• Find preferred job with Jobstinger
  • ID
    #15531416
  • Job type
    Permanent
  • Salary
    Depends on Experience
  • Source
    Pitisci & Associates
  • Date
    2021-05-27
  • Deadline
    2021-07-26
 
Permanent

Vacancy expired!

Risk and Compliance Manager/DirectorThe Risk and Compliance Manager role will blend business and technical knowledge with strong analysis and documentation skills in

support risk, compliance, and business continuity programs. The ideal candidate will have broad working knowledge of both risk and compliance frameworks and information security gained from working in roles that included exposure to risk management, compliance, technical and business operations. This candidate will have a passion for working with business units to analyze and document business process in a way that ensures secure and compliant processes. Experience with risk, security and compliance frameworks and their application in a working environment with sensitive data is key to this role. Familiarity with technical security toolsets, their capabilities and limitations will be needed to fulfill the requirements of this role, as well as the desire and ability to stay current on the latest security trends, laws and regulations.

RESPONSIBILITIES:
  • Work with leadership cross functionally throughout the Company to evolve, design, implement, and test the effectiveness of our internal risk and compliance programsLead execution of PCI-DSS, HIPAA, SOC 2 Type 2, Privacy Shield, ISO 27001, Cyber Security Maturity Model (CMMC), and GDPR reoccurring audits.Lead

    Risk Assessment Program and reporting to executive managementLead

    Business Impact Analysis Program
  • Lead

    Third Party Risk Management Program
  • Create internal and customer facing security and compliance documentation to facilitate sales and customer retention (e.g. Data sovereignty, CMMC, FedRAMP, StateRAMP, GDPR, etc.)
  • In support of risk Management,

    document and track implementation and testing of security controls in accordance with established procedures. Responsible for development, implementation, and rehearsal of

    RQ’s disaster recovery and business continuity program.Responsible for the development, implementation, and enforcement of RQ’s

    physical security program.

QUALIFICATIONS
  • Strong understanding of security architectures, frameworks, and controls to include knowledge of security technologies such as Cloud Infrastructure as a Service (IaaS) and Software as a Service (SaaS), Security Incident and Event Management (SIEM), intrusion prevention and detection (IPS/IDS), firewalls, proxies, web filters, email filters, web application firewalls, and end-point anti-virus, etc.
  • Experience managing relationships and leading customer initiated and external re-occurring meetings and audits
  • Experience translating and operationalizing compliance requirements into technical controls
  • Experience with Privacy Regulations such as GDPR, CCPA
  • Experience with cloud security best practices
  • A broad range of exposure to business continuity, systems analysis and risk management
  • Experience with deploying and administering a GRC Solution
  • Excellent written and verbal communications
  • Expert user of GRC tools, compliance portals, and Microsoft productivity tools
  • Project or engagement management experience with the ability to manage multiple and complex priorities across cross-functional teams
  • Bachelor's degree in Business, Computer Science, Engineering or related discipline or equivalent experience
  • Current CISSP, CISM, CRISC, CISA, or similar credentials desired
  • Clean background and ship
  • Highly motivated self-starter with great attitude, energy, and effort
  • Minimum of 5 years relevant experience in the security industry

Vacancy expired!

Report job

Related Jobs

Jobstinger