Responsibilities and Accountabilities :
- Complete Objectives and Key Results (OKR) as established by value teams, ensuring alignment with overall business goals.
- Ensure risk assessment methodology, policies, standards and methods are in place to effectively manage regulatory, operational, and third-party risks across global business units.
- Establish third party risk management standards including due diligence processes, contract terms, audit rights, and ongoing monitoring.
- Develop and manage third party risk assessment program (KPI) and (KRI) metrics
- Ensure monitoring for risk management lifecycle to include procedures for the risk register, risk exceptions, risk acceptance and management escalation based on the level of associated risk.
- Ensure risk assessments are performed to identify and prioritize potential threats and vulnerabilities
- Interpret and analyze third party security risk assessment results, report findings to business owners, and provide recommendations for remediation
- Develop risk mitigation strategies and action plans in alignment with business objectives.
- Act as a risk advisor to the business by analyzing, simplifying, and expressing complex problems in an easily consumable and meaningful way
- Manage remediation plans to respond to previously unidentified or inadequately addressed risk areas
- Monitor and assess IT risks on an ongoing basis and make recommendations for risk reduction
- Evaluate existing risk monitoring metrics and tools, develop metrics and continue to enhance maturity of analytics. Develop security reports and dashboards for varied audience
- Understand legal requirements and identify emerging security risks working with the relevant business groups to facilitate proactive implementation of mitigation measures
- Implement tool to streamline and mature risk assessment activities
- Develop and maintain documentation related to security requirements, policies, and procedures.
- Providing training and support to teams on compliance-related matters and best practices.
- Monitor industry trends and emerging threats to inform cyber and product security strategies.
Requirements
Required Qualifications :
Bachelor's degree in Computer Science, Information System or related field8+ years of IT and / or security experience in a position related to this role (e.g., information security, compliance, audit, risk, etc.)Demonstrated experience with security best practices and risk management operating in cloud environments such as AWS, Azure and in other 3rd party SAAS platformsDemonstrated experience in third party risk management, managing security risks, developing and implementing security training programsDemonstrated experience in teaming skills incorporating global cross-functional teams, peer relationships, informing, and understanding and appreciating differencesKnowledge of emerging technology risks, including cloud computing, agile development / CICD, cybersecurity, and privacyOrganized self-starter; versatile and capable of working with minimal management oversightProficient time management skills and ability to juggle multiple, competing prioritiesKnowledge and understanding of information security best practicesStrong consultative skills, with the ability to advise and consult with business and technical professionals.Preferred Qualifications :
Relevant certifications (e.g., CISSP, CISM) are a plus.