Job Description
The Endpoint Security Risk & Compliance Lead will be responsible for risk management, audit, and regulatory compliance activities for the Endpoint Security team. They will partner closely with technical Endpoint Security teams, Security Risk teams, and auditors to help ensure compliance with relevant regulations and industry standards. The lead will also drive the development and maintenance of reporting to ensure transparency and accountability for overall compliance with business and governance activities, including the development and implementation of policies, procedures, and controls to maintain the highest level of endpoint security risk management and compliance.
Whatwill you do?
- Stakeholder
Collaboration:
Work closely with endpoint security teams, IT operations, and risk partners to understand security controls and processes and manage risks. - Audit & Regulatory Engagement Leadership: Champion audit, regulatory, and key control engagements with support from technical teams to drive accurate and meaningful responses for evaluators while also identifying areas for learning and improvement.
- Risk Management: Own primary accountability for endpoint security risk management across endpoint security products. Capturing risks, tracking risks through their lifecycle, and supporting technical teams driving towards remediation.
- Reporting & Remediation: Drive the development, distribution, and maintenance of meaningful reporting for key governance and compliance metrics relating to endpoint security (e.g., patching, certificate management, and password rotations).
- Supplier Management Governance: Manage regular reviews of endpoint security technology solutions relating to supplier and data risk, model risk, and exit strategies.
- Excellent leadership and collaboration skills: The ability to collaborate with various stakeholders, including endpoint security teams, IT operations, and risk partners, is crucial for success in this role. The candidate must understand, speak, and write in both technical and simplified language, translating technical concepts between various audiences and partner teams including communications to auditor or regulator audiences.
- Audit and regulatory compliance expertise: Experience with audit and regulatory engagements, including knowledge of relevant laws, regulations, and industry standards (e.g., NIST, SWIFT, PCI-DSS, GDPR), is essential for this position.
- Strong understanding of security risk management frameworks: The ideal candidate should have in-depth knowledge of security best practices, risk management principles, and industry-recognized security frameworks.
- Experience with reporting and metrics ownership: The ability to develop and maintain meaningful reports and metrics to measure endpoint security governance and compliance is critical for this role.
- Certifications in information security (e.g., CISSP, CCSP, CRISC, CIAM, ITIL)
- Previous work experience within the Finance or Insurance sector or other large enterprise industry
- Understanding of security technologies such as anti-virus, data monitoring and protection, cryptography, identity and access management, and vulnerability scanning technologies
- Knowledge of enterprise environments including IT ecosystems, software networks, traditional on-premise infrastructure and cloud platforms (AWS, Azure, GCP)
- Experience with agile methodologies and tools, such as Jira or Azure Dev Ops, for backlog management and sprint planning
We thrive on the challenge to be our best, progressive thinking to keep growing, and working together to deliver trusted advice to help our clients thrive and communities prosper. We care about each other, reaching our potential, making a difference to our communities, and achieving success that is mutual.
- A comprehensive Total Rewards Program including bonuses and flexible benefits, competitive compensation, commissions, and stock where applicable.
- Leaders who support your development through coaching and managing opportunities.
- Ability to make a difference and lasting impact.
- Work in a dynamic, collaborative, progressive,…
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search: