Primary Responsibilities
This individual will:
Build and manage the Cybersecurity Risk Management function.
Establish and maintain policies and standards.
Determine current state of cybersecurity controls through interviews and evidence.
Document where controls do not meet policy or regulatory requirements.
Work with technology owners to define and plan control enhancements efforts to reduce risk and satisfy regulatory
requirements.
Create technology roadmaps to illustrate current state and the path to our desired state.
Support Cybersecurity governance through reporting and tracking of projects for broader awareness.
Participate in the third-party assessment process.
Conduct risk assessments.
Facilitate and manage external audits.
Qualifications
Required Education, Skills and Competencies
Working knowledge of NIST 800-53 or how to work with cybersecurity frameworks in general.
Breadth of knowledge on cybersecurity controls.
Ability to organize and structure large amounts of information to facilitate programs, processes and compliance.
Program management
Strong analytical skills.
Ability to organize and run effective meetings.
Strong analytical and communication skills.
Interpersonal skills to develop strong collaborative working relationships with a broad range of constituents.
Excellent written and verbal communication skills;
Exceptional attention to detail;
Interest in and ability to interact effectively with diverse groups of people;
Great problem-solving and decision-making skills;
Ability to work independently and with minimal supervision; and
Ability to be discrete and keep sensitive information confidential.