Ability to adapt quickly to new technologies and changing regulatory landscape
Ability to write and coordinate corporate policy
Key Responsibilities:
Execute IT and application risks assessments, including planning, context definition, identification, analysis, evaluation, treatment, communication, and monitoring risks
Consult and assist to risk and control owners in the planning, design, implementation, operation, maintenance & remediation of control activities and other supporting requirements (eg policies, standards, processes, system configurations, etc) as appropriate
Assist and advance the businesss compliance accreditations such as ISO 27001 and SOC 2
Perform third-party risk assessments, track remediation and compliance
Respond to customer security questionnaires and attestation requests
Develop strategies to address awareness and training for all stakeholders
Support the Incident Response teams creating and maintaining policies, plans, processes and procedures, training, testing, and monitoring, identifying and documenting lessons learned, and improving the program
Work with key business units to drive the adoption, design, implementation, operation, and remediation of control activities and other supporting requirements like policies, standards, processes, system configurations and reporting
We would like to talk with you if you possess:
bachelors degree with at least 3+ years of prior experience in IT security, information security, governance, risk and compliance in a SaaS environment.
Deep understanding of risk assessment frameworks, IT risk assessments, enterprise risk assessments, and risk calculation and reporting.
Previous experience developing and testing business continuity and disaster recovery plans.
Experience running third-party risk assessments and understanding of SIG and CAIQ questionnaires
Experience with controls definition, design, implementation, and assessment
Familiarity with incident response and handling
Previous exposure to security standards such as ISO 27001/2, NIST 800-53 and 800-171
Ability to manage complex local and international security requirements
Experience using GRC tools is preferred
ISO 27001, ISO22301 or other relevant certification is preferred, or ability and willingness to achieve one after hire