Assist in conducting enterprise-wide, ongoing risk analysis in tandem with compliance and internal audit.
Assist in the development and management of the Vendor Security Risk Management Program and performing supporting tasks
Support Customer risk assessments , audits and evidence collection.
Assist in the development and maintenance of the Information Security Risk Register
Monitors control effectiveness and escalates where issues are identified
Contributes and co-manages the Metrics and Measures Program
Contributes to security requirement documentation packages
Assists in development and maintenance of Information Security control mappings to defined frameworks
Ensures risk treatment plans are appropriately communicated and tracked to the proper level of management
Performs Technology and Information Security risk assessments
Collaborate with Internal Audit and other assessors on Audits for Technology
Works closely with cross functional teams to address control maturity or issues
Review and provide feedback on other members work and documentation
Job Requirements:
1+ years experience in Information Security and/or Technology.
Prefer candidates with critical technical and IT security certifications, such as CISSP, CISM, CISA or equivalent.
Experience in Vendor Security Risk Management
Experience in performing risk assessments
Must have knowledge and experience in managing GRC tools.
Must be highly analytical with the ability to present your analysis
Must have great written and verbal communication
Must have experience in performing risk assessments.
Must have experience in maintaining metrics and measures.
Must have experience in supporting customer audits
Must have experience working with software engineering teams in an agile environment
General understanding of Cloud technologies
General understanding of meeting multiple compliance frameworks such as ISO 27001, FedRAMP, SSAE-18 SOC2, CSA STAR, Security Control Framework, HIPAA, PCI-DSS, etc.
Preferred Skills:
General knowledge of security technologies and approaches to secure an organization.
General knowledge of risk management and how to use risk management in a security program.
Additional Skills:
Ability to be an active member of a team
Ability to communicate effectively (written and verbal)
Self-motivated to work on tasks independently within the team
Ability to educate other members of the on existing processes and technologies
Adds to the diversity (gender, religion, race) of the team
Self and quick learner
Ability to ask questions
Knowledgeable pertaining to news and current events.
Education:
Bachelor s Degree or equivalent in experience preferred.