Sr Associate, Information Security Governance, Policy & Control

Auxis

Bogotá ciudad

Presencial

COP 200.880.000 - 334.800.000

Jornada completa

hace 2 horas
Sé de los primeros/as/es en solicitar esta vacante
Generador de candidaturas

No envíes un currículum genérico: crea un currículum y una carta de presentación adaptados a este puesto concreto.

Supera los filtros ATS

Descripción de la vacante

Grant Thornton in Bogotá seeks a Sr Associate, Information Security Governance, Policy & Controls, to drive policy development and risk management. You will oversee controls, monitor regulatory compliance, and partner with stakeholders to protect information assets in a matrixed environment.

The role emphasizes execution, change leadership, and deep expertise in information security frameworks, risk, and audit activities, with a focus on resilience and data protection.

Formación

  • Experience with information security risk management frameworks (NIST, ISO, COSO, HiTrust, CMMC).
  • Experience with regulatory requirements (PCI, GDPR, HIPAA, Privacy, CCPA).
  • Experience using GRC tools (RSA Archer, Security Scorecard, Risk Recon).
  • Experience gathering information from multiple sources to identify security weaknesses.
  • Expert in security control design, development, implementation and monitoring.
  • Demonstrated experience across multiple information security domains.

Responsabilidades

  • Develop or enhance information security policies, control objectives, controls and standards.
  • Develop and oversee control framework to prevent violations of guidelines and policies.
  • Deep functional expertise in information security policy, standards, risk & compliance.
  • Collaborate with process owners to document processes, risks and controls.
  • Perform control testing and compliance assessments to identify security risks.
  • Support front-line controls, self-assurance, and risk assessment activities.
  • Provide ongoing risk monitoring and status reporting within data governance processes.
  • Coordinate with stakeholders to review assessment results and drive actions.
  • Assess risk exposure and help establish policies to minimize risk.
  • Assist auditors with questions and findings related to security risk management.
  • Identify process improvements and promote best practices in reports and tools.

Conocimientos

English B2+ or Higher

Educación

Bachelor's degree in Computer Science, Engineering or related field or equivalent work experience

Herramientas

RSA Archer
Security Scorecard
Risk Recon

Descripción del empleo

Job Summary

The Sr Associate, Information Security Governance, Policy & Controls position will be an integral member of the Information Security and Risk Management team. This role will be will drive development of information security policy, standards and controls, and monitor compliance to regulations and policies, with the goal of safeguarding the company assets and maintaining confidentiality, integrity and availability of information. Work in Chief Information Security Officer (CISO) office under Associate Director, Information Security Governance, Risk and Compliance, this role serves as an information security professional for Grant Thornton.

Job Summary

The Sr Associate, Information Security Governance, Policy & Controls position will be an integral member of the Information Security and Risk Management team. This role will be will drive development of information security policy, standards and controls, and monitor compliance to regulations and policies, with the goal of safeguarding the company assets and maintaining confidentiality, integrity and availability of information. Work in Chief Information Security Officer (CISO) office under Associate Director, Information Security Governance, Risk and Compliance, this role serves as an information security professional for Grant Thornton. This is a change agent position. We are seeking breadth/depth of experience as a recognized expert, delivering business value and meeting commitments, operating across a matrixed environment, able to manage ambiguity and to reach understanding and gain commitment to act. Focus on successful execution/delivery of outcomes, and track record for driving change are critical. The successful candidate will have a good mix of technical knowledge, understanding of industry best practices, frameworks and regulations, and a demonstrated background in information security risk and compliance management program.

Responsibilities
  • Develop or enhance information security policies, control objectives, controls and standards aligned with information security regulations, best practices and frameworks.
  • Develop and oversee control framework to prevent or deal with violations of legal guidelines and internal policies.
  • Deep functional expertise in the area of information security policy, standards, guidelines and risk & compliance functions.
  • Partner with stakeholders, including process owners and control owners, to document processes/procedures (via process flows), risks, and controls.
  • Perform control testing and compliance assessments to identify and manage security risks and issues.
  • Support the execution of front-line controls, self-assurance, and risk assessment activities (ad-hoc controls review, business process management (BPM), risk control self-assessment (RCSA), and independent risk and audit activities as directed.
  • Provide ongoing assessment of InfoSec's risk profile through regular monitoring and status reporting of risks, issues, events, and initiatives within data governance processes
  • Support iterative review of assessment results, working with appropriate stakeholders across the lines of defense
  • Perform and facilitate the collection, review, and assimilation of risk assessment data and reporting into concise and meaningful reports
  • Assess exposure to risk, measure operational risk against ERM frameworks, assist in establishing policies and procedures to minimize risk, identify ways to protect the organization from data loss and reputational damage
  • Coordinate efforts with InfoSec's Issues Management and other Control Testing functions, to continually update control effectiveness and residual risk rating of InfoSec's business processes as needed
  • Assist with internal and external auditors to address and resolve audit questions and findings relative to core process of security risk management
  • Support the testing of control design and the testing of control effectiveness for assigned areas as needed
  • Identify areas of improvement in the existing processes, methodology, and policies. Identify gaps and recommend enhancements. Drive, adopt, and enforce best practices in report templates and tools
  • Perform other duties as assigned
Skills And Experience
  • English B2+ or Higher
Experience
  • Experience with information security risk management framework, assessment, audit and controls based on industry standard frameworks (i.e. NIST; ISO; COSO; HiTrust, CMMC)
  • Experience with regulatory requirements (i.e. PCI; GDPR; HIPPA; Privacy; CCPA; etc.)
  • Experience using GRC tools and technologies in support of the assessment/audit process (RSA Archer, Security Scorecard, Risk Recon, etc.)
  • Experience gathering information from a range of different sources to help identify weaknesses in security controls
  • Expert with security control design, development, implementation, and monitoring
  • Demonstrated experience across multiple information security domains preferred
Qualifications
  • Bachelor's degree in Computer Science, Engineering or related field or equivalent work experience
  • CISA, CRISC, CISM, or CISSP certifications (one or more) preferred
  • Demonstrated advanced verbal and written communication skills
  • Excellent organization skills and be a self-motivated learner
Consigue la evaluación confidencial y gratuita de tu currículum.
o arrastra y suelta tu archivo aquí
Similar jobs

Puestos de trabajo similares que vale la pena comparar

Sr Associate, Information Security Governance, Policy & Controls
Sr Associate, Information Security Governance, Policy & Controls

Auxis • Bogotá

Presencial
COP 186.347.000 - 372.694.000
Audit Manager, Information Security
Audit Manager, Information Security

Auxis • Bogotá

Presencial
COP 120.000.000 - 180.000.000
Senior Information Security Policy and Controls Architect
Senior Information Security Policy and Controls Architect

Auxis • Bogotá ciudad

Presencial
COP 200.880.000 - 334.800.000
Information Security Audit Manager: Risk & Compliance Lead
Information Security Audit Manager: Risk & Compliance Lead

Auxis • Bogotá

Presencial
COP 120.000.000 - 180.000.000
INTERNAL CONTROL SPECIALIST RBS
INTERNAL CONTROL SPECIALIST RBS

SGS • Colombia

Presencial
COP 120.000.000 - 180.000.000
InfoSec Policy & Controls Leader: Governance & Compliance
InfoSec Policy & Controls Leader: Governance & Compliance

Auxis • Bogotá

Presencial
COP 186.347.000 - 372.694.000
Security Risk Governance
Security Risk Governance

Laborintos • Bogotá

Presencial
COP 156.905.000 - 235.359.000
GRC, Cybersecurity, and Compliance Professional
GRC, Cybersecurity, and Compliance Professional

Yuxi Global powered by Veritas Automata • Medellín

Presencial
COP 286.205.000 - 477.008.000
Senior Information Security Analyst
Senior Information Security Analyst

Ibope • Colombia

Presencial
COP 183.143.000 - 293.030.000
CSIRT Incident Responder / Threat Hunter
CSIRT Incident Responder / Threat Hunter

Auxis • Bogotá

Presencial
COP 90.000.000 - 180.000.000