Project Planning and Execution:
- Lead and manage security-related projects from initiation to completion, ensuring they are delivered on time, within scope, and on budget.
- Develop detailed project plans, timelines, and resource allocations, coordinating with internal teams and external stakeholders.
- Identify and manage project risks, ensuring that issues are escalated and resolved in a timely manner.
Stakeholder Communication:
- Serve as the main point of contact for security projects, providing regular updates to leadership and key stakeholders on project status, risks, and milestones.
- Collaborate with Engineering, Operations, and Business Units to ensure alignment on project goals and deliverables.
Project Documentation:
- Ensure comprehensive project documentation, including requirements, technical specifications, risk assessments, and post-project reviews.
- Maintain and update project tracking tools, providing clear visibility into project progress.
Risk Identification and Assessment:
- Conduct ongoing risk assessments to identify security risks and vulnerabilities across the organization’s IT infrastructure, processes, and data assets.
- Maintain a comprehensive risk register and prioritize risks based on business impact and likelihood.
Risk Mitigation and Strategy:
- Develop and implement mitigation strategies to address identified risks, collaborating with teams across departments to ensure proper execution.
- Monitor the effectiveness of risk mitigation efforts and recommend continuous improvements to risk management processes.
Compliance and Regulatory Requirements:
- Ensure compliance with industry regulations and standards (e.g., GDPR, HIPAA, CCPA, SOX) and support internal and external audits as needed.
- Stay informed on regulatory changes and emerging risks that may impact the organization.
Qualifications:
- Experience:
- 5+ years of experience in security project management and risk management, with a proven track record of managing complex security projects.
- Strong understanding of risk management frameworks (e.g., NIST, ISO 27001/27005) and regulatory compliance requirements.
- Skills:
- Expertise in managing cross-functional security projects, from planning through to execution and delivery.
- Strong analytical skills to assess and manage security risks.
- Excellent communication and leadership skills, with the ability to collaborate effectively with technical and business teams.
- Ability to handle multiple priorities, manage time effectively, and deliver projects under tight deadlines.
- Proficiency in project management tools and methodologies, along with security technologies and practices.
- Education:
- Bachelor’s degree in information security, Project Management, Risk Management, or related field (Master’s degree preferred).
- Certifications such as PMP, CISSP, CISM, or CRISC are highly desirable.