Search jobs > Jersey City, NJ > Security specialist

Security GRC Specialist (DFS500 SME)

MDMS Recruiting LLC
Jersey City, NJ, us
Full-time

Job Description

MUST HAVE EXPERIENCE WITH DFS500

The Security GRC Specialist - Regulatory and Audit Lead is an experienced professional in Information Security Governance, Risk management and Compliance functions.

The role involves performing security risk assessments and assessing compliance against cybersecurity related external (laws and regulations), internal (company policies) requirements and industry frameworks (NIST CSF, ISO 27001, FFIEC CAT) as well as working with other IT and security teams to implement security solutions, test the effectiveness of security controls, and document the compliance levels.

It is a key role to develop, deploy, and manage the security GRC framework.

ESSENTIAL JOB FUNCTIONS

Cybersecurity Regulatory Lead

Manage the regional cyber regulatory compliance program including : assessing requirements, communicating and working with internal stakeholders to ensure required controls are in place and supporting documentation is maintained.

Review controls implemented for appropriateness, effectiveness, and completeness. Assist, follow-up and report on any necessary remediation actions.

  • Act as a subject matter expert for all DFS500-related matters and ensure the bank maintains and enhances its level of compliance with DFS500 requirements
  • Assist during cyber regulatory examinations by preparing presentations, responses and associated artifacts
  • Act as the subject matter expert to develop and maintain an effective FFIEC CAT framework for the bank
  • Manage the FFIEC CAT inherent and maturity assessments
  • Develop related reports and metrics

Security GRC Framework Specialist

  • Maintain an in-depth understanding of the broad regulatory landscape impacting business and IT areas
  • Understand the impact of laws and regulations on company systems and technology
  • Map external and internal requirements against security controls in place
  • Develop and implement the components of the security GRC Framework for mapping threats, vulnerabilities, risks, assets, stakeholders, assessments, standards, policies, controls into a holistic lifecycle to achieve Assess and Test Once, Report Multiple Times
  • Actively manage the security GRC framework by :
  • Performing various security risk assessments to identify residual risks and control gaps
  • Ensuring clients, regulatory, and internal requirements are being met consistently and effectively
  • Ensuring the required and expected controls are in place and working as they should
  • Reviewing, and maintaining security policies, standards and procedures as needed
  • Recommending tooling and process improvements of the Security GRC function, including automation
  • Providing multi-level reporting to stakeholders in the company
  • Build partnerships across the organization : Audit, Legal, Compliance, Information Technology, business operations, Risk management, etc.

to ensure the security GRC program is aligned with business objectives and requirements

Documentation, Reporting & Analytics

Contribute to the reporting framework that will provide regular metrics about our business and IT environment; analyze trends in security events, activities, etc.

to better understand risks, and current gaps.

KNOWLEDGE AND EXPERIENCE

  • 8-10 years’ demonstrable experience in security GRC, security project management, and other security practices
  • Working knowledge of relevant cybersecurity and data privacy regulations
  • Knowledge of common security frameworks (NIST CSF, ISO 27001, COBIT, FFIEC CAT, etc.)
  • Proficient with MS Office, project management processes, and at least one GRC tool (highly preferred to have experience with RSA Archer)
  • Solid understanding of common security topics (e.g., application security, infrastructure security, vulnerability management, Identity and Access Management, data protection, cyber incident response, cloud security, etc.)
  • Requires strong analytical skills, oral and written communication skills including documentation of requirements, problem solving skills, and project / program management skills and presentation skills
  • Experience in managing risk and compliance (IT audit, IT or cyber risk management, regulatory compliance)

EDUCATION / CERTIFICATIONS

  • Degree in IT, Computer Science, Cybersecurity, or related subject required
  • Certified training in security management, risk and compliance solutions and practices
  • Ability to work towards or has achieved at least one Information Security or Risk Management Certification (Security+, CISSP, CCSP, CCSK, CISA, CISM, GSEC, CRISC, etc.)

Requirements

DFS500; GRC; Security; Archer

6 days ago
Related jobs
Promoted
MDMS Recruiting LLC
Jersey City, New Jersey

The role involves performing security risk assessments and assessing compliance against cybersecurity related external (laws and regulations), internal (company policies) requirements and industry frameworks (NIST CSF, ISO 27001, FFIEC CAT) as well as working with other IT and security teams to impl...

MDMS Recruiting LLC
Jersey City, New Jersey

The role involves performing security risk assessments and assessing compliance against cybersecurity related external (laws and regulations), internal (company policies) requirements and industry frameworks (NIST CSF, ISO 27001, FFIEC CAT) as well as working with other IT and security teams to impl...

MDMS Recruiting LLC
Jersey City, New Jersey

The role involves performing security risk assessments and assessing compliance against cybersecurity related external (laws and regulations), internal (company policies) requirements and industry frameworks (NIST CSF, ISO 27001, FFIEC CAT) as well as working with other IT and security teams to impl...

MDMS Recruiting LLC
Jersey City, New Jersey

The role involves performing security risk assessments and assessing compliance against cybersecurity related external (laws and regulations), internal (company policies) requirements and industry frameworks (NIST CSF, ISO 27001, FFIEC CAT) as well as working with other IT and security teams to impl...

Promoted
Allied Universal
Teterboro, New Jersey

As a Security Guard, you will serve and safeguard clients in a range of industries such as Commercial Real Estate, Healthcare, Education, Government and more. Allied Universal, North America's leading security and facility services company, provides rewarding careers that give you a sense of purpose...

Promoted
New Jersey Institute of Technology
Newark, New Jersey

Must be NJ Police Training Commission Certified SLEOII, Alternate Route Graduate, or Current New Jersey Police Officer (Non-Correctional Officers). Under supervision, provides police services designed to provide assistance and protection to members of the University community and its guests. Res...

Promoted
USSS
Union, New Jersey

During the course of their careers, Uniformed Division Officers carry out assignments in protection. Note: Lasik, ALK, RK, and PRK corrective eye surgeries are acceptable eye surgeries for Uniformed Division Officer applicants. Applicants will be considered eligible for the Uniformed Division Office...

Promoted
TriHire Solutions
Newark, New Jersey

You are an IT Security Analyst who is excited to use the latest technologies. Support the ongoing and near real-time monitoring, analyzing, investigating, tracking, and remediating of IT Security events and incidents across the enterprise in an overall effort to minimize the potential for a breach o...

Promoted
Randstad Enterprise
Newark, New Jersey

Provides technical expertise and support IT management and staff in cybersecurity threat risk assessments, development, testing and the implementation and operation of appropriate information security plans, procedures, and control techniques designed to prevent, minimize or quickly recover from cyb...

Promoted
Solomon Page
Jersey City, New Jersey

For more information and additional opportunities, visit:. Working with newly acquired broker agency to integrate with client systems. Working closely with users and stakeholders to ensure smooth transitions, create documentation, and insuring success of integration. Knowledge of AMS, Sagitta, Benef...