What you'll get to do:
- Manage the process and tools for Information Security & Risk Management, and process IT due-diligence requests and ensure compliance to policies, procedures and regulations.
- Function as a central third-party risk management subject matter expert looking to involve third parties in processes that interact with data. Support completion of information security review process for all new third parties, and annual reviews for all other relationships, that receive and/or interact with data.
- Maintain inventory of third parties who possess and/or interact with data, including key risk information about the relationship, data attributes involved, and regulatory compliance. Monitor open third party security issues and remediation actions associated with security control gaps to ensure timely closure.
- Educate and build cybersecurity awareness across the enterprise
- Identify and analyze new requirements for policy impacts; develop and update policies, procedures and guidelines.
- Improve compliance with security standards and policies across the enterprise.
- Be the primary point of security risk management activities, including analyzing, quantifying, and tracking identified information security risks and reviewing and documenting risk exception requests.
- Work with the Technology Process Owners to create, modify, validate, and decommission policies/procedures.
- Create dynamic dashboards and scorecards for visibility of Information Security Governance activities.
What you'll bring to the team:
- Experience with security and control frameworks, such as FFIEC, NIST, COBIT, ITIL, and ISO control framework
- Background in Information Security, IT Risk Management, or third party risk management
- 8+ years of experience supporting Information Technology compliance programs to meet regulatory or compliance requirements
- Experience identifying potential IT controls risks and opportunities through and offering sustainable recommendations that address cause rather than symptoms
- Experience with information security standards, best practices for securing computer systems within applicable laws and regulations
- Experience with Governance Risk & Compliance (GRC) tools and procedure development
- Experience working in a regulated industry (financial services or health care)
Reports to: Senior Manager, Information Security Governance
Job Level: Lead
The minimum salary for this role is $102,400. The total compensation package includes eligibility for performance-based bonuses as well as a 1-time equity grant based on level.
The actual offer, reflecting the total compensation package and benefits, will be at the company’s sole discretion, and determined by a myriad of factors including, but not limited to, years of experience, depth of experience, and other relevant business considerations.