\r\nWe are seeking a skilled and experienced cross-functional Governance, Risk, and Compliance consultant that can work with IT Compliance and IT Risk on assessments, testing, reporting, and risk analysis within the Information Security Program.
\r\n
\r\nKey Responsibilities:
\r\nAssessments: Perform Risk Assessments to ensure proper design and associated risks (inherent and residual) for systems, environments, and domains analyzed.
\r\nAbility or understanding to gather information to determine threat event frequencies, loss event frequencies, susceptibility, and impact.
\r\n
\r\nTesting: Ability to test the design and operating effectiveness of quarterly/re-occurring IT controls that support our regulatory assessment programs (SOX, NYDFS, etc.).
\r\nAbility to determine proper design of processes and ineffective processes and key elements of an effective process design.
\r\nUnderstanding of key control points and able to perform walkthroughs and/or review of evidence to determine operating effectiveness.
\r\n
\r\nRisk Identification and Mitigation: Collaborate with cross-functional teams to identify emerging risks, assess their potential impact on the organization, and develop mitigation strategies.
\r\n
\r\nReporting: Ability to contribute towards creating reports for different audiences for IT and non-IT stakeholders (senior management, executive leadership, system owners, and relevant stakeholders) to facilitate decision-making and drive continuous improvement efforts.
\r\n
\r\nPreferred Qualifications:\r\n
T-mapp
Interapt
Vneuron Risk & Compliance
Coalition, Inc.
Wiz