Responsibilities:
- Advise the board and senior management to ensure best-practice IT in internal controls, SOP, governance, risk, and audit
- Conduct internal audits to ensure organizational and program compliance with best practice and regulatory requirements, including Data Protection and contract requirements
- Perform security and compliance assessments on new and existing systems, processes, and technology.
- Collaborate to define IT security standards and develop supporting organizational policies.
- Work with various business units or departments to ensure controls are adequate, appropriate, and effective
- Participate in disaster recovery and business continuity planning, including backup systems
- Perform business impact analysis and assist with development of IT risk register
- Stay up to date and informed on developing regulatory concerns and changing IT and information security trends.
- Design, consult on, gain management approval for, implement, and change management for corporate compliance and risk processes to ensure governance & compliance are in place & well implemented
Requirements:
- Strong understanding of fundamental information security concepts and technology (IT Knowledge)
- Experience with IT Governance, risk, and compliance management in a large environment
- Experience in IT Governance, Risk & Compliance for SOP design, creation, seeking approval, implementation, and change management process
- Having certification in IT security will be a plus