About this role
About the Role The Principal Information Security Analyst will be a key member of Skyworks’ Information Security team, partnering with cross-functional groups to ensure appropriate physical, administrative and technical controls are operating effectively to protect Skyworks’ information resources. This role supports the strategy and execution of the Information Security program in partnership with senior management and may act as the subject matter expert across information security, privacy, and compliance. What You'll Do
- Oversee and maintain the organization’s privacy program, ensuring compliance with applicable data protection laws and regulations; create, update, and maintain the privacy data map for GDPR, CPRA, PIPL, and DPDP.
- Perform privacy impact assessments and security assessments as needed for different projects and systems.
- Educate users on privacy by design requirements when deploying new systems.
- Contribute to the continuous improvement of the Information Security risk management program, compliance initiatives, and overall security risk posture.
- Develop, maintain, and enforce Skyworks Information Security Policies, Standards, Guidelines, and other Information Security related documents.
- Assist with risk assessments to identify potential threats and vulnerabilities across the organization, analyzing their impact and likelihood of occurrence, and developing appropriate mitigations strategies.
- Collaborate with cross functional teams to collect evidence for customer audits and policy frameworks such as ISO27001, CMMC, TISAX, GDPR, CCPA.
- Maintain the security risk register and track the progress of remediation efforts.
- Update monthly metrics and dashboards that measure and showcase the maturity progression of Skyworks Information Security program.
- Provide cybersecurity expertise/consulting to teams and management.
- Perform other security related duties and assignments, as needed, to support the program.
- Maintain an up-to-date inventory of third-party vendors and their associated risk profiles.
- Assess and monitor new and existing third-party vendors to ensure they meet security and compliance requirements.
- Issue corrective/improvement action requests and track vendor’s progress through closure.
- Utilize security ratings services to continuously evaluate the security posture of third-party vendors.
- Manage the information security awareness programs which include security awareness training, phishing campaigns, security newsletters and publications.
- Promote a culture of security awareness throughout the organization.
- Identify creative security campaigns for Cybersecurity Awareness Month in October. What We're Looking For
- Bachelor’s degree in Information Systems Management, Computer Science, Cybersecurity, or a related field.
- 5+ years of full-time work experience in IT audit, security risk management, information security, security compliance, privacy, or other GRC areas.
- Experience in security assessments, developing and implementing security controls, and driving security compliance programs.
- Working knowledge of industry standards (ISO 27001, NIST, SANS) and Privacy (GDPR, CCPA, PIPL) requirements.
- Good communication skills, strong work ethic, attention to detail, and ability to collaborate in a team setting.
- Strong critical thinking, analytical, and problem-solving skills.
- Proficient with the Microsoft Office suite.
- Personal attributes: treat people with respect; meet commitments; earn the trust and respect of colleagues; work ethically and with integrity; and accept responsibility for your own actions.