This position is responsible for serving as a thought leader in the governance, risk and compliance space; planning, designing, enforcing and auditing information technology and information security policies, standards and procedures which safeguard the integrity of and access to enterprise systems, files and data elements; analyzing, tracking and acting on information technology or information security policy exceptions, audits and assessments; maintaining knowledge of changing technologies, and provides recommendations for adaptation of new technologies, processes or policies; recognizing and identifying potential areas where existing information technology or information security policies, standards and procedures require change, or where new ones need to be developed, especially as a result of future business expansion and technology advances; providing management with analysis via risk assessments and briefings / reports to advise them of critical information technology / information security issues that may affect the company’s business objective and / or compliance; collaborating with and feeds it risk information into the enterprise risk management program; evaluating and recommending information technology and information security products, services and/or processes to reduce risk and maintain compliance with applicable policies, mandates, laws and regulations; implementing the activities associated with the information technology and information security awareness programs and provides education and training on information technology and information security policies, standards and practices; performing control assessments and works with appropriate subject matter experts (SME’s) to document remediation plans; serving as a project lead and mentor to junior GRC team members.
Stand Out From the Crowd
Upload your resume and get instant feedback on how well it matches this job.
Job Type
Full-time
Career Level
Senior