Expedia

Information Security Control Assurance Senior Manager

Heredia, Heredia Province, Costa Rica

Not SpecifiedCompensation
Senior (5 to 8 years), Expert & Leadership (9+ years)Experience Level
Full TimeJob Type
UnknownVisa
Information Services, Financial ServicesIndustries

Company Description

Experian is the world's leading global information services company, unlocking the power of data to create more opportunities for consumers, businesses, and society. We are thrilled to share that FORTUNE has named Experian one of the 100 Best Companies to work for. Also, for the last five years we've been named in the 100 "World's Most Innovative Companies" by Forbes Magazine. Experian prioritizes our culture and look to bring people to the team who are passionate about their jobs, who are easy to work with, and who continue to value team over self.We have 23,000 people operating across 44 countries and every day we're investing in new technologies, experienced people, and new ideas to help all our clients maximize every opportunity.

Job Description

As an Information Security Control Assurance Manager, you will lead a team evaluating security controls for both on-premise and cloud processes to mitigate risks and ensure compliance with regulatory standards. Reporting to the Global Head of Information Security, you will direct the team in testing security controls to verify their design, implementation, and operational effectiveness. Working in an Agile environment, you will ensure the quality of security assessments through testing, automation, and collaboration with various teams and partners.

Summary of Primary Responsibilities

  • Oversee the information security control testing program, collaborating across regions.
  • Manage a team of testers to assess information systems per corporate security standards.
  • Design repeatable testing methodologies, including automation for cloud environments.
  • Plan control tests with risk identification, sampling, control selection, testing methods, and reporting criteria.
  • Manage teams in testing the design and effectiveness of security controls, including fieldwork and reporting.
  • Ensure quality assurance for control testing documentation.
  • Compile management reports and presentations on risks, controls, and deficiencies.
  • Be the primary contact for control tests, ensuring quality engagements and partner communications.
  • Improve the efficiency of the control testing program by standardizing indicators and testing materials.

Qualifications

What your background is

  • Bachelor's degree in computer science, management information systems, or equivalent experience.
  • 3+ years managing IT auditors or Information Security control assessors.
  • 12+ years in IT Audit or Information Security control assessments, including cloud security controls.
  • Professional certifications like CISA, CISM, CISSP, ISO 27001 Lead Auditor.
  • Knowledge of standards like NIST 800-53, ISO 27001/27002, CIS Controls, COBIT.
  • Experience with automated and manual methods for evaluating security controls on-premise and in cloud environments.
  • Communicate complex information.
  • Use partner feedback to improve processes.

Technical Skills

  • Knowledge of security tools like Sailpoint, Rapid7, Wiz.io, MS Defender.
  • Experience with cloud security in AWS and Azure.
  • Automation, data-driven testing techniques, and generative AI for control assurance.
  • Create queries and reports using RSA Archer and ServiceNow.
  • Familiarity with Kanban boards and Jira.

Desired Competencies

  • Big 4 consultant experience.
  • Knowledge of cybersecurity principles: integrity, availability, authentication, non-repudiation.
  • Mentor junior team members, encouraging continuous improvement.
  • Security reporting to senior management on posture, control effectiveness, risks.
  • Apply security governance, risk, and control principles.
  • Proficiency in automation and data analytics tools (Excel, Tableau, Alteryx, PowerBI).
  • Agile working methodology experience.

Additional Information

This is a permanent home-based role in Costa Rica. No relocation available.

Culture at Experian

Our uniqueness is that we value yours. Experian's culture, people, and environments are main differentiators. We take our people's agenda very seriously. We fo

Skills

Information Security
Control Assurance
Risk Mitigation
Regulatory Compliance
Security Control Testing
Cloud Security
Agile Environment
Quality Assurance
Automation

Expedia

Travel booking platform for flights, hotels, rentals

About Expedia

Expedia Group operates in the travel industry, offering a wide range of services for travelers and travel-related businesses. It connects users with options for flights, hotels, car rentals, vacation packages, and activities through its various brands, including Expedia, Hotels.com, and Vrbo. Travelers can easily find and book trips that match their preferences and budgets. The company earns revenue primarily through commissions on bookings and advertising from travel service providers looking to promote their offerings. Additionally, Expedia Group supports its partners by providing access to valuable data and technology, helping them improve their operations and grow their businesses. The goal of Expedia Group is to create a seamless travel experience for users while maximizing the potential of its partners.

Bellevue, WashingtonHeadquarters
1996Year Founded
$3,277.3MTotal Funding
IPOCompany Stage
Consumer Goods, EntertainmentIndustries
10,001+Employees

Benefits

Competitive Paid Time Off
Travel Discounts
Healthcare Flexible Spending Accounts
Employee Assistance Program
Wellness & Travel Reimbursement
Workplace Accomodations
Medical, Dental, & Vision Insurance
Matching Gifts
New Parental Benefits

Risks

Riyadh Air's entry could increase competition, affecting Expedia's market share.
CFO transition may lead to strategic shifts impacting financial management and investor confidence.
Expedia's partnerships may strain resources, affecting service quality if not managed well.

Differentiation

Expedia offers a comprehensive suite of travel services under one platform.
The company leverages a diverse portfolio of brands like Hotels.com and Vrbo.
Expedia provides partners with valuable data and technology to optimize their offerings.

Upsides

Expedia can capitalize on the rise of 'workcations' with longer stay packages.
The trend of 'bleisure' travel offers opportunities for specialized leisure-business packages.
Increased demand for personalized travel experiences can enhance user engagement for Expedia.

Land your dream remote job 3x faster with AI