Security Governance Manager
About this position
Responsibilities
• Responsible for the effective implementation of security governance practices within the organization.
• Conduct the development and maintenance of security policies, standards, processes and procedures to ensure compliance with industry regulations and best practices.
• Conduct the development of security baselines to establish minimum security requirements for existing and streamline technologies.
• Proficient in conducting security static and dynamic testing and interpreting high-level technical vulnerabilities identified through, and including penetration testing results.
• Oversee the design and implementation of security controls to protect company assets and data.
• Conduct regular assessments and audits to identify security risks and vulnerabilities, and develop mitigation strategies.
• Collaborate with cross-functional teams to ensure alignment of security governance objectives with business goals.
• Serve as a point of contact for internal and external stakeholders regarding security governance matters.
• Establishing and maintaining an effective security awareness training program that results in increased employee understanding and adherence to security policies and procedures.
• Successfully developing and implementing comprehensive security policies, standards, and procedures that align with industry regulations and best practices.
• Developing and managing a robust security program management framework and calendar that ensures timely execution of security initiatives and proactive risk management.
• Identifying and mitigating security risks through thorough assessments, implementing effective controls, and continuously monitoring and updating security measures.
• Successfully coordinating with internal and external stakeholders to address security governance requirements, respond to audits, and meet regulatory compliance obligations.
Requirements
• 6+ years work experience in cybersecurity engineering roles, preferably for banking and payment companies or similar industries.
• Strong communication and organization skills.
• Good understanding and knowledge of information security fundamentals.
• Familiarity with network security and information systems security principles and best practices.
• Demonstrate a solid understanding of protocols.