Information Security Risk Officer
Core
Enforce the Information Security Framework, conduct internal risk assessments, and manage the Information Security Risk Management Program to safeguard business operations.
Role type
Information Security Risk Officer (GRC)
Builds
Risk assessments, remediation strategies, and security posture reports for the organization
Domain
Information Security / GRC / Risk Management
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Risk assessment, risk analysis, remediation strategy development, risk register management, regulatory compliance knowledge, technical security knowledge (operations, physical, network, host, application, architecture, virtualization, cloud), report writing, stakeholder communication
Preferred skills
CRISC, CGRC, CISSP certifications
Technologies
ISO 27005, ISO 27001, NIST CSF, NIST 800-53, DORA, GDPR
Responsibilities
Plan and execute technical risk assessments in IT infrastructure, applications, technologies, and third parties; Assess internal controls, processes, and policies related to IT and Security, identify deficiencies, and develop remediation strategies; Perform risk analysis on current risks and identify potential risks at operational, tactical, and strategic levels; Maintain the risk register and the Information Security Risk Management Program; Identify information security risks and make recommendations that are appropriate, practical, and cost-effective; Manage and monitor the progress of remediation steps on risk assessment findings; Prepare comprehensive reports summarising the actions taken for to remediate identified risks; Provide regular reports and metrics on the security posture of the company; Act as the escalation point of the information security department for any information security related risks
Seniority
Mid-level, hands-on IC