Lead Info Security Analyst - Issue and Regulatory Support
Role details
Job location
Tech stack
Job description
The Lead Information Security Analyst (Cybersecurity) is responsible for strengthening Global Cybersecurity and Fraud Management (GCFM) control programs by implementing and supporting assessment readiness activities, as well as monitoring, escalating, reporting, and influencing the prioritization of significant risks and control weaknesses.
The GCFM organization is responsible for keeping pace with the ever-changing cybersecurity and fraud management landscape, safeguarding the company's assets from threats and attacks, and managing information technology and security risks and incidents.
The Lead Information Security Analyst serves as the primary interaction point between GCFM Control and Control Program owners and line of defense partners, as well as external assessors and auditors., * Relationship Management - Build and maintain effective relationships with key stakeholders across all three lines of defense and with internal and external business partners to successfully address current regulatory examinations, audits, and inquiries, and prepare for future ones.
- Issue Management - Support the Holistic Issue Management enterprise program and provide appropriate governance and oversight for the GCFM Issue Portfolio. Ensure the execution of program requirements and support activities required to document and report on risk remediation activities.
- Regulatory Support - Communicate the schedule of regulatory exams that impact IT, assess readiness, and provide support for interactions with regulators and assessors. Track information requests, perform preliminary reviews of artifacts prior to submission to legal and compliance partners, and schedule meetings with regulators as needed. Govern regulatory findings as they are documented and tracked as formal issues.
- Assessment Readiness - Maintain and develop the GCFM evidence catalog to support ongoing assessment readiness.
Requirements
- University (Degree) Preferred, * 5 or more years of working experience in Cybersecurity/Information Security, IT/Technology Risk Management, IT/Technology Compliance, IT/Technology Audit, or Information Technology.
- Experience with Cybersecurity/Information Security-related laws, regulations, and control frameworks, such as NIST CSF, and experience with control testing of technology risks, controls, policies, and standards.
Preferred Qualifications
- Experience independently evaluating and/or performing risk and control assessments and audits across Cybersecurity/Information Security domains.
- Professional certifications including CISSP, CISA, CRISC, CISM, and/or CCSP.
Related Skills
Accountability, Adaptability, Business Continuity Planning, Cloud Computing Security, Collaboration, Communication, Compliance, Consultative Communication, Cybersecurity, Detail-Oriented, General Risk Management, Network Security, Prioritizes Effectively
Benefits & conditions
Actual base salary may vary based upon, but not limited to, relevant experience, time in role, base salary of internal peers, prior performance, business sector, and geographic location. In addition to base salary, the competitive compensation package may include, depending on the role, participation in an incentive program linked to performance (for example, annual discretionary incentive programs, non-annual sales incentive plans, or other non-annual incentive plans).