Cybersecurity Risk and Compliance Manager

Technology, Data & Digital · IT Infrastructure & Security · Cybersecurity

In short

ASSA ABLOY Americas is hiring a Cybersecurity Risk and Compliance Manager for an onsite position in New Haven, CT. This role is responsible for building and managing the divisional cyber risk and compliance program, including establishing cyber risk governance, developing policies based on ISO27001 and NIST standards, and reporting on KPIs and KRIs.

Responsibilities

  • Establish divisional cyber risk governance
  • Build divisional risk management culture and methodologies
  • Maintain divisional cyber risk register
  • Transform business requirements into IT Policies and controls
  • Establish and execute risk assessment and management with business functions
  • Build and maintain Cyber Risk and Compliance Reporting dashboards and reports
  • Define, monitor, and report on Key Risk Indicators and Key Performance Indicators
  • Create, modify, and implement divisional policies and directives based on ISO27001 and NIST standards
  • Develop coalitions with business partners to anchor Information Security into Policy framework
  • Collaborate with corporate counsels and HR departments to monitor enforcement of standards and regulations
  • Review policies periodically to identify hidden risks or non-conformity issues
  • Develop and oversee control systems to prevent or deal with violations of legal guidelines and internal policies
  • Evaluate the efficiency of controls and improve them continuously

Requirements

  • Professional certification in Information Security CISM or CISSP
  • Minimum 3 years of experience in a global cyber security management role
  • Proven experience of implementing and operating information security risk and compliance management within an environment of similar size and global representation
  • Strong knowledge of current digital service delivery concepts, technology, and its cyber protection capabilities
  • Good enterprise business knowledge with the ability to articulate risks in clear business language
  • Good knowledge of global regulatory compliance demands in the areas of privacy, industry or governmental segments (GDPR, CCPA, PCI-DSS, critical infrastructure, Patriot Act)
  • Expert knowledge and proven success in implementing Information Security Management System (ISMS) in an enterprise organization
  • Analytical and conceptual ability to identify compliance risks and develop practical solutions and adjustments
  • Excellent business and IT communication skills in the English language

Desired Qualifications

  • Professional certification in CRISC or ISO27005 preferred
  • Engaged, committed, creative, hands-on and self-motivated personality

Benefits

  • Continuous professional development opportunities and an environment that fosters internal growth and mobility
  • Competitive compensation and benefits package
  • Multiple healthcare options
  • Tuition reimbursement
  • Matching 401k
  • Generous holiday schedule and paid time off
  • Employee pricing on our products and discount programs for travel, entertainment, and more
#cybersecurity#risk management#compliance#information security#ISMS#IT policies#NIST#ISO27001#GDPR#CCPA#PCI-DSS
ASSA ABLOY Group Logo

Company

ASSA ABLOY Group

Job Posted

3 weeks ago

Expires

in 1 week

Employment Type

Full Time

WorkMode

On Site

Experience Level

Mid-Senior

Locations

New Haven, United States

Applicants

Be an early applicant