Job Description
Accumulus is seeking an Information Security Governance Manager. This will be a key role within the Security Assurance Team, reporting directly to the Director of Security Assurance.
The Information Security Governance Manager is responsible for overseeing the Governance Security Assurance Team and ensuring security efforts comply with business goals and regulations, while also collaborating with stakeholders to guarantee responsibility, clarity, and efficient decision-making for security governance initiatives. Starting day one, you will have the unique opportunity to support the growth of Accumulus Synergy through creating and enforcing policies, procedures, and guidelines to ensure cybersecurity aligns with business objectives and regulations, managing the Unified Compliance Matrix (UCM), overseeing security training and awareness programs, monitoring external regulatory changes, and maintaining documents related to Security Governance programs.
Responsibilities
- Lead the Governance Security Assurance Team (FTE and Contract)
- Oversee the governance framework to ensure that security efforts align with business objectives and regulatory requirements.
- Coordinates with stakeholders to ensure accountability, transparency, and effective decision-making regarding security governance initiatives.
- Develops policies, procedures, and guidelines to ensure that cybersecurity efforts align with business objectives and regulatory requirements.
- Maintains Unified Compliance Matrix (UCM) to ensure controls align with security strategy, support business objectives, and are consistent with applicable laws and regulations
- Owns Security training and awareness programs
- Monitor external regulatory, security and compliance landscapes and proactively inform management of significant changes
- Maintains handbook pages, policies, standards, procedures and runbooks related to Security Governance programs
Qualifications
- A minimum of 5 years of experience defining and shaping Security Governance and technical writing programs for regulated markets
- Demonstrated experience with security control frameworks such as: SOC 2, ISO, NIST, COSO, COBIT, etc.
- Detailed understanding of security and governance within cloud-native technology stacks