Experis jest wyspecjalizowaną marką dedykowaną realizacji zaawansowanych usług poszukiwania i selekcji specjalistów i kadry zarządzającej w obszarach: IT, inżynierii oraz finansów. Experis to wynik połączenia dwóch profesjonalnych marek – Elan IT oraz Manpower Professional, które od wielu lat dostarczały swoje usługi polskim przedsiębiorstwom, a kandydatom pomagały znaleźć pracę marzeń. Obecnie dla jednego z naszych Klientów poszukujemy Kandydatów na stanowisko:
Zadania:
Manage and operate global business units' information assurance program. Develop, deploy, and manage company's information assurance framework for the Business Unit and specific information security operations including deployment and management of technologies, systems, policies, and procedures. Coordinate assignments for cross-functional teams from Global IT operations. Provide enterprise IT security design and configuration to: i) allow development of advanced technologies that enable system availability for business development and operation; ii) meet and exceed regulatory requirements; and iii) provide adequate protection against the threats to information systems and in particular, the data assets. Lead business unit certifications and manage processes required to maintain certification.
Responsibilities
Responsibilities include (but are not limited to) the following:
- Develop and lead cross-functional assignments to define, implement, and manage the information assurance and certifications programs for the business unit.
- In collaboration with internal (IT operations, legal, audit, business and other) and external stakeholders, develop the regional deployment plan for company's information assurance framework in compliance with applicable laws and regulations. This includes policies and procedures tailored for regional operation and the set of controls aligned with the business' risk tolerance. Translate business unit and regional regulatory requirements to specific information security controls. Develop metrics for framework implementation, compliance evaluation, and certifications.
- In collaboration with internal stakeholder, deploy the information assurance framework to the business unit. Evaluate regional information security components of the enterprise architecture, conduct feasibility studies for selecting cost effective and compliant solutions (if different than global solution), and provide design and implementation guidance for the information assurance system components including intrusion prevention, vulnerability management, access control, and event monitoring. Define and monitor the technical implementation of the information assurance controls.
- Lead the development and maintenance of information assurance and certification processes, systems, technology, and documentation to support internal and external audit, incident response, IT enterprise risk assessment, identity and access management evaluation, threat and vulnerability management, incident response, and post-incident forensics. Define process and lead incident response and security incident investigation.
- Develop the tactical plans for information assurance and certification maintenance and on-going operations including identification and evaluation of business and technology risks; information security controls assessment; configuration, operations, and maintenance monitoring and control of system performance against target information assurance policies, procedures, and security metrics. Periodically evaluate system design and security posture and propose new information security features in accordance with the threat level and the business risk.
- Lead the certification and accreditation of systems or system components when required.
- Assist business development and sales pursuits by providing information security briefs and evaluation of internal security posture against industry standards.
A successful candidate will have the following skills and experience (exceptions can be granted given sufficient evidence of related experience):
- Experience in information technology related positions with working knowledge of IT infrastructure, networks, databases, processing systems, web applications, and mobile technology.
- In-depth expertise and working knowledge of information systems design, analysis, and operations.
- Experience with security programs design, implementation, and operations.
- In-depth expertise and working knowledge of information security technology and science supporting encryption, authentication, access control, information systems attack patters.
- Experience with automated network and application security vulnerability scanners.
- Proven record of information security thought and execution leadership.
- Experience designing, proposing, and implementing information assurance programs.
- Significant experience from working knowledge of risk assessment, compliance, information security controls, incident response, information security architecture, access control and authentication, network security, information security governance, data security, intrusion detection.
- Knowledge industry frameworks (ISO/IEC, COBIT) design and implementation.
- Knowledge translating regional regulation requirements to information assurance controls.
- Experience and desire to deliver significant value to (mainly internal) clients as a valued partner and trusted advisor.
- Proven record of leadership for cross-functional collaboration.
- High level of accountability and ability to execute; experience of estimating and planning work effort including managing risks and issues in relation to delivery of work
- Strong communication skills, excellent team player and collaborator.
- Committed to ongoing self development and development of team capabilities.
Required Education and Certifications
A successful candidate will have the following education and certifications (exceptions can be granted for certifications given comparable training, education, or experience)
- Bachelor's degree in computer science, computer engineering, or information technology.
- CISSP preferred.