Governance, Risk and Compliance Manager
United States
Applications have closed
- Manage the development, implementation, and maturity of Conair’s Information Security Risk Management Program
- Partner and coordinate with IT stakeholders, auditors (internal/external), management, and other groups to best address relevant risks to Conair as part of 3rd party risk management, Payment Card Industry (PCI), and Sarbanes Oxley compliance.
- Lead the selection process and implementation of a GRC platform
- Continuously identify areas of improvement, create action plans, and execute to implement changes in a timely manner.
- Develop a cloud risk management program to support Conair’s expansion into public cloud infrastructure.
- Acts in a key role supporting technology compliance initiatives.
- Own and maintain security policies and procedures in support of legal, regulatory and compliance objectives.
- Conduct routine and ad-hoc information security risk assessments and or compliance reviews.
- Supporting vendor due-diligence process and help with overall third-party risk management efforts.
- Supporting vulnerability management efforts, which include remediation tracking, status reporting and program enhancements.
- Maintain the Conair Risk Register
- Assist with data analytics and compile metrics.
- Training & Awareness:
- Assist with documentation (e.g., desktop procedures, newsletters, tip sheets, and security alerts/advisories)
- Work with the Global Security Team to coordinate logistics for Training and Awareness exercises across Conair.
- Acts as a key resource driving the security awareness strategy and developing a security conscious culture.
- 5+ years of experience in IT risk management, IT governance, or internal controls.
- Experience with implementing and operationalizing IT General Controls, CIS Critical Security Controls, and/or other similar security frameworks.
- Knowledge of SAP controls
- Experience with Microsoft Purview
- Experience in ensuring compliance with multiple compliance requirements, include Payment Card Industry (PCI) and SWIFT as well as familiarity with privacy requirements.
- Experience in major cloud security provider security and protection techniques which would include security assessments and the application of enterprise security strategies, etc.
- Practical & technical understanding of network, system, application, cybersecurity, and cloud security controls.
- Experience with policy development and designing information security controls.
- Knowledge regarding risk management practices, GRC concepts, and automation tools.
- Involvement in coordinating cyber security awareness programs.
- Experience with PowerBI is a plus
- Knowledge of, and experience using Third-Party Risk Management methodologies.
- Strong understanding of the MS O365 Suite including SharePoint
- Ability to work in or lead projects with cross-functional teams for projects and initiatives.
- CISA, CISSP, CCSK, CRISC, CIPP, or other professional certifications/associations is a plus
- Bachelor’s Degree in computer information systems, cybersecurity or a related field
- This position is Remote but the candidate must live in the Metro NYC area.
- Working conditions are normal for an office environment.
- Must be able to sit for extended periods of time.
- Must be able to use a computer keyboard and view a monitor for extended periods of time.
- Must be able to travel domestically and internationally for business (% if needed)
- This position is remote but the candidate must live in the Metro NYC area.
- Comprehensive Medical/Dental/Vision plans
- Generous Paid Time Off Programs
- Life & Disability Insurance
- FSA/HRA/Dependent Care FSA
- Paid Parental Leave
- 401k and company match
- EAP & Employee Wellness Programs
- Volunteer Days Paid Time Off
- Free Lunch at our Stamford location
* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰
Tags: Analytics Automation CCSK CIPP CISA CISSP Cloud Compliance CRISC Data Analytics Governance Privacy Risk assessment Risk management SAP Security assessment SharePoint Strategy Vulnerability management
Perks/benefits: 401(k) matching Career development Health care Insurance Medical leave Parental leave Wellness
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.