Hyundai Capital America-posted 3 months ago
Senior
Irvine, CA
5,001-10,000 employees
Credit Intermediation and Related Activities

The Sr. Cybersecurity Compliance Manager is responsible for tasks and projects that support HCA process and technology compliance with company policies, regulatory requirements, and industry standards. This role will conduct compliance related research, program development, monitoring, and support internal/external assessments, including consulting with stakeholders regarding applicable compliance requirements.

  • Design, develop, and implement programs supporting compliance with HCA policies, PCI-DSS, IS27001:2022 (GSIF), FFIEC, GLBA, NYDFS Cybersecurity Regulation, and other relevant regulations.
  • Manage the internal/external audits/assessments (i.e., evidence identification, interpretation, validation, and delivery) regarding compliance with requirements for HCA policies, PCI-DSS, IS27001:2022 (GSIF), FFIEC, GLBA, NYDFS Cybersecurity Regulation, and other relevant regulations by collaborating with internal audit.
  • Monitor system operations associated with HCA policies, PCI-DSS, IS27001:2022 (GSIF), FFIEC, GLBA, NYDFS Cybersecurity Regulation, and other relevant regulations. Overseeing required remediation when security gaps/observations are identified.
  • Develop metrics and reporting to identify cybersecurity compliance gaps and priorities for leadership awareness/attention. Serve as the cybersecurity advisor for compliance assurance.
  • Participate with the execution of Information Security risk management initiatives including IT Operation Risk Assessments, Cloud Application Risk Assessments, and Vulnerability Risk Assessments.
  • Minimum 8 years progressive work experience in cybersecurity governance, risk management, or compliance within a private sector company environment significantly governed by Federal and state regulations.
  • Bachelor's degree in Cybersecurity, Information Security, Risk Management, or related field.
  • One or more certifications in CISSP, CGEIT, CRISC, CISM required.
  • Expert knowledge of Information Security risk management frameworks, Governance, Risk, and Compliance process.
  • Expert knowledge of PCI-DSS 4.0 and Information Security & Risk Frameworks including, but not limited to ISO 27001:2022, ISO27005:2022, NIST SP 800-30, NIST SP 800-37.
  • Expert knowledge of California Consumer Privacy Act (CCPA), Gramm-Leach-Bliley Act (GLBA), NYDFS Cybersecurity Regulation, FFIEC, SOX, and other relevant laws and regulations.
  • Understanding of financial regulatory frameworks and cybersecurity best practices.
  • Ability to communicate complex security concepts to business leaders and technical teams.
  • Medical, Dental and Vision plans that include no-cost and low-cost plan options
  • Immediate 401(k) matching and vesting
  • Vehicle purchase and lease discounts plus monthly vehicle allowances
  • Paid Volunteer Time Off with company donation to a charity of your choice
  • Tuition reimbursement
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service