GRC & BCP Manager
Santurce - Lucchetti, United States
LUMA Energy
Job Summary:
As the Governance, Risk & Compliance (GRC) & Business Continuity Plan (BCP) Manager, you will have a key leadership role in Information Security Governance. This includes developing policies, procedures, and plans for all areas of information and operational security that comply with industry practices and applicable regulations, as well as and collaborating with team members to build-out reports/dashboards.The manager will lead cross-functional efforts to ensure that the IT OT business continuity plans and disaster recovery plans are implemented and will be responsible for developing and maintaining overall service continuity strategy, processes, plans, and procedures in alignment with LUMA business objectives and risk and readiness factors.
Job Description:
Develops and implements a comprehensive governance framework to ensure the company operates within legal and regulatory requirements.
Leads the development and implementation of company policies and procedures to support compliance with legal and regulatory requirements.
Oversees the cyber security program governance processes, such as cyber security risk reporting and recommends new report formats and technologies.
Leads incident response activities and participate in the review of relevant data and information related to data protection, user access review programs, third-party audits and compliance program, log reports, and other restricted information.
Identifies, prioritizes, and implements initiatives to ensure that potential disruptions of service are identified and that appropriate mitigate plans are in place in support of these requirements.
Conducts periodic risk assessments to identify areas of vulnerability and recommend appropriate mitigation strategies.
Develops and manages a business continuity program that ensures the organization can respond effectively to unplanned events and disruptions.
Develops and maintains crisis management plans and lead the response to incidents that may impact the organization's operations.
Collaborates with other departments to ensure they understand and comply with governance policies and procedures.
Provides regular reports to senior management on the status of the governance and business continuity programs.
Monitors and reviews existing policies and procedures to ensure they remain relevant and effective.
Works with organizational stakeholders to develop, implement, and maintain effective security and business continuity training programs.
Follows all policies and procedures.
Performs other duties as assigned.
Performs major storm restoration work and associated drills as assigned.
Additional Job Description:
Required Education and Experience:
Bachelor’s degree in business administration, Information Technology, Information Security, or a related field.
Minimum of 5 years of experience in information security governance, risk management, business continuity, or a related field.
Minimum 5-8 years of supervisory experience.
Strong analytical and problem-solving skills.
Excellent project management and organizational skills.
Excellent communication and interpersonal skills.
Preferred :
Master’s degree in business administration, Information Technology, or a related field.
Minimum of 8 years of experience in Governance, Risk, and Compliance (GRC), business continuity, or a related field.
Strong knowledge of relevant laws, regulations, and industry standards.
Required Licenses/Certifications:
Valid Drivers License
Preferred :
Professional certifications in relevant areas such as:
Certified Business Continuity Professional (CBCP)
Governance, Risk and Compliance (GRC) will be an added advantage.
Travel Requirements
Travels: Seldom
Percent of time: 10%
Physical Demands
If one-third of the time – “seldom” or “occasionally” If one-third to two-thirds of the time or more occasionally to frequently” If more than two-thirds of the time – “constantly”
Stationary Position -Seldom
Pushing/Pulling/Reaching - Seldom
Climb - Seldom
Kneel - Seldom
Grab - Seldom
Bend - Seldom
Lift/carry over - 5-10 LBS
Vision - N/A
Hearing - N/A
We are committed to diversity and inclusion, and it is because of this that we offer equal employment opportunity to both our employees and candidates, while also striving for an environment that is free of any form of discrimination and harassment. We base our employment decision solely on the qualifications of the individual, their merits, and the present needs of the business.
* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰
Tags: Audits Compliance Driver’s license Governance Incident response Risk assessment Risk management Strategy
Perks/benefits: Team events
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.