Risk - Cyber / Information Security
7 to 10 Years of experience
Certifications on PCI DSS,PMP
Job Responsibilities:
- Develop and refine risk assessment methodologies to ensure thorough and consistent risk identification and prioritization.
- Lead comprehensive information security risk assessments across the organization spans the business units and the bank critical applications (I.e crown jewels)
- Conduct application threat modeling as part of the applications security risk assessments.
- Maintain and update the Infosec Risk Register and Library, ensuring it accurately reflects the current risk landscape and contains detailed documentation of all identified risks.
- Oversee the development and implementation of risk remediation plans. Monitor progress and ensure timely completion of remediation actions.
- Implement continuous monitoring strategies to track the status of identified risks and the effectiveness of mitigation efforts.
- Conduct security risk assessments for potential and existing 3r parties through questionnaires, on-site visits, and review of documentation including assessment reports to identify control gaps and risks.
- Review the PACS process (risk assessment process covering Privacy, Architecture, Compliance and Security)
- Conduct regular audits and reviews to ensure compliance with internal controls and regulatory requirements related to information security.
- Identify compliance gaps and oversee the implementation of corrective actions to strengthen the security framework.
- Standardize the the Risk assessment process across the entities
- Establish KPIs/metrics for Cyber Risk Assessments and provide management reporting to colleagues and stakeholders
- Ensure that GRC solution (OneTrust) is configured to accurately reflect the organization's risk management framework and compliance requirements
- Utilize GRC Solution (OneTrust) to automate the risk assessment processes, ensuring consistent application of risk criteria and methodology across the organization.
- Develop custom risk assessment templates and workflows within OneTrust to meet the specific needs of different business units.
- Develop metrics for Security Risk Assessments and ensure they are monitored across all entities