The Sr Associate, Information Security Governance, Policy & Controls position will be an integral member of the Information Security and Risk Management team. This role will be will drive development of information security policy, standards and controls, and monitor compliance to regulations and policies, with the goal of safeguarding the company assets and maintaining confidentiality, integrity and availability of information. Work in Chief Information Security Officer (CISO) office under Associate Director, Information Security Governance, Risk and Compliance, this role serves as an information security professional for Grant Thornton.
This is a change agent position. We are seeking breadth/depth of experience as a recognized expert, delivering business value and meeting commitments, operating across a matrixed environment, able to manage ambiguity and to reach understanding and gain commitment to act. Focus on successful execution/delivery of outcomes, and track record for driving change are critical. The successful candidate will have a good mix of technical knowledge, understanding of industry best practices, frameworks and regulations, and a demonstrated background in information security risk and
compliance management program.
· Develop or enhance information security policies, control objectives, controls and standards aligned with information security regulations, best practices and frameworks.
· Develop and oversee control framework to prevent or deal with violations of legal guidelines and internal policies.
· Deep functional expertise in the area of information security policy, standards, guidelines and risk & compliance functions.
· Partner with stakeholders, including process owners and control owners, to document processes/procedures (via process flows), risks, and controls.
· Perform control testing and compliance assessments to identify and manage security risks and issues.
· Support the execution of front-line controls, self-assurance, and risk assessment activities (ad-hoc controls review, business process management (BPM), risk control self-assessment (RCSA), and independent risk and audit activities as directed.
· Provide ongoing assessment of InfoSec’s risk profile through regular monitoring and status reporting of risks, issues, events, and initiatives within data governance processes
· Support iterative review of assessment results, working with appropriate stakeholders across the lines of defense
· Perform and facilitate the collection, review, and assimilation of risk assessment data and reporting into concise and meaningful reports
· Assess exposure to risk, measure operational risk against ERM frameworks, assist in establishing policies and procedures to minimize risk, identify ways to protect the organization from data loss and reputational damage
· Coordinate efforts with InfoSec’s Issues Management and other Control Testing functions, to continually update control effectiveness and residual risk rating of InfoSec’s business processes as needed
· Assist with internal and external auditors to address and resolve audit questions and findings relative to core process of security risk management
· Support the testing of control design and the testing of control effectiveness for assigned areas as needed
· Identify areas of improvement in the existing processes, methodology, and policies. Identify gaps and recommend enhancements. Drive, adopt, and enforce best practices in report templates and tools
· Perform other duties as assigned
Experience
· Experience with information security risk management framework, assessment, audit and controls based on industry standard frameworks (i.e. NIST; ISO; COSO; HiTrust, CMMC)
· Experience with regulatory requirements (i.e. PCI; GDPR; HIPPA; Privacy; CCPA; etc.)
· Experience using GRC tools and technologies in support of the assessment/audit process (RSA Archer, Security Scorecard, Risk Recon, etc.)
· Experience gathering information from a range of different sources to help identify weaknesses in security controls
· Expert with security control design, development, implementation, and monitoring
· Demonstrated experience across multiple information security domains preferred
Qualifications
· Bachelor's degree in Computer Science, Engineering or related field or equivalent work experience
· CISA, CRISC, CISM, or CISSP certifications (one or more) preferred
· Demonstrated advanced verbal and written communication skills
· Excellent organization skills and be a self-motivated learner
Software Powered by ICIMS
www.icims.com