Full-Time

Information Security Governance Specialist

Posted on 11/21/2024

Harris Computer

Harris Computer

Senior

Remote in USA + 1 more

More locations: Georgia, USA

Category
Cybersecurity
IT & Security
Requirements
  • Minimum of 5 years experience in IT security risk management or governance experience.
  • Minimum of 2 years experience as a system administrator, network administrator or in security operations may substitute 1 of the 5 years required experience above.
  • Minimum of 2 years experience in cloud services security
  • Knowledgeable about security controls and processes, vulnerabilities, regulatory and legal changes, and security standards that may impact information security
  • Hands on experience managing various security and governance, risk and compliance tools (e.g., Vulnerability Scanning, GRC Tools, etc.)
  • Experience in access control and identity management for on premise and cloud environments.
  • Ability to write security requirements and design documents.
  • Bachelor’s degree in Computer Science, Information Systems, Network Security Engineering or related major or equivalent work experience.
  • CISSP, CRISC, CISA, CDPSE, HCISPP certifications would be considered an asset
Responsibilities
  • Assist with the management of and participates in the information security, governance, and risk management programs according to established policy requirements.
  • Monitor the information security, governance, and risk management programs to ensure organizational controls and processes are appropriate to minimize security risks and to ensure compliance with various security standards and regulatory requirements.
  • Assist with the development, maintenance and publishing of up-to-date information security policies, standards, and guidelines.
  • Advise executive leadership and provide oversight of policies, standards and procedures related to information security and regulatory requirements as it relates to security controls and processes.
  • Lead and/or participate in various steering committees and other groups as appropriate.
  • Assist with the development of and oversee effective disaster recovery policies and standards to align with enterprise business continuity management program goals.
  • Responsible for conducting risk assessments against various regulatory compliance such as HIPAA, PCI, etc.
  • Perform risk and security assessments of applications, databases, and servers and supporting network technologies, such as routers, switches, access points.
  • Participate in annual security audits, incident response exercises, security reporting, audit, and compliance support.
  • Develop and execute corrective action and remediation plans for identified issues, risks, or vulnerabilities.
  • Assess potential risks and vulnerabilities to develop baselines and assist with response to deviations.
  • Manage the training awareness program, monitor compliance, and develop security training.
  • Review security control surveys, information security addendums and data protection addendums as required.
  • Develops and maintains standard practices and procedures for appropriate response to identified threats.
  • Analyzes and assesses with security incidents and escalates incidents by following incident plan.
  • Work with information security team to provide security incident escalation support and remediate security issues.
  • Assist with evidence collection for security audits and responding to security questionnaires.

Company Stage

N/A

Total Funding

N/A

Headquarters

N/A

Founded

N/A