Maintains a high skill level of risk management and systems knowledge as it relates to the overall corporate technology environment.
Is primarily responsible for conducting the Information Technology (IT) risk assessment processes which include asset identification, threat identification, mitigating control identification and reporting of the IT asset’s inherent and residual risk ratings across all Information Technology assets of the organization.
Responsible for ensuring all IT assets (including in-house software, hardware, data, third party hosted software/services, third party hosted data, and third party developed APIs) are identified and documented within the IT asset inventory/risk assessment for the proper reporting of IT risk at an asset based level.
Will work closely with various department subject matter experts to ensure that Technology risks are appropriately identified and mitigating controls are effectively established, documented, and managed across all Information Technology assets.
Responsible for conducting IT asset-based risk assessments on a cycle basis to help identify recommendations for the treatment of risk not within the organization’s risk appetite thresholds.
Duties include report development against IT asset inventory systems, conducting IT risk assessments at an asset-based level, risk reporting, IT risk management policies and procedures development and administration of the existing IT asset-based risk assessment solution.
The candidate will also act as an intermediary between the Information Technology area and internal/external auditors to assist in the coordination and collection of IT audit documentation requests from various departments within the organization to ensure responses are received and delivered in a timely manner.
Responsibilities also include facilitating the change management documentation review process to ensure that changes for IT systems and services are properly documented, approved and adhere to the existing Change Management policies and procedures.
Essential Job Responsibilities__________________________________
.
Conducts risk assessments at an Information Technology asset-based level to identify the threats, mitigating controls and assign inherent and residual risk ratings.
.
Performs administration and maintenance activities associated with the IT asset-based risk assessment solution and processes.
.
Develops and maintains IT asset inventory reports used to create the scope of the IT asset-based risk assessment.
.
Assists in developing and maintaining IT risk management policies and procedures.
.
Develops IT risk assessment reporting and status updates for management and committees.
.
Works with various department subject matter experts to identify, analyze and assess key risk scenarios and support stakeholders with risk analysis and reporting.
.
Reviews and recommends suitable and appropriate, cost-effective controls or counter measures to address key technology risks not within the organization’s risk appetite.
.
Stays informed about emerging threats and vulnerabilities within the IT landscape.
.
Acts as an intermediary between internal and external audit to coordinate and prepare audit documentation requests from various departments in a timely manner.
.
Assists in the receipt, logging, and initial assessment of change requests to ensure they are complete and accurately documented.
.
Facilitates communication between change requestors, IT teams and other stakeholders to ensure all parties are following the change management policies and procedures accurately.
.
Monitors and reviews the results of implemented changes to ensure the required documentation is obtained while also identifying opportunities for potential improvements.
.
Develops and cultivates effective relationships with other departments, vendors, and within the Technology Group.
.
Maintains in depth knowledge of the technological assets used within the corporation and foreseeable IT threats in order to accurately identify potential risks and mitigating controls.
.
Completes assigned tasks within established timelines and specifications.
Bona Fide Occupational Qualifications___________________________
.
A bachelor’s degree or equivalent experience is required.
.
A minimum of two years related experience in Information Systems, IT Risk and/or Information Security practices.
.
A valid certification such as CISA and/or CRISC is preferred.
.
In depth technical knowledge of the assigned systems and how the technical functions relate to processing is necessary.
.
Proficient reading, writing, and grammatical skills are critical, as are analytical and mathematical skills.
Excellent written and oral communication, organizational, and interpersonal relations skills are also required.
.
A valid driver’s license and the ability to travel are required.
.
May be eligible for telecommuting.