- The Cybersecurity Risk and Compliance Manager is a key role in ASSA ABLOYs strategy to accelerate the organization’s cyber resilience.
- The newly created position will report to ASSA ABLOY America’s Division CISO and will be accountable for the divisional Cyber Risk and Compliance program.
- The role will build strong alliances with all functions and sub-groups across the division to help in the process of identifying, analyzing, quantifying, and treating risks.
- In addition, this role will be responsible to define, measure, and report on Information security compliance within the operation of an ISMS, providing relevant KPIs and KRIs.
- Establish divisional cyber risk governance
- Build divisional risk management culture and methodologies
- Maintain divisional cyber risk register
- Establish and execute risk assessment and management with business functions
- Build and maintain Cyber Risk and Compliance Reporting dashboards and reports for stakeholder groups
- Definition, monitoring and reporting of Key Risk indicators and relevant Key performance indicators
- Create, modify and implement divisional policies and directives based on Information security standards ISO27001 and NIST
- Develop deep coalitions with business partners to anchor Information Security into Policy framework
- Collaborate with corporate counsels and HR departments to monitor enforcement of standards and regulations
- Review policies periodically to identify hidden risks or non-conformity issues
- Develop and oversee control systems to prevent or deal with violations of legal guidelines and internal policies
- Evaluate the efficiency of controls and improve them continuously.
Requirements
- Professional certification in Information Security CISM or CISSP
- Professional certification in CRISC or ISO27005 preferred
- Minimum 3 years of experience in a global cyber security management role
- Proven experience of implementing and operating information security risk and compliance management within an environment of similar size and global representation
- Strong knowledge of current digital service delivery concepts, technology, and its cyber protection capabilities
- Good enterprise business knowledge with the ability to articulate risks in clear business language
- Good knowledge of global regulatory compliance demands in the areas of privacy, industry or governmental segments. (GDPR, CCPA, PCI-DSS, critical infrastructure, Patriot Act…)
- Engaged, committed, creative, hands-on and self-motivated personality
- Expert knowledge and proven success in implementing Information Security Management System (ISMS) in an enterprise organization
- Analytical and conceptual ability to identify compliance risks and develop practical solutions and adjustments
- Excellent business and IT communication skills in the English language.
Core Competencies
Demonstrates expertise in Cyber Risk and Compliance Management, with a strong focus on implementing Information Security Management Systems (ISMS) and ensuring compliance with global regulatory standards. Capable of building risk management cultures and effectively communicating risks in business language.
Highest-signal resume keywords
- CISM Certification
- CISSP Certification
- ISMS Implementation
- Cyber Risk Governance
- Regulatory Compliance Knowledge
ATS Optimization Keywords
Hard Skills
- Information Security Management
- Risk Assessment
- Compliance Management
- KPI Development
- Risk Register Maintenance
- Policy Development
- Control System Evaluation
- Analytical Problem Solving
- Digital Service Delivery Concepts
- Cyber Protection Capabilities
Soft Skills
- Engaged Personality
- Creative Thinking
- Self-Motivation
- Effective Communication
Certifications & Qualifications
- CISM
- CISSP
- CRISC
- ISO27005
Industry Keywords
- GDPR
- CCPA
- PCI-DSS
- Critical Infrastructure
- Patriot Act
Tools & Technologies
- Risk Management Dashboards
- Compliance Reporting Tools
Cybersecurity Risk and Compliance Manager in new haven at Unknown Company
This position is listed as full time and onsite.