Security Contracts/Regulations And Third Party Security Specialist – Gis Governance, Risk & Compliance ConsultantResponsibilities: Security Contracts Responsibilities:Develop a deep understanding of the company's Data Security Addendum (DSA) for third-party contracts.Analyze third party modifications to the company's DSA and:Develop/document a position on acceptable versus unacceptable modifications.Propose alternative language that is acceptable to GIS leadership.Work closely with GIS leadership, legal, and third party relationship executives to:Communicate the security impact to FT of third-party DSA modifications.Effectively engage senior business and IT stakeholders with polished executive communication.Negotiate DSA modifications with third parties to the extent permissible by GIS leadership and legal.Participate in conference calls as needed to finalize the DSA.Propose periodic updates to the DSA based on lessons learned from third party negotiations, emerging regulatory third-party security oversight requirements, and the evolving security threat landscapeSecurity Regulations ResponsibilitiesResearch, monitor and analyze updates to existing international cybersecurity regulations and emerging/new cybersecurity regulations.Track regulations manually, map requirements to the company’s Security Policy and Security Program and Framework and identify misalignments.Propose updates to the company's Corporate Information Security Policy and Security Program and Framework based on identified misalignments.Document/Communicate the results to GIS leadership.Monitor industry wide Cybersecurity threat landscape for emerging threatsPropose potential additional updates to the company's Corporate Information Security Policy and Security Program and Framework that may be needed to address emerging threats.Third Party Security ResponsibilitiesConduct vendors security assessments for compliance with our firm’s information security policies, standards, and controls.Identify vendors security issues/non-compliance and recommend appropriate remediation activities to resolve them.Engage vendors IT and Cybersecurity leadership to further investigate identified security risks and negotiate their resolution.Communicate status/progress to business stakeholders.Requirements:Overall 7+ years of industry experience in security contract negotiations, security regulations research/analysis, and third-party security assessments for large global financial organizations and their Cybersecurity teams.Deep experience in applying knowledge of Cybersecurity policies, Cybersecurity standards, Cybersecurity controls, Cybersecurity programs and frameworks to third party security contract negotiations and international cybersecurity regulations.Experience with NIST CSF, ISO 27001, NIST 800.30, FFIEC, and SEC Regulation S-P industry standards, frameworks, and regulations for Information Security.Subject Matter Expertise in using the Standard Information Gathering Questionnaire (SIG) to conduct third party security assessments.Experience with evaluating SOC reports, ISO 27001 certifications, and other internationally recognized independent attestations for evaluating third party security controls.Proven expertise in related security domains (e.g., security risk assessments, audits, controls definition/testing, etc.).Comfortable collaborating with Business and Cybersecurity leadership on security contract risks, third-party security assessment risks, and negotiating their resolution.Experience in IT Governance, Compliance, and Risk management processes and tools (MetricStream, RSA Archer, OneTrust or similar eGRC platforms).Bachelor’s degree in Computer Science, Computer Information Systems, or an equivalent combination of education, certifications, and experience.Proficient use of Microsoft Outlook, Microsoft Teams, Microsoft SharePoint, and Microsoft Office 365.Preferred professional qualifications with certifications (CISSP, CISA, CISM, CRISC, etc.).Strong contract negotiation skills.Problem solving/analytical skills, research skills, and technical aptitude.Exceptional executive presence and ability to communicate complex security topics to senior leadership.Good interpersonal skills, team participation skills, and a positive work ethic.Exceptional attention to detail.Able to multitask and prioritize effectively.Effective partnership & collaboration.