leading the execution of Information Security governance, risk, and compliance programs
developing and maintaining the compliance framework
supporting compliance and attestation activities
oversight of security policy management, exceptions, subsidiary risk, and third‑party risk management
facilitating the identification, reporting, management, and remediation of security risks
maintaining effective risk tracking and reporting processes
identifying and recommending improvements to the organization’s security risk management controls
Requirements
Bachelors Degree and 10 years in Information Technology / Information Security or 14 years of experience Information Technology, Information Security, Risk, or Compliance disciplines
4-5 years in Management or Leadership experience
Knowledge of project management Information Technology and security risk management
Knowledge of regulatory and compliance standards and practices
Understanding of information security principles and control frameworks
Understanding of business priorities and technology capabilities
Strong oral and written communication skills
Strong analytical and problem-solving skills
Experience with security standards, regulatory compliance tools, and platforms
Knowledge of emerging technologies and associated risk implications
System and technology integration concepts
IT standards, procedures, and policies
Applied governance and risk program execution
Ability to influence stakeholders and execute within complex organizations
Leadership—effectively leads teams and collaborates across functions
Adaptability and ability to manage change
Relationship management and conflict resolution skills
Support budget planning and resource allocation for GRC initiatives
Contribute to business cases supporting GRC investments
Provide input to investment and prioritization decisions