Information Security Officer
Core
Implement and maintain the organization's information security program, protect people and information assets, and assess third-party supplier security.
Role type
Information Security Officer
Builds
Secure supply chains of information systems and compliant third-party service agreements
Domain
Information Security / Cybersecurity
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Information Security Governance, policy and procedure development, third-party security due diligence, security assessments (cloud/outsourced services), risk identification, GDPR compliance, DORA regulation knowledge, ISO27001, NIST CSF, NIST 800-53
Preferred skills
CompTIA Security+, ISC2 CC, EC-Council CEH
Technologies
ISO27001, NIST CSF, NIST 800-53, GDPR, DORA
Responsibilities
Identify and address security violations and inefficiencies in systems and applications; Conduct due diligence of third-party service providers' security controls and ensure compliance; Perform security assessments on third-party software and services; Monitor and seek assurance on third-party compliance to improve security standards; Work with Legal to ensure adequate security provisions in third-party contracts; Make recommendations for improving controls to reduce security risks; Initiate and promote information security awareness activities.
Seniority
Junior to Mid-level, hands-on IC
