Assisting in managing daily operations of the Risk Management Program
Assisting in the review and evaluation of Anthology s corporate and product security and privacy risks by assessing the effectiveness and adequacy of internal management controls, and recommending control enhancements
Performing assessments of new programs and projects to determine the information security risk(s) and determine the applicable/reasonable security controls that need to be implemented to mitigate the risk(s)
Providing guidance and advice to business stakeholders to realize security by design by validating requirements prior to Go-Live
This includes defining any remaining risks, validating them with business stakeholders, recommending mitigations, registering them, and following up on remediation progress
Executing structured risk assessments of key applications with focus on compliance with company policies, frameworks and standards (e.g., CIS, ISO27001, ISO27701, ISO27017, ISO27018, NIST 800 series, SOC2)
Conducting vendor risk assessments
Driving compliance to policies and standards while providing transparency of compliance status
Keeping up with relevant international legislation, emerging threats, forecasts, policies, risk management developments and benchmarks
Aligning with other security risk management teams and related functions including Corporate IT, our data privacy office, and internal audit
The Candidate:
Required skills/qualifications:
2-5 years of relevant experience in Information Security Risk Management , particularly around assessments/audits
Knowledge of and experience with security standards and frameworks such as ISO, NIST, CIS, etc.
Translation of IT threats and vulnerabilities to business risks
Experience in a global organization with the proven ability to navigate complex, international work environments.
Strong written and oral communication skills
Effective project management skills
Experience with cloud technologies (e.g., AWS, Azure)
Fluency in written and spoken English
Preferred skills/qualifications:
Experience in a global organization with the proven ability to navigate complex, international work environments
Experience using the Center for Internet Security s Risk Assessment Methodology (CIS-RAM)
In possession of relevant industry certifications (e.g., CRISC, CISM, CISA, CISSP, CCSP)
Experience working with project management tools
Experience documenting security-related policies or procedures
The ability to pick up on new technologies and skills quickly
Experience with cloud technologies (e.g., AWS, Azure)