This role will be responsible for helping drive governance, risk and compliance in the information security domain
- Establish and maintain a program of operational metrics relating to information security - both at an enterprise level and at a client specific level
- Drive implementation of appropriate GRC tools for automation of metrics and creation of dashboards
- Perform validation of metrics and ensure appropriate evidence associated with metrics is retained to support internal and external audits
- Ensure framework and processes are integrated with broader information security and IT compliance processes
- Work closely with other groups in Information Security and other functions to ensure tight integration with broader processes (e.g. metrics, incident management, audits)
- Present on company's IT GRC process to clients and auditors
Requirements :
- Strong knowledge of IT GRC concepts esp information security metrics. At least 2 years on hands on experience in this area required
- Additional min 2 years of experience in information risk / security / IT audit domains strongly preferred
- Knowledge of key security and compliance frameworks - ISO 27001, NIST, HIPAA, SSAE 16 etc
- Excellent verbal and written communication skills
- Certifications like CISSP, CISA, CISM preferred
Didn’t find the job appropriate? Report this Job