Information Security Manager, Technology Risk
Current● Administer, review and update firm-wide information security practices, including IT general controls, CIS controls, and IT, privacy and cybersecurity standards and procedures● Support the IT organization through identification of gaps in the control framework and recommendation of mitigating controls● Create testing program for key controls to mitigate redundant efforts and audit impact on resources● Maintain list of key IT controls to ensure compliance with regulatory requirements, such as SOX and PCI.DSS, and enforce management accountability● Liaise with internal and external auditors to ensure reliability and accuracy of information sharing for SOX, SOC1 and FICCA audits related to IT and InfoSec controls● Review and approve exception requests for deviations to IT security policies● Coordinate with Business Information Security Leads to explore solutions and alternate options to security policy violations● Collaborate with Identity Access Management (IAM) personnel to approve atypical access requests and prevent security violations● Coordinate with cyber security and vulnerability management teams to ensure application patches and updates are applied to remedy vulnerabilities● Track and mitigate issues related to key IT controls, related deficiencies and ensure accountability and effectiveness of management response actions to address control weaknesses● Aggregate significant IT control risks or compliance issues to the for reporting to the CISO, Enterprise IT Risk, ERM and ORM boards