Working as part of the Regional Information Security Office within the IT department, the Sr Cyber Risk and Assurance Specialist will be responsible for support the day-to-day IT Security Governance, Risk and Compliance management functions. The role will include primary responsibility for managing IT and organizational policies and standards in support of legal and regulatory compliance needs as well as general IT and organizational information security practices.
Key Responsibilities
Collaborate to define IT security standards and develop supporting organizational policies.
Support IT security compliance assessments on new and existing systems, processes, technology.
Support vendor due-diligence process and help to lead and define overall third party risk management efforts.
Work with various business units to ensure controls are adequate, appropriate, and effective.
Support internal and external audit process for relevant IT Security concerns including PCI-DSS, SOX.
Perform business impact analysis and assist with development of IT/InfoSec risk register.
Interface with global IT and business partners to provide guidance and support about the IT Security landscape.
Perform periodic gap assessments to validate compliance on an ongoing basis.
Stay up to date and informed on developing regulatory concerns and changing regional IT and information security risk trends.
Proactively look for, documents and escalate cyber security risks in the region as appropriate.
Spanish – native,
English – Full bilingual.
Portuguese - a plus