It Security & Compliance Specialist
CurrentIT Security & Compliance Specialist• Works as a liaison between IT, the business units and Information Security team to ensure complete and effective implementation of security controls, standards, and supporting policies.• Defines and executes the roadmap, control, and audit of internal IT Security functions.• Manages IT Compliance issues through resolution with the appropriate subject matter experts. • Works with IT subject matter experts to produce detailed documentation including, but not limited to: logical access, facilities management, network architecture with ACL controls, logical diagrams, etc.• Identify and determine IT Security improvements and standards using CIS (Critical Infrastructure Security Controls) as a model.• Develop policies and procedure documentation related to the effective development and execution of the companies IT Security Program.• Manage all Security End User Training and testing by collaborating with internal business units using KnowBe4 security awareness system.• Draft a complete, custom, IT Security Program with action items for each area of risk.• Document and execute internal IT audit schedule and plans with audit attributes for each internal IT control.• Create internal IT general controls (ITGC) for all company assets including but not limited to Facilities Management, Applications, Video Surveillance, Security Awareness, Vulnerability Mgmt., Vendor Management, Disaster Recovery, Vendor Management, Veeva Document & Learning Management, Computer Systems Validation, Knowbe4 Security Awareness.Manage company KnowB4 Security Awareness metrics - Phishing campaigns, end user training.