Salary
💰 $135,320 - $159,200 per year
About the role
- Lead IT process and gap assessments against industry standards and technology regulatory requirements to evaluate control design and operating effectiveness
Design, review and validate processes and configurations across technology systems, including cloud environments, operating systems, databases, and network infrastructure, to ensure alignment with established standards, compliance requirements, and best practices
Assist in maintaining and providing oversight over the technology controls inventory to mitigate technology risks and meet regulatory requirements, technology policies, and frameworks
Collaborate with stakeholder teams including Security, Engineering, Technology Governance, IT, and Operational Risk to support technology requirements and ensure control ownership
Developing technology requirements for new products, updating existing controls, and providing subject matter expertise to product teams
Support Security Compliance, Information Security, Platform, and Engineering stakeholders in identifying and executing on continuous control monitoring opportunities
Provide guidance and leverage technical expertise to determine effectiveness of change management processes, i.e. unit testing, CI/CD, etc.
Define, draft and communicate identified issues and technology process improvement opportunities and assist in developing creative solutions to mitigate risks and address regulatory challenges
Provide reporting to stakeholders and management on progress, escalations, and control initiatives
Drive the creation of procedural documentation, including training materials that support first line of defense risk management, in the form of runbooks and narratives
Validate remediation efforts for identified gaps and issues to ensure resolution effectively aligns with regulatory requirements, industry standards, and internal policies
Drive creation of clear and concise technical documentation for control monitoring
Requirements
- Minimum of 2+ years of experience in Security Engineering, Technology Compliance, IT audit, or equivalent roles
Strong knowledge and hands-on experience in technology frameworks such as COBIT, NIST, ISO 27001
Hands on experience in security engineering, implementing security frameworks, or designing and managing technical controls
Proven technical understanding and operation within cloud technologies, AWS preferred
Strong understanding of control monitoring processes
Excellent oral and written communication skills
Ability to effectively and autonomously accomplish outcomes across cross-functional teams in ambiguous situations with limited supervision
Ability to multitask, prioritize work, and meet deadlines in a fast paced environment
Ability to communicate with technical and non-technical stakeholders to align on shared outcomes