As an Information Security, Risk & Compliance Specialist, you will be a responsible for identifying, assessing, and helping mitigate potential risks within the organization by ensuring adherence to relevant regulations, industry standards, and internal policies, primarily focusing on maintaining data security and compliance with legal mandates through proactive monitoring, risk assessments, and supporting implementation of appropriate controls; acting as a subject matter expert on IT compliance issues and collaborating with various departments to maintain a secure IT environment.
In This Role…
- You will conduct system risk and gap assessments.
- You will also contribute to the development and review of security policies and procedures.
- You will be part of the team who provides risk management consulting services to various teams within the organization, aiding in prioritizing issues for resolution.
- You will support monitoring against internal standards within the program, acting as the second line of defense before internal audits.
- As others on the team wear 3-4 “hats”, you will also juggle multiple roles within the team, including risk identification, quantification, and consulting.
- You will facilitate risk assessments at the operational level, acting as a bridge between tactical and enterprise risks within the organization.
What You Will Need to Succeed…
- 5 to 7 years of experience within IT Audit or IT Project management, with experience with GRC (Governance, Risk & Compliance), Controls, Risk Assessment, Project Management, or Internal Audit.
- You have one of these certifications: CISA, CISM, CISSP, CRISC, CRMA or certification eligible
- You know how to develop and implement controls and processes through frameworks like NIST, ISO, CIS, COSO, COBIT, etc.
- You think strategically and focus on achieving goals together with your team.
- You communicate successfully in person and in writing and develop strong relationships with all levels in the organization.
- You can handle difficult issues in a professional, assertive, and proactive manner.
- You can perform and develop IT Risk Assessments