Associate Information Security Risk Manager – Cebu City, Cebu

Please login or register as jobseeker to apply for this job.

TYPE OF WORK

Full Time

WAGE / SALARY

20000-30000

HOURS PER WEEK

TBD

DATE UPDATED

Sep 27, 2021

JOB OVERVIEW

Combine two of the fastest-growing fields on the planet with a culture of performance, collaboration and opportunity and this is what you get. Leading edge technology in an industry that's improving the lives of millions. Here, innovation isn't about another gadget, it's about making health care data available wherever and whenever people need it, safely and reliably. There's no room for error. Join us and start doing your life's best work.(sm)

Positions in this function are involved in facilitating and ensuring the organization's adherence to domestic and international laws, regulations, guidelines, policies, and specifications relevant to its collection, storage, use, and dissemination of data and informational assets in order to minimize the effects of financial, strategic, operational, and other risks. Positions in this function are also involved in analyzing, educating, and advising clients on information security/risk management topics within their business operations portfolios in order to help them make the best possible choices relative to risk mitigation. Educate and communicate security requirements and procedures to all users and new employees. Participate in sales and marketing strategy work with internal business partners and/or external clients. Advising on acquired entities and their risk portfolios.

Primary Responsibilities:

Provide day to day team leadership for third party supplier security risk assessment and remediation analysts
Contribute to employee coaching, development, and performance reviews
Manage key performance indicators (KPI) for service metrics daily, weekly, monthly, such as but not limited to:
Maintaining individual and shared mailbox response service level agreements (SLAs)
Maintaining defined questionnaire response standards
Maintaining remediation timeline service levels
Maintaining virtual assessment activity service levels
Maintaining acceptable business escalation percentages
Lead assessment of various workstream
Communicate performance results to leadership
Develop and/or contribute to training programs to support program implementation and operations
Track analysts’ quality and SLAs in assessments and remediation
Present and understand key operational and risk metrics to internal stakeholders and other business partners
Lead collaboration efforts with internal stakeholders on projects and objectives for process improvement
Work directly with supplier management office on escalations
Perform peer reviews and provide guidance to analysts on their assessments and remediation
Research and analyze supplier profiles
Conduct discovery calls with suppliers and internal stakeholders
Work with peer and management to identify information security risks to move to remediation
Escalate any assessments to internal stakeholders and management in a timely manner
Able to support and handle risk assessments activities end to end from determining tier, workstream to assessment and remediation closure
Collaborate with internal stakeholders and management for any delays and escalations during the remediation process
Review supplier’s supporting documentation to close remediation records
Develop and guide a group of analysts in skills or career development
Enable business partners through insights for process and programs developments
Manages and is accountable for professional employees and/or supervisors
Impact of work is most often at the local level
Comply with the terms and conditions of the employment contract, company policies and procedures, and any and all directives (such as, but not limited to, transfer and/or re-assignment to different work locations, change in teams and/or work shifts, policies in regards to flexibility of work benefits and/or work environment, alternative work arrangements, and other decisions that may arise due to the changing business environment). The Company may adopt, vary or rescind these policies and directives in its absolute discretion and without any limitation (implied or otherwise) on its ability to do so
Required Qualifications:

Bachelor's degree or its equivalent in accounting, finance, business, computer science, or related field required
At least 7 years of experience in IT or IS compliance/audit
At least 2 years of experience in people management
Working experience in reporting risk metrics and dashboard to leadership
Working Experience in IT/Financial Audit and/or IT risk assessment activities
Working experience in troubleshooting general computing controls for desktop, information, and network security
Advance level experience in MS Office Suite
Familiarity and/or working experience in HIPAA Risk Assessments
Familiarity and/or working experience with industry accepted security control frameworks like ISO27001/NIST
Strong Communication (listening, verbal, written) and presentation skills
Ability to develop effective relationships with team members, suppliers, and internal stakeholders
Ability to manager diverse set of analysts and provide day to day
Ability to maintain measurable productivity and quality standards at or above minimum established standards
Ability to work well with large and diverse groups in matrix driven and virtual organization
Ability to assist suppliers in navigating the process to help resolve their queries
Inquisitiveness to learn existing and/or emerging data security risk/threat landscape
Ability to understand and communicate general computing controls for desktop, information, and network security (i.e. Encryption, up-to-date Patches/Antivirus) associated with mobile devices
Ability to execute project and program managements for continuous development
Ability to manage and resolve complex data security issues
Preferred Qualifications:

Certifications: CISA, CISM, ISO 27001 Lead Auditor

VIEW OTHER JOB POSTS FROM:
SHARE THIS POST
facebook linkedin