Manager of Information Security - GRC
Posted on Oct 8, 2021 by Request Technology
*We are unable to sponsor as this is a permanent full time role*
A prestigious fortune 500 company is on the search for a Manager of Information Security - GRC. This positions will manage 4-5 people and the role is revolved around Security Risk compliance team and following along the industry frameworks such as ISO/IEC 27001, ITIL, COBIT as well as those from NIST.
- Managing and executing the security risk and compliance program in collaboration with Information Security teams and stakeholders.
- Management, alignment, mapping, continuous improvement of internal security controls framework and control owner relationships.
- Integration expertise of vendor risk reviews, customer engagement surveys, control exceptions, risk assessments, audit readiness coordination, or security control requirement services.
- Subject Matter Expert to stakeholders and team in relation to the spirit of controls, associated security framework or regulation, and alignment to information security.
- Ensuring hiring, training, staff development, performance management and annual performance reviews are aligned and effectively executed to continue to grow skills and capabilities in accordance with Company's strategic needs.
- Monitoring external developments that may impact overall risk profiles, including emerging threats, technological developments, regulatory changes, etc.
- Report key operational, and program metrics designed to provide transparency of key attributes such as compliance readiness, security framework alignment, program maturity and operations.
- Experience in managing regulatory, legal, and/or Information Security frameworks and obligations.
- Experience in working with control owners to establish accountability, awareness, rationale, and relevance.
- Previous Risk Management experience preferred, with an emphasis on alignment to corporate risk appetite within the Cybersecurity discipline.
- Three or more years of IT people management experience, preferably in Information Security
- Written and verbal communication skills.
- Ability to communicate information security and risk-related concepts to technical and nontechnical audiences at various hierarchical levels.
- Knowledge of common information security management frameworks, such as ISO/IEC 27001, ITIL, COBIT as well as those from NIST, including 800-53 and Cybersecurity Framework.
- Skills in financial/budget management, scheduling and resource management.
- A degree in Engineering, Information Technology, Computer Science, Risk Management, or Audit Practices is preferred.
- Professional management certification in a related field such as Certified Information Systems Security Professional (CISSP), Certified in Risk and Information Systems Control (CRISC), Certified Information Security Manager (CISM), Certified Information Systems Auditor (CISA) or other similar credentials preferred
- Six or more years of relevant work experience in a combination of risk management, information security and technology.