Job Overview:
The Our Client Technology and Cyber Security Risk Analyst will be working closely with Our Client business stakeholders, customers, and suppliers to identify and understand risk so it can be effectively managed through ServiceNow’s IRM module. You will have previous experience in transforming a GRC department and be able to directly transform current services as well as support business as usual activity. This is a global role with responsibility for responding to information security needs across the entire Our Client corporation.
An ideal candidate will have a demonstrated ability to drive security risk change, compliance, and business outcomes, can present security practices to business stakeholders, customers and suppliers, is detail-oriented and able to operate effectively under pressure.
Responsibilities:
1. Support internal and external stakeholders on matters of risk assessments and framework requirements (working knowledge of NIST CSF, 800-53). Ensuring security and compliance requirements are understood by those stakeholders.
2. Driving transformational change to the Technology and Security Risk program as it evolves to meet changing organizational and regulatory needs.
3. Help build and maintain an effective third-party risk assessment program.
4. Perform supplier risk assessments, contract reviews, respond to customer security questionnaires and establish that Our Client security and compliance requirements are understood.
5. Develop tactical and trusted relationships within business stakeholders, partners and vendors. Awareness of project management techniques, while having the ability to support meetings when required.
6. Ability to present clear, consistent information and professional risk reporting to directorate and executive to highlight highest priority risks and their treatment plans.
7. Work directly with internal business partners to assist in the identification and assessment of potential security risks, establish risk owners, ratings, and management action plans.
8. Develop Standard Operating Procedures (SOP) to document procedures for risk assessments, third-party assessments, and business process workflows for Security Governance, Risk, and Compliance.
9. Document recommendations and implementation of corrective action plans to remediate issues for identified deficiencies. Monitor the progress of plans for on-time completion.
10. Counsel and guide business partners in identifying risks and potential risk mitigation alternatives commensurate with the risk identified and consistent with risk appetite.
11. Utilizing working knowledge of IRM (Integrated Risk Management) of ServiceNow to build GRC processes within it.
12. Ensure that fundamental information on accountable technology is accurate (e.g. KB Articles / process maps / training documents and presentations / RACI / Contract information).
13. Identify problems that cause negative impact to Our Client or the team and help to create solutions.
14. Provide on-the-job training and peer review to team members.
15. Feed recommendations into strategic plans.
Required Skills and Experience:
1. Security qualifications, i.e., CISSP, CISM.
2. Work directly with technology and business partners to assess security risk controls to ensure data is adequately safeguarded.
3. Experience in conducting internal security assessments and reviews.
4. Experience in articulating and documenting information security risks.
5. Customer-driven; help bring the voice of customer into every technical decision.
6. Influencing the security agenda across a large enterprise.
7. Experience with security and privacy controls deployed in large enterprise and cloud environments.
8. Able to independently solve straightforward problems by investigating fully and provide recommended solutions for more sophisticated problems.
9. A driven demeanor will thrive at Our Client. Proactive mentality is a must.
10. Ability to clearly communicate information security concepts and complex technical topics to a wide audience of both technical and non-technical personnel (business leaders, auditors, legal staff, engineers).
11. Execution-oriented with an ability to manage multiple projects simultaneously with a focus on outcomes driving impact.
12. Ability to effectively work and collaborate with technical and non-technical resources.
13. Demonstrates the ability to manage and prioritize multiple projects simultaneously and adapt to rapidly changing schedules, priorities, and workflows.
14. Attention to detail, ability to multi-task and maintain composure when under pressure.
15. Agile, self-starter and can prioritize quickly and effectively. Contributes through the quality, accuracy and timeliness of the tasks/services provided by self, and quality control of work provided by others.
“Nice To Have” Skills and Experience:
1. Hands-on experience implementing security within public cloud services (AWS, Azure, Google).
2. Good familiarity with other Enterprise Security organizations (can identify which team fulfills which roles) and a solid understanding of ITIL processes.
3. Experience working in a security role focused on technical controls, services and procedures.
4. Demonstrates a good understanding of the variety of technical security control concepts, procedures and systems (e.g., Email Security, AV, EDR, Firewalls).
5. Experience with Configuration Management Database (CMDB).
6. Strong familiarity with security standards and audit requirements including NIST CSF, 800-53, ISO 27001, PCI DSS, and SOC 2 Type 2 reports.
In Return:
Our Client is an equal opportunity employer, committed to providing an environment of mutual respect where equal opportunities are available to all applicants and colleagues. We are a diverse organization of dedicated and innovative individuals, and don’t discriminate on the basis of any characteristic.
If you're interested in this role, click 'apply now' to forward an up-to-date copy of your CV, or call us now.
If this job isn't quite right for you, but you are looking for a new position, please contact us for a confidential discussion on your career.
#J-18808-Ljbffr