Senior Manager Information Security
CurrentStrategic Leadership: Develop and implement comprehensive GRC and data security strategies that align with the company’s business goals and regulatory requirements.Risk Management: Identify, assess, and prioritize organizational risks, including data security risks; design and implement effective risk mitigation strategies.Regulatory Compliance: Ensure compliance with all relevant laws, regulations, and internal policies, including data protection regulations such as GDPR and CCPA.Data Security: Oversee the development and implementation of data security policies and procedures to protect the organization’s data assets from internal and external threats.Policy Development: Create, review, and update GRC and data security policies and procedures to reflect changes in regulations and industry best practices.Training and Awareness: Develop and deliver GRC and data security training programs to employees at all levels to enhance awareness and understanding of compliance, risk management, and data protection.Reporting and Documentation: Prepare and present regular reports on GRC and data security activities, including risk assessments, compliance audits, and incident investigations, to senior management and the board of directors.Incident Management: Lead investigations into compliance violations, data breaches, and other security incidents; develop corrective action plans and oversee their implementation.Collaboration: Work closely with departments such as Legal, IT, HR, and Internal Audit to ensure a coordinated approach to GRC and data security.Stakeholder Engagement: Liaise with regulators, auditors, and other external stakeholders to address GRC and data security matters and ensure transparency.