Job descriptionRead, understand, and reference policies, standards, and guidelines as they pertain to information security, and identify instances of non-conformityCreate and update all documents related to ISO27001 and assist with ISO27001 auditsDevelop, implement, and update the Firm's US and international privacy policies, procedures, and processesOrganize initial and ongoing information privacy training for all staffPerform periodic risk assessments and ongoing compliance monitoringParticipate in the development and review of business associate and qualified service organization agreements to ensure that all privacy concerns, requirements, and responsibilities are addressedDevelop, implement, and manage data governance policies, procedures, and process to ensure availability, usability, integrity, and security of the data employed in the FirmIdentify old data and create lifecycle governance around all data in the Firm.Create policies around access to the Firm's data by the third partyHandle Third-Party Vendor management processes and procedures in regards to data governance, Risk, and compliance