Assistant Manager – Information Security Risk and Governance

JTC Group

Colombia

A distancia

COP 60.000.000 - 90.000.000

Jornada completa

Hace 3 días
Sé de los primeros/as/es en solicitar esta vacante
Generador de candidaturas

Transforma esta oferta en una entrevista: un currículum y una carta de presentación creados pensando en lo que quiere el empleador.

Supera los filtros ATS

Descripción de la vacante

JTC Group in Colombia is seeking an Assistant Manager to support the Information Security Risk and Governance functions across the group's global IT landscape. You will help deploy control oversight, perform risk assessments, and assist in business continuity planning and audits.

The role requires strong communication, detail oriented work, familiarity with GRC solutions and Azure infrastructure, and the ability to translate security controls into practical guidance for teams.

Formación

  • Relevant academic and/or professional certifications are required.
  • Experience in Information Security Risk and Governance is essential.
  • Strong technical skills with a risk-based approach including GRC solutions and Azure.
  • Familiarity with information security frameworks, policies, standards and controls.
  • Excellent attention to detail and clear communication skills.
  • Ability to propose innovative approaches to evolving information security risks.

Responsabilidades

  • Policy Enforcement: support implementation of security policy and standards.
  • Governance, Risk and Compliance: perform risk governance duties.
  • Risk Management: maintain and update risk registers and escalations.
  • Assessments: conduct proactive risk assessments across domains.
  • Business Continuity: assist with BCPs and BIAs, RTOs and RPOs.
  • Due Diligence: assist in client due diligence evidence gathering.
  • Audits: aid internal and external audit evidence collection.
  • Reporting and Analytics: support monthly security metrics reporting.
  • Training and Development: stay updated on security trends and controls.
  • Monitoring and Auditing: assist with access reviews and risk mitigation.
  • Documentation: maintain comprehensive role-related documentation.
  • Compliance: adhere to risk, compliance procedures and CPD requirements.

Conocimientos

InfoSec Risk & Governance
GRC solutions
Azure infrastructure
Information system frameworks
Attention to detail
Communication skills
Innovative approach

Educación

Relevant academic or professional certifications

Descripción del empleo

Assistant Manager – Information Security Risk and Governance

To support the Information SecurityTeam in managing and overseeing the daily operations of information securityrisk and governance controls to ensure the ongoing security and efficiency ofJTC’s global system. This role includesthe deployment of control oversight, assurance, testing and due diligenceresponsibilities as part of the Group’s overall Information Security strategy.

MAIN RESPONSIBILITIES AND DUTIES

  • Policy Enforcement: Either directly or in-directly support the implementation of the control requirements specified in our Information Security Policy and Standards and best practices. Be a central point of reference for any queries and questions in relation to Information Security Policies and Standards.
  • Governance, Risk and Compliance: Perform the applicable and necessary Information Security Governance duties, both directly and in-directly.
  • Risk Management: Maintain and update the Information Security Risk Register. As well as perform the necessary updates and escalations if necessary.
  • Assessments: Help perform the necessary proactive Information Security Risk Assessments (network, infrastructure, application and 3rd parties) to identify any control gaps and risks, then with the applicable stakeholders agree risk action plans in-line with the groups risk appetite and tolerance levels.
  • Business Continuity: Assist the Information Security Risk and Governance team head with the creation, management, review and maintenance of the Group wide Business Continuity Plans (BCP’s) and Business Impact Analysis (BIA’s). BIAs are to include documented ‘Recovery Time Objectives (RTO’s) and ‘Recovery Point Objectives (RPO’s) in line with business requirements and agreeable with Group Chief Information Office and Senior Director – Head of IT Infrastructure.
  • Due Diligence: Assist when required in completion and evidence gathering as part of client due diligence assessments as and when necessary, consistently, accurate and to a high standard.
  • Audits: Assist when required in completion and evidence gathering as part of internal and external audits as and when necessary, consistently, accurate and to a high standard.
  • Reporting and Analytics: Aid the Group Information Security Officer with the monthly analytical reporting which measures and tracks all IT security related information and initiatives and is delivered to key stakeholders.
  • Training and Development: Research and keep up to date with the latest information technology security trends, threats, vulnerabilities and control measures.
  • Monitoring and Auditing: Assist with user access reviews and address any inconsistencies or security related risks.
  • Documentation: Maintain comprehensive documentation in relation to role and responsibilities .
  • Adhere to Risk & Compliance procedures in relation to regulatory requirements and AML legislation.
  • Adhere to CPD requirements in accordance with qualification level and in-house procedures.
  • Adhere to JTC core values and expected behaviours.
  • Any other duties as deemed necessary by Management.

ESSENTIAL REQUIREMENTS

  • Relevant academic and/or professional certification(s).
  • Experience in Information Security Risk and Governance.
  • Strong technical skills with a risk-based approach, including experience with Governance, Risk and Compliance (GRC) solutions and Azure infrastructure.
  • Familiarity with Information System frameworks, policies, standards, best practices, processes, and controls.
  • Strong attention to detail.
  • Excellent communication skills both verbal and written.
  • Ability to demonstrate an innovative approach to emerging changes and advancements in information security risk and governance.

OUR COMMITMENT TO INCLUSION & WELLBEING

JTC is committed to fostering a healthy, inclusive organisation where all individuals feel welcome and feel able to participate in the workplace fully. We value different perspectives, backgrounds and lived experiences. This includes supporting employee wellbeing so that people feel equipped to thrive.

Whether you are just starting out or seeking new challenges, JTC offers an environment where you can grow, develop, and succeed at every stage of your career.

Stay up to date with expert insights, latest updates and exclusive content.

Consigue la evaluación confidencial y gratuita de tu currículum.
o arrastra y suelta tu archivo aquí
Similar jobs

Puestos de trabajo similares que vale la pena comparar

Accounts Officer – Finance
Accounts Officer – Finance

JTC Group • Colombia

Presencial
COP 20.088.000 - 35.712.000
InfoSec Risk & Governance Lead
InfoSec Risk & Governance Lead

JTC Group • Colombia

A distancia
COP 60.000.000 - 90.000.000
Finance Administration Trainee: Client Support & Billing
Finance Administration Trainee: Client Support & Billing

JTC Group • Colombia

A distancia
Sr Associate, Information Security Governance, Policy & Control
Sr Associate, Information Security Governance, Policy & Control

Auxis • Bogotá ciudad

Presencial
COP 200.880.000 - 334.800.000
TPM Framework & Strategy Specialist
TPM Framework & Strategy Specialist

Johnson & Johnson Innovative Medicine • Bogotá ciudad

Presencial
COP 60.000.000 - 120.000.000
Security Risk Governance
Security Risk Governance

Laborintos • Bogotá

Presencial
COP 156.905.000 - 235.359.000
Governance & Board Secretariat Specialist
Governance & Board Secretariat Specialist

JTC Group • Colombia

A distancia
COP 60.000.000 - 90.000.000
Senior Information Security Analyst
Senior Information Security Analyst

Ibope • Colombia

Presencial
COP 183.143.000 - 293.030.000
Third Party Risk Management Manager
Third Party Risk Management Manager

Auxis • Bogotá ciudad

Presencial
COP 90.000.000 - 140.000.000
CyberSecurity Manager
CyberSecurity Manager

Lean Solutions Group • Colombia

Presencial
COP 120.000.000 - 200.000.000