The position is responsible for the assessing and documenting of the company's compliance and risk posture as they relate to the its information assets.
Required Candidate profile
The purpose of this position is to provide highly skilled technical and information security expertise for development and implementation of the information security risk management program. Responsibilities require leadership and project management experience, as well as expertise to ensure effective system-wide security analysis; intrusion detection; standards and testing; risk assessment; awareness and education; and development of policies, standards and guidelines
Primary :
Lead the system-wide information security compliance program, ensuring IT activities, processes, and procedures meet defined requirements, policies and regulations.
Develop and implement effective and reasonable policies and practices to secure protected and sensitive data and ensure information security and compliance with relevant legislation and legal interpretation.
Execute strategy for audits, compliance checks and external assessment processes for internal/external auditors.
Work with Internal Audit, State Board of Regents, Auditor General's Office and outside consultants as appropriate on required security assessments and audits.
10+ years of advanced IT skills with high level of information security experience and expertise.
7+ years of planning and managing security projects
Knowledge of information security risk management frameworks and compliance practices.
Knowledge of securing network technologies, client, and server operating systems.
Ability to develop security standards and guidelines based on best practices and industry standards.
Excellent interpersonal, communication, and presentation skills, including formal report writing experience.
Skills in documenting risk and compliance activities.
Information security related training or certifications such as CISSP or CRISC.
Experience performing information security audits or risk assessment
Secondary
Business continuity planning and corporate compliance experience is preferred..
Demonstrated problem-solving ability and sound judgment for evaluating new situations.
Able to work with minimal supervision. Proactive, take-charge attitude
Relationship management and leadership of cross-cutting security development project
Clear experience and working knowledge of documentation management and GRC tools is a plus.
Experience in Agile, Lean and/or scrum methodologies.
Desired Candidate profile:
Designs, develops, configures, and implements solutions to resolve complex and highly complex technical and business issues related to related to information security, identity management, user access authentication, authorization, user provisioning, and role-based access control.
Designs, develops, and implements solutions to successfully integrate new information security and identity management systems with the existing architecture.
May drive one or more projects as part of a Security or Security Risk Management team.
Acts as a subject matter expert (SME) for one or more security, IDM, or risk management areas.
Act as team-lead for other security or risk management personnel. Coaches and trains security engineers.
Job Classification
Industry: IT-Software, Software ServicesFunctional Area: IT Software - Application Programming, Maintenance, Role Category: Programming & DesignRole: Programming & DesignEmployement Type: Full time
Education
Under Graduation: Any Graduate in Any Specialization, Graduation Not RequiredPost Graduation: Post Graduation Not Required, Any Postgraduate in Any SpecializationDoctorate: Any Doctorate in Any Specialization, Doctorate Not Required