Talent.com
Information Security Governance, Risk and Compliance (GRC) Lead
Information Security Governance, Risk and Compliance (GRC) LeadO'Melveny & Myers LLP • Dallas, TX, US
No se aceptan más aplicaciones
Information Security Governance, Risk and Compliance (GRC) Lead

Information Security Governance, Risk and Compliance (GRC) Lead

O'Melveny & Myers LLP • Dallas, TX, US
Hace 15 días
Tipo de contrato
  • A tiempo completo
Descripción del trabajo

Information Security Governance, Risk and Compliance (GRC) Lead

O'Melveny & Myers LLP has an immediate opening for a remote Information Security Governance, Risk and Compliance (GRC) Lead in one of our Texas offices. The GRC Lead serves as the subject matter expert for firmwide Information Security GRC initiatives, collaborating closely with the Information Security Officer. This role encompasses the development, implementation and ongoing coordination of GRC efforts, tracking information security risks, conducting risk analyses and mitigation options, coordinating information security metrics, and regular reporting to Information Security leadership. The Lead enforces GRC rigor globally for firmwide information security obligations and helps implement a comprehensive control framework to execute the GRC strategy. The role oversees administration of standards and controls, risk management, third-party risk management (TPRM), baseline security controls and technology compliance initiatives. It coordinates information security audits and assessments, tracks responses, and interacts with clients and external auditors. It may also involve reviewing outside counsel guidelines and developing a third-party risk management program, including due diligence documentation such as questionnaires and SOC reports.

Responsibilities Include

  • Lead firmwide Information Security GRC initiatives in partnership with the Information Security team.
  • Assist and coordinate with the ISO 27001 annual certification preparations, as well as client audits.
  • Track external requirements such as outside counsel guidelines and assist with review and response as needed.
  • Oversee Information Security GRC activities and coordinate with the Information Security Officer.
  • Serve as a subject matter expert and trusted advisor for leadership on Information Security GRC matters.
  • Serve as the primary contact for responding to business unit inquiries regarding operational compliance.
  • Collaborate with IT, legal, finance and operations to develop a cohesive Information Security GRC program.
  • Partner with business units during solutions onboarding to ensure adequate controls are in place and enabled.
  • Conduct regular risk assessments and analyze emerging risks across the organization.
  • Coordinate with stakeholders to implement effective risk mitigation strategies.
  • Maintain a strategic and comprehensive GRC program that includes policies, standards, processes and guidelines.
  • Stay updated on regulatory changes and industry standards (ISO, NIST, GDPR, HITRUST, HIPAA).
  • Provide guidance to team members to ensure compliance with relevant laws and regulations.
  • Deliver GRC reports to management, emphasizing compliance status, risk exposure and mitigation efforts.
  • Oversee third-party and vendor risk as part of the organization's risk management strategy.
  • Document and enforce cybersecurity standards that balance risk with business operations.
  • Ensure audit readiness by documenting GRC activities, policies, assessments and corrective actions.
  • Implement process improvements using GRC tools and methodologies to drive productivity gains.
  • Cooperate with internal and external auditors to maintain and implement controls that meet GRC requirements.
  • Motivate functional areas to adopt practices that comply with cybersecurity policies and standards.
  • Provide leadership in collaboration with technical and business teams to strengthen business resiliency.
  • Guide team to align with security, audit and risk management efforts in ongoing security program assessments.
  • Assist Information Security with projects as needed.
  • Stay abreast of current technologies, developments, security compliance requirements, standards, and industry trends.
  • Perform analysis of security threats and vulnerabilities and use threat intelligence to anticipate and mitigate risks.
  • Ensure secure handling of privileged accounts and credentials.

Qualifications

  • Five years of experience in GRC or as a cybersecurity practitioner, including roles in security analysis, compliance, and risk management.
  • Experience working in a distributed and hybrid office environment.
  • Understanding of information security and privacy frameworks : ISO / IEC 27001 required; NIST, HIPAA, HITRUST, GDPR, and GLBA are optional.
  • Bachelor's degree in Cybersecurity, Computer Science, Data Science, or related field.
  • Experience conducting tabletop exercises, coordinating disaster recovery exercises, and other information security control tests is ideal.
  • Excellent analytical and problem-solving abilities.
  • Effective communication and interpersonal skills; ability to work independently and in a multidisciplinary team.
  • Professional certifications are a plus (CISSP, CISM, CISA, CRISC, CGRC).
  • We offer an excellent salary and benefits package. For more information, or to be considered for this position, please apply online at www.omm.com. EOE M / F / D / V. No phone inquiries please.

    J-18808-Ljbffr

    Crear una alerta de empleo para esta búsqueda

    Information Security • Dallas, TX, US

    Ofertas relacionadas
    Cyber Resiliency Director

    Cyber Resiliency Director

    VirtualVocations • Carrollton, Texas, United States
    A tiempo completo
    A company is looking for a Director of Cyber Resiliency.Key Responsibilities Lead and mentor the Cyber Resiliency team in areas such as cloud security engineering and incident readiness Design a...Mostrar más
    Última actualización: hace 2 días • Oferta promocionada
    Senior Information Security Analyst

    Senior Information Security Analyst

    VirtualVocations • Mesquite, Texas, United States
    A tiempo completo
    Key Responsibilities Conduct security assessments and monitor systems for vulnerabilities and misconfigurations Assist in remediating findings from vulnerability assessments and provide risk-bas...Mostrar más
    Última actualización: hace más de 30 días • Oferta promocionada
    Security Operations Associate Director

    Security Operations Associate Director

    VirtualVocations • Garland, Texas, United States
    A tiempo completo
    A company is looking for an Associate Director of Security Architecture Operations.Key Responsibilities Coordinate workflows and facilitate conversations between the Security Architecture & Engin...Mostrar más
    Última actualización: hace 1 día • Oferta promocionada
    Lead IT Security Analyst

    Lead IT Security Analyst

    VirtualVocations • Grand Prairie, Texas, United States
    A tiempo completo
    A company is looking for a Lead IT Security Analyst to safeguard security governance, compliance, and risk management frameworks. Key Responsibilities Develop, update, and enforce comprehensive IT...Mostrar más
    Última actualización: hace 4 días • Oferta promocionada
    Threat Intelligence Lead

    Threat Intelligence Lead

    VirtualVocations • Grand Prairie, Texas, United States
    A tiempo completo
    A company is looking for a Threat Intelligence Lead to design and mature its Cyber Threat Intelligence program.Key Responsibilities Build and enhance automation pipelines for intelligence collect...Mostrar más
    Última actualización: hace 1 día • Oferta promocionada
    Lead Associate Principal, Security Assurance

    Lead Associate Principal, Security Assurance

    The Options Clearing Corporation • Dallas, TX, United States
    A tiempo completo
    THIS POSITION IS NOT ELIGIBLE FOR VISA SPONSORSHIP • • • • •.The Lead Associate Principal, Security Assurance is responsible for leading the scoping, planning, conducting, and reporting of various Secur...Mostrar más
    Última actualización: hace más de 30 días • Oferta promocionada
    Cybersecurity Vulnerability Management Lead

    Cybersecurity Vulnerability Management Lead

    VirtualVocations • Grand Prairie, Texas, United States
    A tiempo completo
    A company is looking for a Vulnerability Management Team Lead to oversee cybersecurity vulnerability management efforts.Key Responsibilities : Develop and lead the enterprise-wide product security...Mostrar más
    Última actualización: hace 4 días • Oferta promocionada
    Identity and Access Management Lead

    Identity and Access Management Lead

    VirtualVocations • Carrollton, Texas, United States
    A tiempo completo
    A company is looking for a Senior Identity and Access Management (IAM) Leader.Key Responsibilities Lead and mentor a team of security access management professionals while defining and implementi...Mostrar más
    Última actualización: hace 2 días • Oferta promocionada
    Senior GRC Analyst

    Senior GRC Analyst

    VirtualVocations • Irving, Texas, United States
    A tiempo completo
    A company is looking for a Sr GRC Analyst to support the development and maintenance of internal governance, risk, and compliance programs. Key Responsibilities Support the development, mapping, a...Mostrar más
    Última actualización: hace más de 30 días • Oferta promocionada
    Cybersecurity C-SCRM Lead

    Cybersecurity C-SCRM Lead

    VirtualVocations • Mesquite, Texas, United States
    A tiempo completo
    A company is looking for a Cybersecurity IV&V and Supply Chain Security (C-SCRM) Lead.Key Responsibilities Serve as the lead technical advisor for Third-Party Cyber Risk Management (TPCRM) and In...Mostrar más
    Última actualización: hace 4 días • Oferta promocionada
    Senior Program Director - Risk Management

    Senior Program Director - Risk Management

    VirtualVocations • Mesquite, Texas, United States
    A tiempo completo
    A company is looking for a Senior Program Director - Risk, Issue, and Opportunity Manager.Key Responsibilities Lead the R&O Management Team to support the full program scope across multiple sites...Mostrar más
    Última actualización: hace 3 días • Oferta promocionada
    Director of Vendor Governance

    Director of Vendor Governance

    VirtualVocations • Garland, Texas, United States
    A tiempo completo
    A company is looking for a Director - Vendor Governance to oversee and manage third-party supplier relationships within its Retirement & Income Solutions business. Key Responsibilities Lead strate...Mostrar más
    Última actualización: hace 4 días • Oferta promocionada
    Security and Compliance Manager

    Security and Compliance Manager

    VirtualVocations • Carrollton, Texas, United States
    A tiempo completo
    A company is looking for a Security and Compliance Manager to oversee the development and governance of its information security program. Key Responsibilities Maintain and enhance the information ...Mostrar más
    Última actualización: hace más de 30 días • Oferta promocionada
    Information Security Risk Analyst

    Information Security Risk Analyst

    VirtualVocations • Garland, Texas, United States
    A tiempo completo
    A company is looking for an Information Security Risk Analyst to identify and mitigate risks to information assets.Key Responsibilities Identify and document information security risks and assist...Mostrar más
    Última actualización: hace más de 30 días • Oferta promocionada
    Operational Risk Director

    Operational Risk Director

    VirtualVocations • Grand Prairie, Texas, United States
    A tiempo completo
    A company is looking for an Operational Risk Director.Key Responsibilities Lead the operational risk strategy focusing on technology, product, change management, and business risks Conduct data-...Mostrar más
    Última actualización: hace 3 días • Oferta promocionada
    Senior Director of Security Operations

    Senior Director of Security Operations

    VirtualVocations • Irving, Texas, United States
    A tiempo completo
    A company is looking for a Senior Director of Security Operations & Engineering.Key Responsibilities Lead and develop teams responsible for cloud security engineering, network and infrastructure ...Mostrar más
    Última actualización: hace más de 30 días • Oferta promocionada
    Chief Information Security Officer

    Chief Information Security Officer

    VirtualVocations • Mesquite, Texas, United States
    A tiempo completo
    A company is looking for a Chief Information Security Officer (CISO).Key Responsibilities Build and lead a security organization aligned with the company's growth strategy Develop frameworks for...Mostrar más
    Última actualización: hace más de 30 días • Oferta promocionada
    Senior IT Security Analyst

    Senior IT Security Analyst

    Busey Bank • Frisco, TX, United States
    A tiempo completo
    The Senior IT Security Analyst is responsible for managing activities relating to monitoring and responding to security events. The analyst is responsible for monitoring application, host, and netwo...Mostrar más
    Última actualización: hace 15 días • Oferta promocionada