Employer Active
Job Alert
You will be updated with latest job alerts via emailJob Alert
You will be updated with latest job alerts via emailPortfolio Compliance Enablement Leader
Location: Wrocaw Warszawa
Hybrid model: 2 days office/3 days remote
Let us introduce you the job offer by EY GDS Poland a member of the global integrated service delivery center network by EY.
Todays world is fueled by vast amounts of information. Data is more valuable than ever before. Protecting data and information systems is central to doing business and everyone in EY Information Security has a critical role to play. Join a global team of over 1000 people who collaborate to support the business of EY by protecting EY and client information assets! Our Information Security professionals enable EY to work securely and deliver secure products and services as well as detect and quickly respond to security events as they happen. Together the efforts of our dedicated team help protect the EY brand and build client trust.
Within Information Security we blend risk strategy digital identity cyber defense application security and technology solutions as we consider the entire security lifecycle. You will join a team of hardworking securityfocused individuals dedicated to supporting protecting and enabling the business through innovative secure solutions that provide speed to market and business value.
The opportunity
Working closely with our service lines and functions and with our technologists across the world the Portfolio Compliance Enablement function supports digitally enabled services that take advantage of emerging technologies in concert with EYs broad industryspecific experience and professional services knowledge. The Information Security Portfolio Compliance Enablement Leader leads our EY Portfolio business team to improve their risk posture through compliance enablement with Information Security policies. This lead will partner with requisite SL/Functional leaders and business stakeholders to reinforce policies control ownership and compliance responsibilities. They are responsible for and will maintain the overall technology compliance posture for the portfolio leveraging effective governance and oversight. In addition to requiring adequate information security controls data protection privacy and software development practices this role is responsible for helping the organization understand and comply with all laws rules and regulations governing the companys technology including third parties and vendor dependencies.
The role involves comprehensive management of the Portfolio and service line of risk with the primary accountability of reducing that risk by engaging directly with key EY Leaders and ensures the companys technical systems and information assets are protected in accordance with compliance requirements by doing proactive compliance management and compliance hunting. Furthermore the role focuses endtoend security compliance enablement and is responsible for identifying evaluating and reporting on information security risks when technological systems and software are not meeting compliance requirements.
As a Portfolio Compliance Enablement Lead within EYs Global Information Security function this individual will be a trusted compliance advisor to the organization and serve as a trusted advisor for security compliance. This role will directly engage in managing a team of Compliance Enablement specialists who will drive improvements to the overall risk posture of EY provide compliance enablement guidance on projects and programs lead projects aimed at reducing risk provide insight on top risks impacting the security posture or our businesses and help define mitigation strategies for strategic compliance risks. The role will directly consult on security vulnerabilities and translation of security compliance risks into business risk terminology for riskbased investment planning. This role is expected to notably enhance the Service Lines abilities to competently manage and reduce a range of security risks. In doing so it will add value by protecting the companys reputation and stability and accelerate the effective and derisked use of technology.
Furthermore this role will closely collaborate with leaders within Information Security to implement the teams strategy vision and objectives.
Your key responsibilities
This position is a leading role in managing the compliance portfolio for all global regional and countrybased assets and systems. As a compliance consultant dedicated to the EY Service Line and function you will be both an individual contributor capable of supporting multiple projects and lead a team of compliance specialists focused on improving the risk posture of the Service Line or function. In other words it is not just an oversight role but one that requires detailed understanding of the Service Line business drivers key risks and issues and can help strategize on risk reduction strategies based on analysis of compliance data and trends.
You will lead a team focusing on these pillars:
Risk Management and Reduction:Take ownership of the Portfolio or Service Line of security risk and compliance engaging directly with key EY leaders to reduce risks by providing insights on top risks impacting the security posture of the businesses. Engage in compliance and riskbased investment planning to mitigate these risks effectively.
Trend Identification and Remediation:Identify security risk trends and themes that require a comprehensive approach to remediation. Lead and spearhead these efforts ensuring that risks are mitigated in a timely and efficient manner.
Proactive Security Initiatives:Proactively seeking out and identifying security risks weaknesses and potential vulnerabilities in systems and processes before they can be exploited and independently standup initiatives to address them. Improve compliance with security standards and policies though continuous improvement and innovation in security practices.
Governance Risk and Compliance (GRC) Management:Manage the endtoend workflow of security compliance of risk findings in our Governance Risk and Compliance (GRC) tool to ensure continuity and compliance with security policies standards and regulations.
And focus on the following responsibilities:
Define compliance strategies and remediation recommendations that provide pragmatic security guidance that balance business benefit and risks.
Develop appropriate risk treatment and mitigation options to address security risks identified during security reviews or audits.
Translate technical vulnerabilities into business risk terminology for the business.
Maintain compliance framework assessment toolkits used in testing and validation procedures.
Be accountable for and lead assessments for technology infrastructure applications and thirdparty dependencies aligning to regulations best practices and corporate governance.
Skills and attributes for success
Significant working security experience and knowledge in the management of compliance with company security policies in the following areas:
Strong leadership and organizational skills
Strategic skills to assist with the development of a longterm vision for EYs risk management security framework & approach
Ability to appropriately balance firm security needs with business impact & benefit
Ability to facilitate compromise to incrementally advance security strategy and objectives
An overall understanding of the business objectives of EY with an ability to build relationships across EY
Ability to team well with others to facilitate and enhance the understanding & compliance to security policies
Experience facilitating meetings with multiple customers and technical staff including building consensus and mediating compromise
Execute topdown assessment of risk based on policy compliance data and risks
Experience conducting risk assessments vulnerability assessments vendor and thirdparty risk assessments and recommending risk remediation strategies
Looks for ways to continually improve our compliance with Information Security policies
Create promote and oversee enforcement protocols enabling consistency across diverse internal stakeholders
Investigate any violations of policies and recommend corrective action.
Develop training materials and conduct training sessions to educate on policies and enforcement protocols
Develop metrics to evaluate the effectiveness of policy enforcement and generate regular reports
Identify policy and enforcement gaps and propose improvements.
Projects advanced consultative skills to conduct effective questioning to break down complex issues into core elements formulate appropriate ideas or planning and negotiate those ideas and plans clearly and concisely to advance a cooperative engagement by all levels of the organization including senior and/or executive management
Proficient understanding of business focus and processes and the ability to inject cybersecurity compliance into the business through teamwork and influence
Ability to maintain a high level of integrity trustworthiness and confidence to represent the company and security leadership with the highest level of professionalism
Ability to remain credible with the team and external constituents through sustained industry knowledge
Proven project leadership with both legacy and emerging technologies to assess and manage business risk and enforce security controls
Wideranging knowledge in technical infrastructure and applications from legacy through next generation
To qualify for the role you must have
A minimum of 10 years experience in the field of Cyber Security Information Security or related discipline
At least 5 years experience in a leadership role managing a distributed team and workforce
Advanced degree in Cyber Security Information Security Computer Science or a related discipline; or equivalent work experience
One or more of the following or equivalent certifications: Certified Risk and Information Systems Control (CRISC) Certified Information Systems Security Processional (CISSP) Certified Information Security Manager (CISM) Certified Information System Auditor (CISA) Certified Internal Auditor (CIA) Global Information Assurance Certification (GIAC) in related area CIPP CIPT
Experience working with common information security standards such as: ISO 27001/27002 NIST PCI DSS ITIL COBIT
Demonstrated leadership experience and thorough understanding of various regulatory requirements and laws such as but not limited to PCI SOX HIPAA HITRUST GDPR and GLBA.
Experience in policy enforcement and security compliance awareness and learning at a publicly traded company
Strong understanding of governance risk and compliance (GRC) frameworks and tools
Proven competence in communicating confidently and effectively with clients vendors and all levels of management
Experience in managing the communication of security findings and recommendations to IT project teams and management
Skilled in executive level presentations and briefings
Proven ability to identify and mitigate security risks proactively
Insight into the business advantages of good risk management and internal controls beyond compliance purposes
Demonstrated leadership negotiation and collaboration skills and ability to influence up and down
Proven ability to manage multiple projects and meet deadlines in a fastpaced and changing environment
Demonstrated experience in managing endtoend security compliance enablement projects
Extensive experience with security compliance regulations
Strong English language skills: excellent writing presentation interpersonal and communication skills are required
Capable of working with diverse teams and promoting an enterprisewide collaborative security culture
Ability to work flexibly and adapt to changing environments
Ideally youll also have
Exceptional judgment tact and decisionmaking ability
Familiarity with local and regional regulatory requirements and how they impact IT policies
Flexibility to adjust to multiple demands shifting priorities ambiguity and rapid change
Outstanding management interpersonal communication organizational and decisionmaking skills
Experience with RSA Archer and/or IBM Open Pages
An ability to utilize core risk and controls skills in a broad range of projects both in a traditional internal audit and in advisory projects aimed at assisting in the implementation of controls / improvements
What we look for
We are looking for individuals with a passion for information security and demonstrated ability to apply their knowledge to new and emerging technologies that are supporting the growth strategy of a global professional services firm.
What we offer
EY Global Delivery Services (GDS) is a dynamic and truly global delivery network. We work across ten locations Argentina China Hungary India the Philippines Poland Sri Lanka Mexico Spain and the United Kingdom and with teams from all EY service lines geographies and sectors playing a vital role in the delivery of the EY growth strategy. From accountants to coders to advisory consultants we offer a wide variety of fulfilling career opportunities that span all business disciplines. In GDS you will collaborate with EY teams on exciting projects and work with wellknown brands from across the globe. Well introduce you to an everexpanding ecosystem of people learning skills and insights that will stay with you throughout your career.
About EY
EY Building a better working world
EY exists to build a better working world helping to create longterm value for clients people and society and build trust in the capital markets.
Enabled by data and technology diverse EY teams in over 150 countries provide trust through assurance and help clients grow transform and operate.
Working across assurance consulting law strategy tax and transactions EY teams ask better questions to find new answers for the complex issues facing our world today.
If you can demonstrate that you meet the criteria above please contact us as soon as possible.
The exceptional EY experience. Its yours to build.
In compliance with the requirements of the Whistleblower Protection Act our company has established the Procedure for reporting breaches of law and undertaking appropriate followup actions. Any misconduct should be reported through the EY Ethics Hotline.
Full Time