Information Security GRC Manager
8 months ago
Responsibilities (how we will measure success)To provide second line support for all aspects of the Group’s Information Security strategy and arrangem.....
Responsibilities (how we will measure success)
To provide second line support for all aspects of the Group’s Information Security strategy and arrangements encompassing cultural, physical and technology elements throughout the business, with the primary focus being on Info Sec programme governance and oversight.
Working as part of the Group Risk and Compliance department, the second line Info Sec team interact regularly with the first line IT Security team, providing oversight, challenge and validation of operational controls and procedures. The role holder will work closely with business and technology teams to help articulate and communicate the Info Sec governance programme, identify risks and threats, and evaluate and help implement controls and improvements.
Tasks (what does the role do on a day-to-day basis)
- Support the management of Information Security governance for the organization, ensuring adherence to Group policies and standards.
- Work closely with the Group Risk and Compliance team to ensure key Information Security risks and issues are identified, addressed and resolved in a timely manner.
- Serve as the lead representative for the second line Information Security team in the region, working closely with local stakeholders to ensure Group security strategy is appropriately implemented, and regional requirements are understood and supported.
- Assist in management of the Group’s Information Security Management System including maintenance of the ISO 27001 certification.
- Engage with the first line IT Security Operations team and assist the Group CISO in providing oversight and challenge to that function.
- Participate in the security training and awareness programme including the compliance process, assessment of the threat landscape to inform the development of training content and publication of materials through corporate channels.
- Participate in periodic security testing activities (e.g. penetration testing, DR exercises) and prioritise and manage response activities.
- Assist with the audit and client management aspects of the Information Security team, including client due diligence questionnaires; help design more effective procedures in this space.
- Help improve and support relevant security metrics; analyse data, identify trends and drive improvements to the control environment.
- Assist in general Information Security related issues as required, including potential interaction with the Security Operations team, Technology teams and business stakeholders.
Official account of Jobstore.