Lead Cyber Security SOC

Safelite
COLUMBUS, OH
Full-time
We are sorry. The job offer you are looking for is no longer available.

Does this position interest you? You should apply even if you don’t match every single requirement! We're known as an auto glass company.

That's the focus of what we do. But beyond the glass, we're so much more. We'll help you build a fulfilling career and encourage you to have a life.

Let us be the best place you'll ever work.

This role resides in the Cyber Risk & Compliance area which is responsible for defining, implementing, and leading the Cyber Risk & Compliance function in the Safelite Organization.

It creates Soc1 and SOC2 risk management oversight; establishing and managing the controls framework and relevant standards;

overseeing applicable security, privacy, contractual and compliance requirements through strategy development and deployment, controls definition and assessment (internal & external) together with process oversight, through three areas under its remit, Risk Management, Privacy and Technical Compliance with a small team of specialists in each area.

This is a role carries out the Safelite SOC1 and SOC2 compliance management function within the Belron Trust group under the North American CISO, reporting to the Head of Cyber Risk & Compliance.

It assists in the delivery of the security risk management for Safelite, with a focus on generating and monitoring the SOC 1 and 2 program, engaging with key stakeholders.

It will ensure that all functions have clear business owners for the points of focus, control objectives and any risks are reviewed and updated regularly.

It will assist Safelite working towards a SOC 2 type 2 attestation.

It requires an ability to balance a hands-on approach to security compliance and risk management where necessary, with an ability to self-direct, prioritize and manage work in plus the improving the quality of service provided to Safelite regardless of delivery method (internal or 3rd party) with respect to information security and risk.

Information Security, financial processes, and services within Safelite are maturing and a key part of this role will be to work with the Head of Cyber Risk & Compliance together along with the CISO for North America to help define, regulate, and improve these as part of the virtual security team.

This role forms part of the wider strategic Trust program being developed focusing on the reduction of information risk to Safelite.

It requires knowledge of information security activities across technology, process, and governance as well as in depth risk management.

What You’ll Do

  • Help design, develop, and deploy across Safelite SOC1 and SOC2 management programs that focus on the monitoring of controls and ensuring compliance.
  • Develop and deploy processes within the Safelite SOC1 and 2 program where they don’t exist and where they do ensure they meet the Belron group standard for information security risk management and control.
  • Enhance existing Information Security risk processes (where they exist) to extend coverage and give better definition of SOC1 and SOC2 assurance for Safelite.
  • Where such processes don’t exist, establish them working with each function to ensure effectivity and consistency with the Safelite Risk management policy.
  • SOC 1 and SOC 2 governance involve external risk reporting to stakeholders.
  • Conducting audits of policy and compliance to SOC1 and 2, including liaison with internal and external auditors where needed.

What You’ll Need

  • Bachelor’s degree in computer science or equivalent work experience.
  • Formal Risk Management qualification or equivalent (e.g Certified ISMS Risk Management (CIS RM), CISM or equivalent).
  • One or more of the following qualifications are highly desirable :
  • Certified Information Security Manager (CISM)
  • Certified Information Systems Security Professional (CISSP)
  • Minimum 8+ years’ experience in information security governance and assurance - focusing on risk management.
  • Minimum 8+ years’ experience in generating, deploying, and managing risk management control programs within large, diverse corporate businesses.
  • A minimum of 7 + years of experience within an information discipline with a formal information security qualification.
  • Minimum 3-6 years’ experience in managing third party companies risk assessment and evaluations.
  • Experience of SOC 1 and 2 type 2.
  • CPPA enforcement and data process mapping experience within a large complex corporate organization.
  • Experience in supporting an Information Security compliance regime such as PCI DSS.
  • Ability to maintain composure and continue to function effectively under pressure.
  • Excellent presentation, communication and interpersonal skills required.
  • Comfortable interacting effectively at all levels of the Belron and group companies.
  • In-depth knowledge of information security risk management and its effective application within group and subsidiary companies.
  • A good understanding of legislation and regulations that impact information security (CPPA, GDPR).
  • Self- starter with the ability to work independently.
  • Excellent verbal communication and interpersonal skills.
  • Excellent writing and documentation skills.
  • Good analytical skills with the ability to tailor an approach based on data and information received.
  • Ability to think and plan strategically balanced against the need to deliver.
  • Actively drives the sharing of best practice for Security Risk Management.
  • Ability to travel may be required within USA, and occasionally to Europe in order to effectively support the North American CISO, but this is not envisaged to be regular

What You’ll Get

  • Competitive weekly pay and bonus opportunities.
  • A benefits package valued at more than $10k*. This includes a 401(k) plan with company matching, medical coverage plans customized to suit your needs and a commitment to work / life balance through our paid time off (PTO) programs, company holidays and paid volunteer days.
  • Up to $5,250 annually in tuition reimbursement.
  • View all our health, wealth, and life offerings at .

Internal Associates : Already a member of the Safelite team? Apply through your Workday account by searching 'Find Open Jobs'.

Diversity : Safelite welcomes everyone. We value our diverse workforce and suppliers, and we’re proud to be an equal opportunity employer.

Learn more at Safelite.com / Careers.

This position description is not all inclusive for every aspect of this role. Reasonable accommodation will be made for individuals covered by ADA, ADEA, FMLA and other laws and regulations in accordance with their requirements.

Physical and mental demands are not and should not be construed to be job qualification standards, but are illustrated to help the employer, employee and / or applicant identify tasks where reasonable accommodations may need to be made when an otherwise qualified person is unable to perform the job's essential duties because of an ADA disability.

Other qualifications may be required to ensure employment eligibility in accordance with local laws and regulations and with Safelite Group, Inc.

policies and practices.

30+ days ago
Related jobs
Promoted
CACI
Columbus, Ohio

CACI is seeking a Cyber Security Analyst for the DISA GSM-O II program to support Cyber Operations for our customers at Fort Meade, MD. This position provides 24x7 cybersecurity monitoring services for the Department of Defense network. This includes performing real-time cyber threat intelligence an...

Promoted
InsideHigherEd
Columbus, Ohio

Job Title:Lead 340B Compliance Analyst. This position supervises the work of 1-2 compliance analysts in addition to the duties outlined below. This position reports to the 340B Program Manager and is responsible for leading all 340B program compliance and operations within the University Hospital co...

Promoted
Ohio State University Wexner Medical Center
Columbus, Ohio

This position supervises the work of 1-2 compliance analysts in addition to the duties outlined below. This position reports to the 340B Program Manager and is responsible for leading all 340B program compliance and operations within the University Hospital covered entity. ...

Promoted
STRS Ohio
Columbus, Ohio

The State Teachers Retirement System of Ohio (STRS Ohio) is seeking a Business Systems Analyst 1, 2 or 3 to join the ITS Investment Services team. The Business Systems Analyst 3 will coach, train, and mentor others in addition to leading key technology initiatives across the organization. Monitor tr...

Promoted
Leidos Inc
Whitehall, Ohio

The Leidos Digital Modernization sector is continuously looking for cleared Cyber Security Analysts that are interested in join the DISA GSM-O II program in Columbus, OH. This position provides 24x7 cybersecurity monitoring services for Department of Defense networks. This includes performing real-t...

Promoted
Sutton Bank
Columbus, Ohio

Serves as a liaison between the Information Security Office and various department executives. Bachelor's Degree in information systems or related field or equivalent combination of education and. Ability to effectively present information to individuals one-on-one or a small group setting. ...

Promoted
M/I Homes
Columbus, Ohio

The Business Systems Analyst II will perform software administration, training, and end-user support for all software applications. M/I Homes started as a family business and grew into a national leader in a single generation with divisions in 16 markets, including Austin, Charlotte, Chicago, Cincin...

Promoted
TalentBurst, an Inc 5000 company
Columbus, Ohio
Remote

The Senior Global Trade Compliance Analyst performs the day-to-day management of all global trade compliance activities. Global Trade Compliance Analyst. The primary objective of this position is to assist the Compliance Manager with maintaining an import/export control structure consisting of opera...

Promoted
Brooksource
Columbus, Ohio

Strong business and technology aptitude with a willingness to learn and understand business and software solutions. Work with team to respond and answer questions generated by team members and business partners. Act as a liaison between business units and development team. Provide system support for...

Promoted
LingaTech
Columbus, Ohio

Assist the Chief Data Officer and Data Manager in overseeing the development of database structures, conducting data lifecycle analysis, data extraction, and data mining, and utilizing these insights in both traditional extracts and advanced data visualization tools. In this role, you will play a pi...