S. company established in 2008 as a subsidiary of Kura Sushi, Inc. We are an innovative and tech interactive Japanese restaurant chain serving up the ultimate eater-tainment dining experience with a combination of premium ingredients, advanced technology, and affordable prices to create a one-of-a-kind revolving sushi dining experience.
Come join the Kura Krew! We have and exciting opportunity to join our growing team.
This role is a hybrid role. The selected candidate must be able to come to the office in Irvine, CA on in office days and as needed to carry out necessary functions of the role.
The GRC (Governance Risk & Compliance)-Senior Security Analyst will be responsible for safeguarding Kura’s IT (Information Technology) infrastructure by monitoring security systems, conducting vulnerability assessments, and responding to security incidents under the direction of the Integrated GRC Senior Manager. This includes but not limited to monitoring activity throughout the Kura Sushi USA (“Kura”) environments and responding to security alerts in real time; Analyzing system logs, intrusion detection alerts, and suspicious activity; conducting vulnerability assessments and penetration testing; providing guidance on firewall security configurations, Intrusion Prevention System (IPS)/Intrusion Detection System (IDS), and endpoint protection systems; Investigating and documenting security incidents, including root cause analysis; developing and enforcing security and data governance via policies, procedures, and compliance standards; collaborating with ACAS and IT teams to strengthen security controls; and provide cybersecurity training and awareness to staff.
DUTIES:
Essential:
Key responsibilities include but not limited to:
• Forensic Analysis: Conduct forensic analysis of Security Information Event Management (SIEM), environment telemetry or log events to identify security incidents and vulnerabilities.
• Security Solutions: Evaluate, recommend, and implement security solutions to enhance core security capabilities, including access management and network security.
• Incident Response: Monitor security networks for breaches, respond to incidents, and conduct thorough investigations to mitigate risks.
• Vulnerability Assessments: Perform periodic vulnerability assessments and threat hunting to identify and address potential security weaknesses.
• Collaboration: Work closely with IT teams to ensure secure system configurations and compliance with security policies.
• Reporting: Prepare regular security reports for management, detailing findings and recommendations for improvements.
• Training: Conduct security awareness training for staff to promote a culture of security within the organization.
• Other duties as directed by the Integrated GRC Senior Manager and/or the VP of Audit, Compliance and Advisory Services.
Security Regulatory Compliance:
1. Ensures the organization complies with all applicable security laws, regulations, and internal security policies. as it relates to security. This includes monitoring business operations and reporting any infractions.
2. Partners with other members of the GRC team, Head of Department (HOD) of IT and other members of management where/when applicable.
3. Policy Development: Create, modify, and implement enterprise-wide security policies and procedures.
4. Risk Management: Develop risk management strategies and conduct regular assessments to identify areas of potential non-compliance.
5. Training and Education: Design and deliver training programs for employees to ensure they understand compliance requirements and the importance of adhering to them.
6. Liaison with Regulatory Bodies: Act as the point of contact between the organization and regulatory agencies, handling inspections and assessments.
7. Incident Management: Perform assigned duties within the incident response plan. Investigate compliance breaches, conduct root cause analysis, and implement corrective actions to prevent recurrence.
8. Provides regular reports to the VP of ACAS and applicable senior management security posture.
9. Conducts annual security risk assessments
10. Reviews contracts containing Personal Identifiable Information (PII) and system components to ensure Data Processing Agreements (DPAs) are issued to 3rd party vendors.
11. Performs security assessments/reviews, monitors compliance deficiencies/remediation efforts, conducting/leading security investigations.
Security Governance, Risk and Compliance (GRC)
1. Provides guidance to other members of ACAS Information Technology management in building a strong IT/Security compliant environment including guiding and mentoring direct and indirect team members.
2. Providing guidance and facilitating coordination with cross-functional members in implementing processes such as Security and IT governance, risk, and compliance activities to automate and facilitate continuous monitoring of information security controls, exceptions, risks, and testing.
3. Contributes to the development and implementation of the Data Governance program, as directed by the Integrated GRC Senior Manager.
4. Liaise with GRC/Internal Audit and IT members to ensure appropriate controls over IT/Security design while working with the IT management and cross-functional members to facilitate operational efficiencies and effectiveness relating to:
• Systems Development Life Cycle (SDLC)-New and existing systems
• Cyber Security, Data Security management
• Artificial Intelligence (AI)
• Identity & Access Management (IAM) e.g., privileged access, User Access Reviews (UARs)
• Security System configurations, e.g., provisioning and deprovisioning
• System and Organizational Controls (SOC) Evaluations
• Other security activities
5. Develops reporting metrics, dashboards, and obtains and retains evidence and provides to the Integrated GRC Senior Manager, VP of ACAS or other leadership, as needed for review.
6. Builds and enhances the organization’s cybersecurity strategy to proactively identify/address relevant security gaps, ensure compliance with internal policies and external regulatory requirements, and improving Kura’s overall security posture and program.
7. Collaborates with cross-functional business and the information technology team to ensure security strategies and initiatives align with business objectives.
8. Provides guidance to the other members of ACAS and the IT team in developing the system-wide information security compliance program, ensuring IT activities, processes, and procedures meet defined requirements, security policies, and regulations.
9. Train and mentors other ACAS GRC members, who will at a minimum, facilitate and monitor compliance related to the security and change management processes.
10. Facilitation and the coordination, development and implementation of security awareness compliance programs and education while partnering with the IT Team.
11. Facilitates, guides coordinates, and partners with other ACAS-GRC members during the systems development life cycle activities and new processes to ensure security components are properly implemented.
12. Evaluates IT control/process deficiencies issued by the Internal Audit team and provides remediation plans to the Internal Audit Team for recommended design improvements while partnering with the GRC and IT team on remediation plan.
13. Facilitates and provides guidance to the IT HOD in the development of IT policies and procedures and ensures alignment with company goals and security regulatory requirements.
14. Presents issues of IT Security and data security non-compliance to the Integrated GRC Senior Manager and the VP of ACAS
15. Attends continuing professional education to keep abreast of security and technology regulations, emerging risks and strategies.
16. Presents progress and initiatives on a monthly basis based on annual plan to the Integrated GRC Senior Manager and the VP of ACAS
17. Perform other projects assigned by the Integrated GRC Senior Manager and VP of ACAS
Non-Essential:
1. Seeks on-going improvement or more cost- efficient and effective solutions in work processes of the department.
2. Researches and develops resources that create timely and efficient workflow.
3. Performs special projects and other miscellaneous duties as assigned by the Integrated GRC Senior Manager or VP of ACAS.
4. Follows up to complete any assigned work.
5. Maintains high ethical standards in the workplace.
6. Reports all irregular issues and problems to supervisor.
7. Maintains good communication with all Kura team members and outside parties.
8. Complies and maintains confidentiality of all company policies and procedures.
9. Maintains a clean and safe working area.
SKILLS AND QUALIFICATIONS:
To perform this job successfully, an individual must be able to perform each essential duty satisfactorily. The requirements listed below are representative of the knowledge, skill, and/or ability required. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.
Education/Experience:
1. A bachelor’s degree in Cybersecurity, Computer Science, Information Technology, or a related field
2. Possess relevant certifications such as CISSP or CISM, GIAC or CEH
3. At least 5 years of experience in cybersecurity or IT security role, with a strong understanding of security frameworks and standards such as (NIST, ISO 27001, CIS)
4. Governance, risk and compliance experience from Big 4 consulting firm or fortune 500 company.
5. Hands-on experience in incident response and forensic analysis
6. Knowledge of cloud security (Amazon Web Services (AWS), Azure, or Google Cloud Platform (GCP) environments)
7. Familiarity with threat intelligence platforms and malware analysis
8. Experience with regulatory compliance (CCPA, PCI DSS, SOX, GDPR)
9. Proficient with Optro (formerly AuditBoard)-Cross Comply and various security tools.
10. Proficiency with SIEM tools such as Splunk, Google Security Operations, QRadar, or ArcSight
11. Knowledge of firewalls, intrusion detection/prevention systems, and endpoint security
12. Knowledge of cloud/data security platforms such as Netskope, CheckPoint, Zscaler
13. Knowledge of data security posture management (DSPM) platforms such as BigID and MS Purview
14. Ability to conduct vulnerability assessments and penetration testing
15. Basic scripting skills in Python, PowerShell, or Bash
16. Strong technical background.
17. Excellent leadership and people management skills.
18. Skills in documenting security, risk, and regulatory compliance activities
19. Familiarity with security/technology auditing processes
20. Familiar with dashboard creation
21. Ability to critically think about issues, research, and develop solutions/options that can be shared with stakeholders.
22. Communicates confidently with executive management, corporate support personnel, cross-functional peers, and product/services providers at appropriate technical levels for each and liaises with Internal Audit to ensure appropriate IT General Controls (ITGCs). Demonstrates ability to articulate business cases for identified technology solutions.
23. Excellent analytical and troubleshooting skills.
24. Ability to work under pressure.
PAY RANGE: $90,000 - $95,000/yr. DOE
Kura Sushi USA is a publicly traded U.S. company established in 2008 as a subsidiary of Kura Sushi, Inc. We are an innovative and tech interactive Japanese restaurant chain serving up the ultimate eater-tainment dining experience with a combination of premium ingredients, advanced technology, and affordable prices to create a one-of-a-kind revolving sushi dining experience.
Come join the Kura Krew! We have and exciting opportunity to join our growing team.
This role is a hybrid role. The selected candidate must be able to come to the office in Irvine, CA on in office days and as needed to carry out necessary functions of the role.
The GRC (Governance Risk & Compliance)-Senior Security Analyst will be responsible for safeguarding Kura’s IT (Information Technology) infrastructure by monitoring security systems, conducting vulnerability assessments, and responding to security incidents under the direction of the Integrated GRC Senior Manager. This includes but not limited to monitoring activity throughout the Kura Sushi USA (“Kura”) environments and responding to security alerts in real time; Analyzing system logs, intrusion detection alerts, and suspicious activity; conducting vulnerability assessments and penetration testing; providing guidance on firewall security configurations, Intrusion Prevention System (IPS)/Intrusion Detection System (IDS), and endpoint protection systems; Investigating and documenting security incidents, including root cause analysis; developing and enforcing security and data governance via policies, procedures, and compliance standards; collaborating with ACAS and IT teams to strengthen security controls; and provide cybersecurity training and awareness to staff.
DUTIES:
Essential:
Key responsibilities include but not limited to:
• Forensic Analysis: Conduct forensic analysis of Security Information Event Management (SIEM), environment telemetry or log events to identify security incidents and vulnerabilities.
• Security Solutions: Evaluate, recommend, and implement security solutions to enhance core security capabilities, including access management and network security.
• Incident Response: Monitor security networks for breaches, respond to incidents, and conduct thorough investigations to mitigate risks.
• Vulnerability Assessments: Perform periodic vulnerability assessments and threat hunting to identify and address potential security weaknesses.
• Collaboration: Work closely with IT teams to ensure secure system configurations and compliance with security policies.
• Reporting: Prepare regular security reports for management, detailing findings and recommendations for improvements.
• Training: Conduct security awareness training for staff to promote a culture of security within the organization.
• Other duties as directed by the Integrated GRC Senior Manager and/or the VP of Audit, Compliance and Advisory Services.
Security Regulatory Compliance:
1. Ensures the organization complies with all applicable security laws, regulations, and internal security policies. as it relates to security. This includes monitoring business operations and reporting any infractions.
2. Partners with other members of the GRC team, Head of Department (HOD) of IT and other members of management where/when applicable.
3. Policy Development: Create, modify, and implement enterprise-wide security policies and procedures.
4. Risk Management: Develop risk management strategies and conduct regular assessments to identify areas of potential non-compliance.
5. Training and Education: Design and deliver training programs for employees to ensure they understand compliance requirements and the importance of adhering to them.
6. Liaison with Regulatory Bodies: Act as the point of contact between the organization and regulatory agencies, handling inspections and assessments.
7. Incident Management: Perform assigned duties within the incident response plan. Investigate compliance breaches, conduct root cause analysis, and implement corrective actions to prevent recurrence.
8. Provides regular reports to the VP of ACAS and applicable senior management security posture.
9. Conducts annual security risk assessments
10. Reviews contracts containing Personal Identifiable Information (PII) and system components to ensure Data Processing Agreements (DPAs) are issued to 3rd party vendors.
11. Performs security assessments/reviews, monitors compliance deficiencies/remediation efforts, conducting/leading security investigations.
Security Governance, Risk and Compliance (GRC)
1. Provides guidance to other members of ACAS Information Technology management in building a strong IT/Security compliant environment including guiding and mentoring direct and indirect team members.
2. Providing guidance and facilitating coordination with cross-functional members in implementing processes such as Security and IT governance, risk, and compliance activities to automate and facilitate continuous monitoring of information security controls, exceptions, risks, and testing.
3. Contributes to the development and implementation of the Data Governance program, as directed by the Integrated GRC Senior Manager.
4. Liaise with GRC/Internal Audit and IT members to ensure appropriate controls over IT/Security design while working with the IT management and cross-functional members to facilitate operational efficiencies and effectiveness relating to:
• Systems Development Life Cycle (SDLC)-New and existing systems
• Cyber Security, Data Security management
• Artificial Intelligence (AI)
• Identity & Access Management (IAM) e.g., privileged access, User Access Reviews (UARs)
• Security System configurations, e.g., provisioning and deprovisioning
• System and Organizational Controls (SOC) Evaluations
• Other security activities
5. Develops reporting metrics, dashboards, and obtains and retains evidence and provides to the Integrated GRC Senior Manager, VP of ACAS or other leadership, as needed for review.
6. Builds and enhances the organization’s cybersecurity strategy to proactively identify/address relevant security gaps, ensure compliance with internal policies and external regulatory requirements, and improving Kura’s overall security posture and program.
7. Collaborates with cross-functional business and the information technology team to ensure security strategies and initiatives align with business objectives.
8. Provides guidance to the other members of ACAS and the IT team in developing the system-wide information security compliance program, ensuring IT activities, processes, and procedures meet defined requirements, security policies, and regulations.
9. Train and mentors other ACAS GRC members, who will at a minimum, facilitate and monitor compliance related to the security and change management processes.
10. Facilitation and the coordination, development and implementation of security awareness compliance programs and education while partnering with the IT Team.
11. Facilitates, guides coordinates, and partners with other ACAS-GRC members during the systems development life cycle activities and new processes to ensure security components are properly implemented.
12. Evaluates IT control/process deficiencies issued by the Internal Audit team and provides remediation plans to the Internal Audit Team for recommended design improvements while partnering with the GRC and IT team on remediation plan.
13. Facilitates and provides guidance to the IT HOD in the development of IT policies and procedures and ensures alignment with company goals and security regulatory requirements.
14. Presents issues of IT Security and data security non-compliance to the Integrated GRC Senior Manager and the VP of ACAS
15. Attends continuing professional education to keep abreast of security and technology regulations, emerging risks and strategies.
16. Presents progress and initiatives on a monthly basis based on annual plan to the Integrated GRC Senior Manager and the VP of ACAS
17. Perform other projects assigned by the Integrated GRC Senior Manager and VP of ACAS
Non-Essential:
1. Seeks on-going improvement or more cost- efficient and effective solutions in work processes of the department.
2. Researches and develops resources that create timely and efficient workflow.
3. Performs special projects and other miscellaneous duties as assigned by the Integrated GRC Senior Manager or VP of ACAS.
4. Follows up to complete any assigned work.
5. Maintains high ethical standards in the workplace.
6. Reports all irregular issues and problems to supervisor.
7. Maintains good communication with all Kura team members and outside parties.
8. Complies and maintains confidentiality of all company policies and procedures.
9. Maintains a clean and safe working area.
SKILLS AND QUALIFICATIONS:
To perform this job successfully, an individual must be able to perform each essential duty satisfactorily. The requirements listed below are representative of the knowledge, skill, and/or ability required. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.
Education/Experience:
1. A bachelor’s degree in Cybersecurity, Computer Science, Information Technology, or a related field
2. Possess relevant certifications such as CISSP or CISM, GIAC or CEH
3. At least 5 years of experience in cybersecurity or IT security role, with a strong understanding of security frameworks and standards such as (NIST, ISO 27001, CIS)
4. Governance, risk and compliance experience from Big 4 consulting firm or fortune 500 company.
5. Hands-on experience in incident response and forensic analysis
6. Knowledge of cloud security (Amazon Web Services (AWS), Azure, or Google Cloud Platform (GCP) environments)
7. Familiarity with threat intelligence platforms and malware analysis
8. Experience with regulatory compliance (CCPA, PCI DSS, SOX, GDPR)
9. Proficient with Optro (formerly AuditBoard)-Cross Comply and various security tools.
10. Proficiency with SIEM tools such as Splunk, Google Security Operations, QRadar, or ArcSight
11. Knowledge of firewalls, intrusion detection/prevention systems, and endpoint security
12. Knowledge of cloud/data security platforms such as Netskope, CheckPoint, Zscaler
13. Knowledge of data security posture management (DSPM) platforms such as BigID and MS Purview
14. Ability to conduct vulnerability assessments and penetration testing
15. Basic scripting skills in Python, PowerShell, or Bash
16. Strong technical background.
17. Excellent leadership and people management skills.
18. Skills in documenting security, risk, and regulatory compliance activities
19. Familiarity with security/technology auditing processes
20. Familiar with dashboard creation
21. Ability to critically think about issues, research, and develop solutions/options that can be shared with stakeholders.
22. Communicates confidently with executive management, corporate support personnel, cross-functional peers, and product/services providers at appropriate technical levels for each and liaises with Internal Audit to ensure appropriate IT General Controls (ITGCs). Demonstrates ability to articulate business cases for identified technology solutions.
23. Excellent analytical and troubleshooting skills.
24. Ability to work under pressure.
PAY RANGE: $90,000 - $95,000/yr. DOE