Director of Information Security & Compliance

Summary

The Director of Information Security & Compliance builds and runs the enterprise information security program, maintains IT General Controls for SOX compliance, and drives cybersecurity risk governance, awareness training, vendor security, and audit coordination across the business.

Position Value Proposition

The Director Information Security & Compliance is responsible for establishing and maintaining the information security program to ensure that information assets and associated technology, applications, systems, infrastructure and processes are adequately protected. This position is responsible for identifying, evaluating and reporting on legal and regulatory, IT, and cybersecurity risk to information assets, while supporting and advancing business objectives. This position is responsible for maintaining IT General Controls for Sarbanes Oxley (SOX) compliance. The successful candidate will be able to collaborate and influence all areas of the business to reduce risk and increase the effectiveness of our information security program.

Core Responsibilities

  • Facilitate an information security governance structure through the implementation of a hierarchical governance program, including the formation of an information security steering committee or advisory board.
  • Provide regular reporting on the current status of the information security program to enterprise risk teams and senior business leaders as part of a strategic enterprise risk management program, thus supporting business outcomes.
  • Work with the vendors to ensure that information security requirements are included in contracts by liaising with business leaders throughout the organization
  • Create and manage a targeted information security awareness training program for all employees, contractors and approved system users, and establish metrics to measure the effectiveness of this security training program for the different audiences.
  • Understand and interact with related disciplines through committees to ensure the consistent application of policies and standards across all technology projects, systems and services, including privacy, risk management, compliance and business continuity management.
  • Provide clear risk mitigating directives for projects with components in IT, including the mandatory application of controls.
  • Work with internal and external audit firms to ensure compliance with Sarbanes Oxley and other compliance requirements. Ensure IT General Controls are effective and operating successfully.

ADDITIONAL DUTIES & RESPONSIBILITIES:

(This job description is not an exclusive or exhaustive list of all job responsibilities and functions that an employee in this position may be asked to perform. Above statements describe the general nature and level of work being performed, .Duties and responsibilities can be changed, expanded, reduced or delegated by management to meet the business needs of the company)

See also

要針對這個職缺調整履歷嗎?

目前無法檢查您與這個職缺的符合程度;請先將履歷加入個人檔案,下次即可查看。

A new version of freehire is available