Director, Regulatory Compliance
Dallas
Applications have closed
Santander
Our purpose is to help people and businesses prosper. We strive to make all we do Simple, Personal and Fair.The Information Security Governance, Risk and Compliance (GRC) function is an integrated component of the Santander US Information Security Program.
As part of the Technology Information Security GRC Team this role will report to the Head of Information Security GRC. The Associate Director, Information Security GRC, will play a key role in the GRC team driving strategic initiatives alongside maintaining operational excellence of existing processes.
Responsibilities:
· Manage and monitor technology, audit and regulatory risk through governance, oversight and reporting.
· Manage audit and regulatory calendar including all regulatory/audit interactions, findings, and regulatory reviews. This includes interaction and coordination of team members across the organization.
· Drive annual Information Security compliance attestation processes across US entities.
· Support a data-driven program using data and reporting.
· Manage key strategic initiatives relating to Third Party Risk Management and Vendor Management.
· Identify, Assess, and manage Information security risks. Provide oversight of remediation activities and timelines.
· Be a Coach / Mentor to junior team members.
Required Skills
· Demonstrated experience working with key Information Security frameworks including NIST and FFIEC CAT.
· 7+ years of experience in related work.
· Pro-active approach to problem solving, with experience in identifying areas of improvement, determining, and implementing solution.
· Knowledge of domestic and international laws governing information security; ability to interpret and take action on the aspects of information security laws that impact the business.
· Knowledge of technologies and technology-based solutions dealing with information security issues; ability to apply these in protecting information security across the organization.
· Knowledge of tools, techniques, approaches and processes of cybersecurity risk management; ability to ensure organizational network operation and minimize negative effect by cybersecurity risks.
· Understanding of the importance of inter-team collaboration in breaking down silos and achieving business results; ability to lead employees from various functions to communicate, coordinate work across divisions, and collaborate in solving problems as one team.
· Understanding of the importance of "big picture" thinking and planning and ability to apply organizational acumen to identify and maintain focus on key success factors for the organization.
· Demonstrated understanding of technological trends and developments in the areas of information security, risk management, web architectures, and cloud computing.
· Ability to maintain and implement best practices within Information Security
· Ability to drive execution of goals through effective planning, prioritization, resource management and follow through.
· Ability to manage multiple, ongoing initiatives.
Diversity & EEO Statements: At Santander, we value and respect differences in our workforce and strive to increase the diversity of our teams. We actively encourage everyone to apply.
Santander is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, genetics, disability, age, veteran status, or any other characteristic protected by law.
Working Conditions: Frequent Minimal physical effort such as sitting, standing and walking. Occasional moving and lifting equipment and furniture is required to support onsite and offsite meeting setup and teardown. Physically capable of lifting to fifty pounds, able to bend, kneel, climb ladders.
Employer Rights: This job description does not list all of the job duties of the job. You may be asked by your supervisors or managers to perform other duties. You may be evaluated in part based upon your performance of the tasks listed in this job description. The employer has the right to revise this job description at any time. This job description is not a contract for employment and either you or the employer may terminate at any time for any reason.
The base pay range for this position is posted below and represents the annualized salary range. For hourly positions (non-exempt), the annual range is based on a 40-hour work week. The exact compensation may vary based on skills, experience, training, licensure and certifications and location.
Base Pay Range
Minimum:
$157,500.00 USDMaximum:
$215,000.00 USDTags: Cloud Compliance FFIEC Governance NIST Risk management Vendor management
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.