Vacancy expired!
- Directs and approves the design of information security systems and performs annual information security risk assessment.
- Maintains a current understanding of the IT threat landscape for the industry.
- Ensures compliance with the changing laws and applicable regulations related to information security. Translates that knowledge to identification of risks and actionable plans to protect the business.
- Constantly updates the cyber security strategy to leverage new technology and threat information.
- Briefs the CIO on status and risks, including taking the role of champion for the overall strategy.
- Ensures the development and implementation of an ongoing employee information security awareness program.
- Ensures that cyber security policies and procedures are communicated to all personnel and that compliance is enforced.
- Prepares the annual information security report for presentation to the CIO.
- Directs development and execution of an enterprise-wide Business Continuity Plan. Conducts an annual Business Impact Analysis, Business Continuity Risk Assessment and plan testing.
- Directs development and execution of an enterprise-wide Incident Response Plan. Develops and directs Response Team to react to security incidents.
- Reviews investigations after breaches or incidents, including impact analysis and recommendations for avoiding similar vulnerabilities. Provides effective and expedient communication.
- Develops strategies to identify and mitigate identified risks.
- Conducts monitoring of Information Technology controls (i.e. segregation of duties, Information Technology general controls, policies, procedures, standards, systems auditing, vulnerability testing in compliance with SOC 2, NIST 800-53.).
- Coordinates and monitors timely Information Technology responses to internal and external auditors, regulatory examinations and review findings. Coordinate policy, procedural and/or process changes to prevent reoccurrence of findings.
- Oversees identity and access management.
- Work closely with DevOps to ensure security for the cloud environment.
- Work closely with HR, Legal, R&D and Compliance on various matters including audits.
- Perform annual tabletop crisis stress testing for ransomware attack and disaster recovery
- ID: #49094007
- State: Pennsylvania Philadelphia 19190 Philadelphia USA
- City: Philadelphia
- Salary: Depends on Experience
- Job type: Permanent
- Showed: 2023-02-09
- Deadline: 2023-04-09
- Category: Et cetera