Job Purpose:Risk compliance Role is ensuresing that the organization conducts its business processes in compliance with laws and regulations, professional standards, international standards, and accepted business practices. These professionals perform audits at regular intervals and execute design control systems, advising the management on possible risks that might occur, and organization policies.Key Tasks and Duties:Risk Management- Develop and manage an information security risk management program including development, evaluation, and adherence to multiple areas of practice- Identify, assess, manage, and track remediation of risks related to IT infrastructure, applications, platforms and suppliers and drive explicit requirements and timelines in all environments- Develop strong relationships with external audit and key stakeholders to ensure risk management oversight is understood, managed appropriately and current with all standards, guidelines, and regulations that are applicable- Establish and manage formal vulnerability management, penetration testing and security posture assessment programs- Performs and investigates internal and external information security risk and exceptions assessments. Assess incidents, vulnerability management, scans, patching status, secure baselines, penetration test result, phishing, and social engineering tests and attacks.- Updates security controls and provides support to all stakeholders on security controls covering internal assessments, regulations, protecting Personally Identifying Information data, ISO 27001 and Payment Card Industry Data Security Standards (PCI DSS).- Trains, guides, and acts as a resource on security assessment functions within the departments.- Assists other staff in the management and oversight of security program functions.- Developing and implementing enterprise governance, risk, and compliance strategy and solutions;- Perform information security risk assessments and risk management activities across the organization. Establish and maintain risk criteria, identify, analyze, and evaluate information security risks. Ensure that repeated information security risk assessments produce consistent valid and comparable results. Maintain repository of documented information about the information security risk assessment process. Conduct risk and vulnerability assessments of planned and installed information systems to identify vulnerabilities and risks.- Perform selection of appropriate information security risk treatment options as a result of risk assessment results, determine all controls that are necessary to implement the information security risk treatment options, compare controls and verify that no necessary controls have been omitted, obtain risk owner's approval of the risk treatment plan and acceptance of residual information security risks.- Design and document IT general controls to ensure the business demonstrates compliance with its regulatory or compliance obligations. Facilitate and coordinate activities and responses related to internal and external controls testing including entitlement reviews. Facilitate the remediation of control gaps and escalate critical issues to management. Work closely with control owners, internal and external auditors to ensure requests are completed for timely delivery to audit. Assist with third party audits and certifications for the organization (i.e. ISO, PCI, NESA, SWIFT etc.)- Analyze and evaluate information security incidents in order to reduce the likelihood or impact of future incidents. Facilitate reports of security violations by documenting and coordinating remediation and awareness of violations to respective managers. Maintain repository of information security incidents and develop metrics for reporting to management.- Conduct the vendor assessment on new onboarding vendors. - Perform any other related duties as required or assigned
Subscribe for free, choose your specializations, and we'll send matching jobs directly to your WhatsApp
Subscribe via WhatsApp, free