The IT Security Compliance Lead will oversee and manage the offshore IT Security Compliance team. This role will involve coordinating compliance projects, reporting on team initiatives and maintaining effective communication with external auditors and internal stakeholders.
The Job
10+ years experience in reviewing and updating policies, procedures and IT security controls.
Knowledge of SOC Audits, Payment Card Industry (PCI) and SOX reviews.
Knowledge of Information Security Frameworks such as NIST CSF, ISO 27001, CIS, etc.
Nice to have (certifications or equivalent experience): AWS (Solutions Architect, Security etc.), CISSP, CISM, CCSP, CGRC
Qualifications & Skills required
Maintain, prioritize, and report on offshore IT Security Compliance team initiatives/projects including Disaster Recovery, User Access Reviews, Third Party Risk Management, Internal and External Audit requests.
Responsible for the IT portion of the Service Organization Control (SOC 1 and SOC 2) audit. Collecting evidence from the various IT teams, serving as the primary point of contact for the auditors, addressing their needs and ensuring timely access to required information.
This position may also be involved in other business processes or IS assurance related engagements including SOX reviews.
Grooming NIST CSF and ISO 27001 controls for the organization.
Periodically updating corporate policies commensurate with information security compliance frameworks and best practices.
Managing the global monthly phishing campaign to enhance security awareness.
This position will involve direct reports and will work closely with the IT Security Compliance and Governance Director.