



Manager - Information Security and Data Privacy
As an Information Security & Privacy SME, you will serve as an individual contributor dedicated to advancing the Governance, Risk, and Compliance (GRC) objectives within the organizations information security and privacy division.
Key Responsibilities:
Policy Development and Governance :
- Author, formalize, and oversee the implementation of robust information security policies, standards, and procedures, ensuring alignment with industry best practices and all pertinent regulatory mandates.
Contractual Review:
- Conduct comprehensive reviews of information security and data privacy provisions within client and supplier agreements, including Data Processing Agreements (DPAs), to ensure alignment with organizational policy and legal obligations.
Regulatory Compliance:
- Ensure adherence to global data protection laws and privacy frameworks by architecting and sustaining rigorous controls designed to protect personal data.
Compliance Oversight:
- Strategize and manage comprehensive compliance activities, including assessments, audits, testing, and remediation, to standards such as ISO 27001, ISO 27701, SOC 2 Type 2, GDPR, and HIPAA.
Audit Management:
- Manage the lifecycle of internal and external security audits, ensuring compliance and coordinating audit-related activities to successful completion.
Strategic Communication:
- Provide communication regarding security objectives, strategic initiatives, and organizational programs to both departmental leadership and the broader workforce.
Stakeholder Liaison:
- Act as the primary point of contact for external stakeholders, regulatory bodies concerning matters of information security and data privacy.
Risk Management:
- Facilitate enterprise-wide risk assessments across diverse business units and support functions, maintaining proactive collaboration with key stakeholders to identify and mitigate potential vulnerabilities.
Emerging Technology Governance:
- Evaluate and execute risk assessments concerning the integration of AI tools and Large Language Models (LLMs), with focus on maintaining rigorous data privacy, security, and governance standards.
Incident Response:
- Direct investigations into security incidents, maintaining thorough documentation of findings and facilitating the expedient resolution and remediation of issues in partnership with stakeholders.
Team Leadership:
- Manage teams tasked with monitoring and enforcing adherence to corporate and business unit information security and data privacy controls.
Didn’t find the job appropriate? Report this Job