מציאת משרת הייטק בחברות הטובות ביותר מעולם לא הייתה קלה יותר
The role involves comprehensive management of the Portfolio and service line of risk with the primary accountability of reducing that risk by engaging directly with key EY Leaders and ensures the company’s technical systems and information assets are protected in accordance with compliance requirements by doing pro-active compliance management and compliance hunting. Furthermore, the role focuses end-to-end security compliance enablement and is responsible for identifying, evaluating and reporting on information security risks when technological systems and software are not meeting compliance requirements.
Your key responsibilities
This position is a leading role in managing the compliance portfolio for all global, regional, and country-based assets and systems. As a compliance consultant dedicated to the EY Service Line and function, you will be both an individual contributor capable of supporting multiple projects and lead a team of compliance specialists focused on improving the risk posture of the Service Line or function. In other words, it is not just an oversight role, but one that requires detailed understanding of the Service Line, business drivers, key risks and issues, and can help strategize on risk reduction strategies based on analysis of compliance data and trends.
You will lead a team focusing on these pillars:
Risk Management and Reduction: Take ownership of the Portfolio or Service Line of security risk and compliance, engaging directly with key EY leaders to reduce risks by providing insights on top risks impacting the security posture of the businesses. Engage in compliance and risk-based investment planning to mitigate these risks effectively.
Trend Identification and Remediation: Identify security risk trends and themes that require a comprehensive approach to remediation. Lead and spearhead these efforts, ensuring that risks are mitigated in a timely and efficient manner.
Proactive Security Initiatives: Proactively seeking out and identifying security risks, weaknesses, and potential vulnerabilities in systems and processes before they can be exploited and independently stand-up initiatives to address them. Improve compliance with security standards and policies though continuous improvement and innovation in security practices.
Governance, Risk, and Compliance (GRC) Management: Manage the end-to-end workflow of security compliance of risk findings in our Governance, Risk, and Compliance (GRC) tool to ensure continuity and compliance with security policies, standards and regulations.
And focus on the following responsibilities:
Define compliance strategies and remediation recommendations that provide pragmatic security guidance that balance business benefit and risks.
Develop appropriate risk treatment and mitigation options to address security risks identified during security reviews or audits.
Translate technical vulnerabilities into business risk terminology for the business.
Maintain compliance framework assessment toolkits used in testing and validation procedures.
Be accountable for and lead assessments for technology infrastructure, applications and third-party dependencies, aligning to regulations, best practices and corporate governance.
Skills and attributes for success
Significant working security experience and knowledge in the management of compliance with company security policies in the following areas:
Strong leadership and organizational skills
Strategic skills to assist with the development of a long-term vision for EY’s risk management security framework & approach
Ability to appropriately balance firm security needs with business impact & benefit
Ability to facilitate compromise to incrementally advance security strategy and objectives
An overall understanding of the business objectives of EY with an ability to build relationships across EY
Ability to team well with others to facilitate and enhance the understanding & compliance to security policies
Experience facilitating meetings with multiple customers and technical staff, including building consensus and mediating compromise
Execute top-down assessment of risk based on policy compliance data and risks
Experience conducting risk assessments, vulnerability assessments, vendor and third-party risk assessments and recommending risk remediation strategies
Looks for ways to continually improve our compliance with Information Security policies
Create, promote, and oversee enforcement protocols, enabling consistency across diverse internal stakeholders
Investigate any violations of policies and recommend corrective action.
Develop training materials and conduct training sessions to educate on policies and enforcement protocols
Develop metrics to evaluate the effectiveness of policy enforcement, and generate regular reports
Identify policy and enforcement gaps and propose improvements.
Projects advanced consultative skills to conduct effective questioning to break down complex issues into core elements, formulate appropriate ideas or planning and negotiate those ideas and plans clearly and concisely to advance a cooperative engagement by all levels of the organization including senior and/or executive management
Proficient understanding of business focus and processes and the ability to inject cybersecurity compliance into the business through teamwork and influence
Ability to maintain a high level of integrity, trustworthiness and confidence to represent the company and security leadership with the highest level of professionalism
Ability to remain credible with the team and external constituents through sustained industry knowledge
Proven project leadership with both legacy and emerging technologies to assess and manage business risk and enforce security controls
Wide-ranging knowledge in technical infrastructure and applications, from legacy through next generation
To qualify for the role, you must have
A minimum of 10 years' experience in the field of Cyber Security, Information Security, or related discipline
At least 5 years’ experience in a leadership role managing a distributed team and workforce
Advanced degree in Cyber Security, Information Security, Computer Science or a related discipline; or equivalent work experience
One or more of the following or equivalent certifications: Certified Risk and Information Systems Control (CRISC), Certified Information Systems Security Processional (CISSP), Certified Information Security Manager (CISM), Certified Information System Auditor (CISA), Certified Internal Auditor (CIA), Global Information Assurance Certification (GIAC) in related area, CIPP, CIPT
Experience working with common information security standards, such as: ISO 27001/27002, NIST, PCI DSS, ITIL, COBIT
Demonstrated leadership experience and thorough understanding of various regulatory requirements and laws such as, but not limited to, PCI, SOX, HIPAA, HITRUST, GDPR and GLBA.
Experience in policy enforcement and security compliance, awareness and learning at a publicly traded company
Strong understanding of governance, risk, and compliance (GRC) frameworks and tools
Proven competence in communicating confidently and effectively with clients, vendors, and all levels of management
Experience in managing the communication of security findings and recommendations to IT project teams and management
Skilled in executive level presentations and briefings
Proven ability to identify and mitigate security risks proactively
Insight into the business advantages of good risk management and internal controls beyond compliance purposes
Demonstrated leadership, negotiation and collaboration skills, and ability to influence up and down
Proven ability to manage multiple projects and meet deadlines in a fast-paced and changing environment
Demonstrated experience in managing end-to-end security compliance enablement projects
Extensive experience with security compliance regulations
Strong English language skills: excellent writing, presentation, interpersonal, and communication skills are required
Capable of working with diverse teams and promoting an enterprise-wide, collaborative security culture
Ability to work flexibly and adapt to changing environments
Ideally, you’ll also have
Exceptional judgment, tact, and decision-making ability
Familiarity with local and regional regulatory requirements and how they impact IT policies
Flexibility to adjust to multiple demands, shifting priorities, ambiguity, and rapid change
Outstanding management, interpersonal, communication, organizational, and decision-making skills
Experience with RSA Archer and/or IBM Open Pages
An ability to utilize core risk and controls skills in a broad range of projects both in a traditional internal audit and in advisory projects aimed at assisting in the implementation of controls / improvements
What we offer
EY Global Delivery Services (GDS) is a dynamic and truly global delivery network. We work across ten locations – Argentina, China, Hungary, India, the Philippines, Poland, Sri Lanka, Mexico, Spain and the United Kingdom – and with teams from all EY service lines, geographies and sectors, playing a vital role in the delivery of the EY growth strategy. From accountants to coders to advisory consultants, we offer a wide variety of fulfilling career opportunities that span all business disciplines. In GDS, you will collaborate with EY teams on exciting projects and work with well-known brands from across the globe. We’ll introduce you to an ever-expanding ecosystem of people, learning, skills and insights that will stay with you throughout your career.
EY exists to build a better working world, helping to create long-term value for clients, people and society and build trust in the capital markets.
If you can demonstrate that you meet the criteria above, please contact us as soon as possible.
In compliance with the requirements of the Whistleblower Protection Act, our company has established the Procedure for reporting breaches of law and undertaking appropriate follow-up actions. Any misconduct should be reported through the EY Ethics Hotline.
משרות נוספות שיכולות לעניין אותך