Technology Risk Management Analyst II Description
Technology Risk Management Analyst II
The Global Information Security (GIS) Technology Risk Management Analyst II will work with peers in GIS and across the Technology Division to ensure that cybersecurity and technology risks are properly identified, assessed, adjudicated, andmunicated in support of the overall GIS Risk Management program.
As part of the GIS Risk Management team, the analyst will work with a broad range of technology and non-technology stakeholders to help CME record and remediate risks.
Accountabilities:
1. Support CME Group's technology and cybersecurity risk management function
2. Work collaboratively with technology and business partners to identify and assess risks related to the confidentiality, integrity, and availability of technology systems and information
3. Develop and document remediation plans with risk owners and technical peers to address identified risks, including rmendations for technology and process controls
4. Foster a culture of risk awareness and accountability through continuous engagement with stakeholders throughout the risk management and finding management life cycle
5. Contribute to the continuous improvement of Risk Management policies and procedures
6. Contribute to regulatorypliance activities including annual enterprise technology risk assessments
7. Synthesizeplex technical details for presentation to non-technical decision-makers
8. Support the collection and creation of technology metrics, aid in identifying meaningful trends, and effectively report and present metrics to decision-makers
Experience:
9. Bachelor's degree inputer science or similar degree, or equivalent work experience (3+ years) in technology roles
10. 2-4+ years of experience working in a cybersecurity and technology risk management orpliance role
11. 2-4+ years of experience working with industry standard information security and control frameworks (NIST Cyber Security Framework, 800-53, ISO 27002, CobIT, etc.)
12. Demonstrable high quality writing skills for technical, management, and executive audiences
13. Demonstrable knowledge of cybersecurity best practices in the areas of identity and access management, intrusion detection and response, secure software development, security architecture, security engineering, and ITpliance
14. Experience working with global organizations and global teams
15. Professional certifications in cybersecurity or Risk Management (such as CRISC, CISM, CISSP, CGEIT, CISA, etc.) desired
16. Knowledge and/or experience with the Factor Analysis of Information Risk (FAIR™) framework and standard desirable but not required
CME Group: Where Futures Are Made
CME Group (cmegroup) is the world's leading derivatives marketplace. But who we are goes deeper than that. Here, you can impact markets worldwide. Transform industries. And build a career shaping tomorrow. We invest in your success and you own it, all while working alongside a team of leading experts who inspire you in ways big and small. Problem solvers, difference makers, trailblazers. Those are our people. And we're looking for more.
At CME Group, we embrace our employees' diverse experiences, cultures and skills, and work to ensure that everyone's perspectives are acknowledged and valued. As an equal opportunity employer, we recognize the importance of a diverse and inclusive workplace and consider all potential employees without regard to any protected characteristic.
The Candidate Privacy Policy can be found here.
Job ID 14517642