Designs and executes critical aspects of the Enterprise Security Risk Management function.
Develops, recommends and implements controls and cost-effective approaches to minimize the organization's risks effects.
Partners with the business and technology teams to promote understanding of the business landscape in order to facilitate security risk-based discussions.
Collaborates with executive and technical leadership to embed a security-focused mindset in all areas.
Analyzes organizational security risks, interactions, develop and publish security risk handbook, and procedures for implementation ensuring alignment with appropriate standards and frameworks.
Manage and execute risk identification, assessment and quantification, aggregation reporting, and monitoring processes.
Interprets internal or external business issues and recommends solutions/best practices.
Solves complex problems; takes a broad perspective to identify solutions.
Analyzes external market dynamics and other data sources to assess trends and develop actionable insights and recommendations to management, via understanding of the business model and the information available for analysis.
Assist in coordinating the security risk within the context of the security risk model.
Assesses and communicates information regarding business risks with functions across the organization.
Builds and maintains relationships with business partners, including understanding their specific risk landscape.
Uses professional knowledge, skills, and experience to influence and guide, monitor, and credibly challenge business areas as they manage risk and make risk decisions.
Coordinates the security risk program efforts including risk modeling, comprehensive periodic risk assessments, and regulatory reporting standards and expectations.
Develops presentations appropriate for senior level audiences and external regulators.
May mentor and give work direction to less experienced colleagues.
Requirements
Bachelors degree or higher in an IT or risk management related field.
Minimum of 8 years of experience working in security (physical or cyber).
3 years of experience with risk assessments, audit or control testing.
Experience and expertise in security and lifecycle management, auditing methodology, and technology risk assessments.
Self-starter; adaptable to change; motivated to set personal and program goals and proactively track performance against goals and initiatives.
Ability to document and explain risks and vulnerabilities to both business and technical stakeholders to influence peers and management; ability to team cross-functionally and form relationships to achieve objectives.
Solid understanding of information security policies, standards, industry best practices, and frameworks. (ISO 27K, NIST 800-53, FISMA, BITS etc.).
Strong business acumen with the proven ability to bridge the gap between business and technology.
Benefits
Annual Incentive Program
Medical/Pharmacy Plan
Dental
Vision
Life Insurance
Dependent Care Reimbursement Account
Health Care Reimbursement Account
Health Savings Account (HSA) (if enrolled in eligible health plan)
Limited-Purpose FSA (if enrolled in eligible health plan and HSA)
Transportation Reimbursement Account
Short-term disability (STD)
Long-term disability (LTD)
Employee Assistance Program (EAP)
Fitness Center Reimbursement (if enrolled in eligible health plan)