Information Technology Program Manager: Grc
CurrentLed 15 – 20 small to medium size projects end to end throughout risk management, risk planning, and risk acceptance lifecycle. Implement IT risk management policies and procedures by working with IT, security, compliance, and business teams ensuring alignment with security and compliance standards by identifying, assessing, and mitigating risks related to information technology systems. - Partner with senior leadership, operations, and software engineering teams to establish a set of key risk indicators (KRIs) to monitor IT risk levels, integrating them into the organization’s overall risk dashboard for product metrics and reporting. - Prepare and present monthly and quarterly governance risk reports to senior management, providing actionable insights and recommendations and updates to adapt to new threats and regulatory changes. - Analyze Single Process Inventory (SPI) to determine control gaps to provide recommendations on platform engineering risk controls. - Conducted comprehensive risk assessments for over 50 IT systems, identifying critical vulnerabilities and potential threats. - Reduced potential risk impacts by 40% through the implementation of IT controls, including access controls, encryption protocols, and network security measures. - Continuous monitoring to ensure ongoing effectiveness of IT controls and promptly address any identified deficiencies.