Senior Information Security Specialist
CurrentManage the security awareness department Including but no limited to: Policy Awareness, Security Articles, Presentations centered around cyber security month, Podcasts, managing internal sharepoint security website, deploying mandatory annual security training. • Consult with IT and business partners to define risk based controls for IT assets via a consistent, repeatable, automated model. • Assisting partners with security control tailoring guidance, implementation, design and development• Articulate and communicate security requirements and their relationship to risk across the operations, business process and executive levels of the organization as part of The Hartford’s overall Risk Management Framework based on ISO 27001, NIST 800-53 and others.• Willingness to leverage governance, risk and compliance workflow management tools to communicate security requirements and streamline risk and controls oversight.• Perform 3rd-Party Security Assessments, in which we evaluate the security practices and programs for those partners engaged by our company. In this capacity, the role directly interfaces with business areas and vendor partners to understand the nature of the business relationships, and then performs detailed reviews of the security practices of the vendor through a series of questionnaires, interviews and/or onsite audits.• Partner with Legal and Procurement teams to ensure the company’s interests are appropriately accounted for in contractual language that enforces privacy and security considerations.• Support our business areas in responding to customer inquiries regarding our own company’s information security policies, programs, and practices. • Respond to a range of ad-hoc security consulting requests, including at times supporting teammates with security-related projects and support services