Ability to work independently on larger, moderately complex projects/assignments
Experience assessing technology-related risks and ensuring compliance with regulations, policies, standards, and controls
Capability to provide guidance to less experienced GRC Analysts
Ability to lead process improvement efforts within the Information Security team
Career Level P2: Works to achieve day-to-day objectives with moderate impact on the area; sets objectives for own area
Responsibilities
Develops and maintains cybersecurity policies, standards, and guidelines
Implements and monitors compliance with cybersecurity control framework
Ensures policies are up-to-date and align with industry best practices, regulatory requirements, and cyber frameworks
Communicates policies to relevant stakeholders
Independently develops security awareness training programs and materials
Plans and executes cybersecurity awareness events and communication campaigns
Develops, organizes, and delivers training sessions to employees on security policies and best practices
Monitors and reports on the effectiveness of security awareness initiatives
Collects, analyzes, and presents cybersecurity program performance metrics and key risk indicators (KRIs)
Independently conducts regular assessments of cyber risks within applications, platforms, and processes
Identifies risks and develops mitigation strategies and risk management plans
Manages third-party risk by assessing the security posture of external vendors and partners, implementing risk mitigation measures, and fostering secure third-party relationships
Ensures appropriate design and operating effectiveness of regulatory and PCI-DSS controls
Manages privacy-related data subject access requests
Monitors compliance and reports effectiveness
Independently performs periodic gap assessments to validate compliance
Monitors regulatory environment and performs impact assessments
Partners with auditors and manages action plans in response to audit discoveries