Position OverviewUnder limited supervision, deliver RGA’s global IT risk management services. Ensure risk services requests are processed and completed within a defined response timeframe. Improve IT risk assessment processes to meet business agility and compliance obligations.
Provide security risk guidance to assist stakeholders or requestors to make risk decisions. Participate in the development of policies, procedures, standards, and controls.Business Area: IT, Security & Disaster RecoveryResponsibilitiesImplement Risk Assessment services, which includes processing and completing risk assessment requests from various departments and offices in RGADesigns, implements, and maintains IT Governance’s Risk Management FrameworkHelp facilitate risk assessment workshops that include threat analysis, control effectiveness evaluation, and risk remediation recommendationsWork with various RGA departments to assess project and data risks associated to security and compliance requirements, and provide guidance and advise for stakeholders to make decisionsMaintain proper linkage from IT risk and controls register to Corporate and IT level policies.Assist with RGA Compliance Inquiry requests process, which includes responding to clients’ security and risk assessment questionnairesPerform other duties as assignedRequirementsEducationRequired: Bachelor’s degree or equivalent experiencePreferred: Master’s degree and/or LOMA certificationRequired Experience4+ years IT security, privacy, audit, controls and regulatory compliance, or related experienceIntermediate ability to evaluate IT controls objectives and feasibilityIntermediate oral and written communication skills, demonstrating the ability to convey complex technical and security concepts and terminology to that which is meaningful and well received by the customerIntermediate knowledge of broad security and risk management related practicesAbility to manage multiple projects and/or sub-teams simultaneously, including the ability to delegate key areas of responsibilityAbility to adapt to new methods, work under tight deadlines and stressful conditionsAbility to work well within a teamIntermediate investigative, analytical, and problem-solving skillsAbility to liaise with individuals across a wide variety of operational, functional, and technical disciplinesAbility to translate business needs and problems into viable/accepted solutionsIntermediate skills in customer relationship managementAbility to resolve conflict and foster teamworkExperience leading security risk assessments, regulatory compliance audits/inquiries, and control assessmentsKnowledge of risk and control frameworks (e.g., NIST CSF, NIST 800-53, ISO/IEC 27001)Technical RequirementsBasic understanding of IT domains: infrastructure, networking, storage, databases, operating systems, cloud, applications, etc.Strong understanding of security technologies, including: SSO, IAM, DLP, EDR, SIEM, firewalls, gateways, IDS/IPS, CASB, antivirus, SSDLC, cryptography, PKI, etc.Preferred ExperienceInsurance/Reinsurance industry knowledge/experienceExperience with risk quantification (FAIR or Hubbard Decision Research)Information security, compliance, risk, or audit professional certifications, such as: CISSP, CISA, CRISC, CISM, CGEIT, CPA, CIAExperience reviewing SSAE 16/ SSAE 18 attestationsProject management skills/experienceStrong understanding of domestic and global security & privacy regulationsPreferred Technical ExperienceCloud assessment experience (AWS, Azure, Google Cloud, etc.)Previous experience as a Systems Administrator, IT Auditor, Developer, Penetration Tester, Cloud Security Engineer, GRC Analyst, Risk Analyst, Information Security Analyst/Engineer/ConsultantCompany OverviewReinsurance Group of America, Incorporated (NYSE: RGA) is one of the largest global providers of life reinsurance, with offices around the world. RGA delivers expert solutions in individual life reinsurance, individual living benefits reinsurance, group reinsurance, financial solutions, facultative underwriting and product development.
Our mission is to enhance our clients’ prosperity by supporting their financial and risk management capabilities.
Sr. Compliance Management Specialist in chesterfield at Unknown Company
This position is listed as full time and onsite.