Lead, develop, implement, and manage security compliance frameworks, policies, and procedures to ensure adherence to industry standards and regulations (e.g., ISO 27001, GDPR, HIPAA, etc.).
- Regularly review and update security policies to align with changes in regulations and technology advancements.
- Conduct risk assessments and audits to identify potential security gaps and recommend corrective actions.
Regulatory Compliance
- Stay abreast of changes in relevant security regulations and ensure the company's compliance with applicable laws and industry standards.
- Collaborate with legal and regulatory teams to interpret and implement security requirements.
Stakeholder Collaboration
- Partner with key stakeholders in Business Units, Technology, Compliance, Internal Audit, Legal, and Third Parties to provide security guidance, evidence, and artifacts for internal and external audits.
Internal Compliance Training and Awareness
- Develop and deliver security awareness training programs to educate employees on security best practices and compliance requirements.
- Work with cross-functional teams to promote a culture of security and compliance throughout the organization.
Documentation and Reporting
- Prepare and maintain documentation related to security policies, procedures, and compliance reports.
- Generate regular reports and metrics on compliance status and present findings to senior management.
Qualifications
- Bachelor's degree in Computer Science, Information Security, or related field (or equivalent work experience).
- 5 years of experience in information security compliance and assurance/CyberSecurity/IT Risk roles.
- Knowledge and experience with information security standards and methodologies, including the PCIDSS, ISO 27000 series, COBIT, Sarbanes Oxley, and other relevant industry security standards, and an in-depth knowledge of risk assessment and risk analysis
- Relevant certifications such as Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), or Certified Information Systems Auditor (CISA) are preferred.
- Proficiency in security assessment tools and methodologies.
- Excellent communication, leadership, and collaboration skills.
- Ability to adapt to a dynamic and evolving security landscape.