Description- Assist with focused information risk assessments of existing or new services and technologies along with business counterparts.
- Provides consultative advice to information governance or security teams that enables them to suggest informed risk management decisions.
- Helps to identify and facilitate the implementation of appropriate controls to effectively manage information risks as needed.
- Identify opportunities to improve risk posture developing solutions for remediating or mitigating risks and assessing the residual risk.
- Support to tracks identified risks and risk events.
- Communicates identified issues and risks to stakeholders to determine actions and support decision making.
- Assist with coordinating the identification and ranking of vendor risks the classification and tiering of vendors by risks and risk impacts.
- Assist with managing vendor risks as defined in vendor contracts and in accordance with existing risk management programs and policies.
- Develops monitors and possibly executes vendor remediation actions mitigation and contingency plans when risks or events are identified.
- Ensures third (and increasingly fourth) party vendor regulatory compliance.
- Contributes to the gathering of vendor risk assessment data and prepares risk assessments for criticalrelated vendors as needed to be published and communicated to stakeholders.
- Collaborates as appropriate with information security finance compliance and/or disaster recovery and business continuity management and other risk functions to maintain an enterprise risk management program.
- Experience with coordinating vendor risk management frameworks policies and processes within a broader enterprise operational and IT risk management model.
- Manages the performance of direct reports by developing accountabilities establishing performance objectives providing career counseling feedback and guidance and ensuring that all policies are understood and adhered to.
Qualifications- University Degree (Equivalent to Bachelors degree) in Business Computer Science Information Security or a related disciplines plus generally 5 years experience in information security especially in an information senior cybersecurity risk role.
- Strong business background; understand financial and strategy.
- Strong understanding of complex vendor riskrelated issues (managing vendor relationships information security or regulatory compliance programs and audits).
- Expertise with regulatory compliance and information security management frameworks.
- Excellent prioritization capabilities.
- Strong decisionmaking capabilities with a proven ability to weigh the relative costs and benefits of potential actions and identify the most appropriate one.
- Strong problemsolving and troubleshooting skills.
Total Rewards: We understand compensation is an important factor as you consider the next step in your career. The estimatedsalary range for this position is $85000 to $110000 and is based on multiple factors including jobrelated knowledge/skills experience geographical location as well as other factors.This position is eligible for annual bonus compensation with a target payout of 10 of the base salary. This position also provides health benefits such as medical dental and vision; wellness benefits such as mental and financial health; and retirement savings 401K) commensurate with the standard rewards offered in each individual location or country. We also provide fulltime employees with paid time off including vacation 15 days) holiday including floating holidays 12 days) and sick time off 72 hours).
#LISG2
#LIRemote
Required Experience:
Exec