Security Partner

Security Partner
Empresa:

Experian


Detalles de la oferta

Job DescriptionExperian seeks a Sr Security Partner to embody and enact the practical day-to-day requirements of the Experian Global Information Security Program by serving as an advisor to the business unit's functional leaders. The ideal candidate will engage with the members of the business unit's (BU) senior leadership team(s) to understand, discuss, and advise on the intersection of strategic priorities and key security risks. The role evangelizes security to the business unit, but more importantly, acts as the voice of the BU with Experian's Global Security Office (EGSO). The successful candidate is required to bring industry-technical knowledge, but also demonstrate business acumen, and possess strong leadership and communication skills with the ability to operate with little supervision, relying on influence rather than authority to get things done. Key Responsibilities Conduct and prioritize project security assessments (PSA) for new enterprise development and significant changes, and facilitate the continual submission, review, and decisions related to business unit-critical issues and exceptions to any security control. Coordinate and maintain strong understanding of all BU information security risks. Anticipate the needs for risk assessment, review, and adjustment or escalation of risk rating, as well as any other demands within the risk lifecycle. Foster trusted executive relationships while dealing with members of the BU's management team. Participate in project planning process to ensure that appropriate levels of security oversight exist. Assess, consult, and collaborate as needed to link security with business unit goals and initiatives. Advocate for the BU by sharing its specific threats, requirements, and insights with the EGSO Leadership, other SPs, and members of the Information Technology (EITS) and security organization, to ensure a business unit-specific perspective exists. In addition, supports resource discussions based on the specific needs, risks, and priorities of that BU. Support BU-level strategic decision-making, product development, system implementations, and the change management associated with the adoption of new security processes and procedures. On-going partnership (vs. one time guidance) to build environments and deploy technologies in a secure manner and mitigating risks beforehand – truly positioning security as an enabler of business. Monitor information security trends internal and external to the business and keep business-facing leadership informed about information security-related incidents [Threat Informed Defense Approach]. Promote corporate cybersecurity awareness activities and support the implementation of security awareness concepts locally, as needed, to suit the business unit. Create and review security metrics to measure security effectiveness at the business unit and corporate level. Quantify and communicate risk to BU leadership in relation to BU-specific goals, initiatives, and changes (people, process, technology). Translate how business unit-specific risks factor into firmwide risks at senior-level, e.g., Regional Management Committees (RMC), Security Review, and Security and Continuity Steering Committee (SCSC). Support on the monitoring and measuring of policies, processes, and controls that support compliance with industry and regionally specific mandates, laws, and regulations specific to the business unit, and how those roll up into broader mandates for the enterprise. Work with other governance functions on educating BU leadership on prospective changes to relevant mandates, laws, and regulations. Uncover any gaps that may exist. Determine any business unit-specific requirements that may exist due to geography, region, data, vertical, etc., and how those differ from or overlap with firmwide or departmental mandates. Assist in the completion of internal and external security assessments for the business unit. Behaviors Ability to operate with little supervision and guidance. Ability to collaborate and build consensus with stakeholders across multiple functions. Ability to lead cross-functional teams to execute on security and business unit objectives. Relies on influence, not authority, to get things done. Advocates for the business unit and for security. Process driven, and has eye for detail, automation, and efficiency to improve programs-processes. QualificationsBachelor's Degree in a relevant major or equivalent experience in security, risk, audit, compliance, and management. 7+ years of experience in an IT-security field with strong demonstrable evidence of a technical background or security risk assessments - audit field. Relationship management, team building, and facilitation. Presentation, data analysis and problem-solving skills. Interpretation and application of security policies, standards, and procedures. Ability, drive and motivation to research and provide the right guidance and find possible solutions. Ability to push back where the risk outweighs the benefits. Adaptive communication skills; can speak to audiences at varying corporate altitudes and business functions. Ability to Influence based on knowledge-experience to align key initiatives with stakeholders. Curiosity to ask questions and challenge status quo. Preferred certifications: Certified Information Systems Security Professional (CISSP) or Certified Information Security Manager (CISM), Certified Information Privacy Professional (CIPP), Certified Information Systems Auditor (CISA), Certified in Risk and Information Systems Control (CRISC), Certified Cloud Security Professional (CCSP). Knowledge Basic knowledge of major security domains including application security, vulnerability management, incident response, cloud security, etc. Information technology-related frameworks, such as International Standards Organization (ISO) 27001 series, NIST series, Information Technology Infrastructure Library (ITIL), Control Objectives for Information and Related Technologies (COBIT). Overall understanding of privacy-related regulations, such as General Data Protection Regulation (GDPR) and California Consumer Privacy Act (CCPA), and regional breach notification laws. Basic knowledge of vertical-specific frameworks and regulations is a plus, e.g., FedRAMP, FFIEC, HIPAA, and PCI. Risk analysis, assessment, treatment, and management methodologies. Agile methodology for application-software. Additional InformationThis is a permanent home-based role in Costa Rica. No relocation available.Our benefits include: Medical, life and dental insurance, Asociacion Solidarista, International Share Save Plan, Flex Work, Work from home, Paid time off, Annual Performance Bonus, Education Reimbursement, Family Bonding, Bereavement Leave, Referral Program, and more.


Fuente: Talent_Ppc

Requisitos

Security Partner
Empresa:

Experian


Master Data, Analyst Iii

Master Data, Analyst III Job Description About Us Huggies. Kleenex. Cottonelle. Scott. Kotex. Poise. Depend. K-C Professional. You already know our legendary...


Desde Kimberly-Clark Corporation - Heredia

Publicado 25 days ago

Product Data Steward Analyst

3M has a long-standing reputation as a company committed to innovation. We provide the freedom to explore and encourage curiosity and creativity. We gain new...


Desde 3M - Heredia

Publicado 25 days ago

Software Engineer (.Net & Azure)

Job Description:About the role: At this role you will be a Sr. Software Engineer (.NET/Azure) who write code, participate in code reviews, evaluate SAST find...


Desde Gft Technologies Se - Heredia

Publicado 25 days ago

Ai Developer

Description First Factory is looking for a dynamic and passionate AI Developer to join our team. The ideal candidate should have a strong interest in artific...


Desde First Factory - Heredia

Publicado 25 days ago

Built at: 2024-05-20T13:56:11.075Z