治理、风险与合规负责人(盖茨堡, MD, US, 20879)
Lead, Governance, Risk & Compliance (Gaithersburg, MD, US, 20879)
准备今天,守护明天。
Emergent 是一家领先的公共卫生公司,为全球社区提供保护性和救命性的解决方案。在这里,您将加入充满热情的专业人士,我们的文化由我们的价值观和对保护与拯救生命的承诺所驱动。
I. 职位概述
治理、风险与合规负责人将负责网络安全治理、风险管理及合规流程,包括数据保护和安全意识培训计划。该职位是独立贡献者角色,向 Emergent 的 IT 副总裁和 CISO 汇报。
该职位最初将专注于提升企业范围内的数据保护能力,包括数据分类、数据防泄漏、信息保护和数据治理框架。随着时间推移,该职位将扩展至支持制造运营技术(OT)安全,并监督更广泛的 GRC(治理、风险与合规)职能,包括网络安全风险管理、法规合规、安全策略和标准以及安全治理。
理想的候选人应具备强大的网络安全专业知识,同时拥有项目领导力、高管沟通能力和实施基于治理和技术的安全项目的经验。该职位需要亲力亲为,并需与各种 IT 和业务部门紧密合作,以满足我们的治理、风险管理和合规流程。
该职位为全职远程办公。
II. 核心职责
将为有残疾的个人提供合理的便利,以使其能够履行核心职责。
数据保护
· 领导实施和管理支持以下技术的治理:数据分类和标记、数据防泄漏(DLP)、内部风险管理和数据发现与库存、记录和信息管理
- 与业务相关方合作,识别、分类并保护信息
- 建立数据所有者、保管人和用户的治理流程
- 定义数据保护指标、关键绩效指标(KPI)和向高管层汇报的报告
- 领导对大量未充分保护的数据进行补救工作
- 监督所有技术平台上的数据保护政策合规性
- 通过培训和变更管理推动数据保护能力的采用
治理
· 在 IS27001、CMMC 或基于 NIST 框架的相关行业认证方面,带领组织提升成熟度。
- 领导网络安全成熟度评估和 c
查看英文原文
Preparedness today, safer tomorrow.
Emergent is a leading public health company that delivers protective and life-saving solutions to
communities around the world. Here, you will join passionate professionals where our culture is informed
by our values and commitment to protecting and saving lives.
I. JOB SUMMARY
The Lead for Governance, Risk and Compliance will oversee cybersecurity governance, risk management and compliance processes including the data protection and security awareness training programs. This position is an individual contributor role, reporting to the IT Vice President and CISO at Emergent.
This role will initially focus on maturing enterprise-wide data protection capabilities, including data classification, data loss prevention, information protection and data governance frameworks. Over time, the role will expand to support Manufacturing OT security and oversee broader GRC functions, including cybersecurity risk management, regulatory compliance, security policies and standards and security governance.
The ideal candidate combines strong cybersecurity expertise with program leadership, executive communications and experience implementing security programs leveraging governance and technologies. This position will be hands-on and require strong collaboration with various IT and business functions to satisfy our governance, risk management and compliance processes.
This position is full-time remote.
II. ESSENTIAL FUNCTIONS
Reasonable accommodations will be made to enable individuals with disabilities to perform the essential functions.
Data Protection
· Lead implementation and governance of technologies supporting: Data Classification and Labeling, Data Loss Prevention (DLP), Insider Risk Management, Data Discovery and Inventory, Records and
Information Management
- Partner with business stakeholders to identify, classify, and protect information
- Establish governance processes for data owners, custodians, and users
- Define data protection metrics, KPIs, and reporting for executive leadership
- Lead remediation efforts for large volumes of inadequately protected data
- Oversee data protection policy compliance across all technology platforms
- Drive adoption of data protection capabilities via training and change management
Governance
- Lead the organization on improved maturity with regards to IS27001, CMMC or related industry certifications based on the NIST framework.
- Lead cybersecurity maturity assessments and create/maintain cybersecurity KPI and metrics for efficient decision making with functional leaders
- Establish and maintain cybersecurity governance frameworks and operating models.
- Support various cyber councils, governance forums and program steering committees
- Collaborate with IT and functional leaders to align cybersecurity initiatives with business objectives
Risk Management
- Create and maintain the Cybersecurity risk register and support risk quantification and prioritization efforts that are appropriate for the environment
- Partner with business leaders to evaluate technology, operational, third-party, data-related risks and document risk assessments and their approvals
- Support risk reporting dashboards for executive management and governance councils
- Assist the vulnerability management program to document risks and plans of actions.
Policies & Communications
- Lead, own and develop new information security policies and review existing policies for updates and approvals
- Lead, maintain and continuously improve security awareness and training programs, cybersecurity company-wide campaign, and
- Lead cybersecurity audits internally and develop readiness activities. Support internal and external audits and assessments.
Manufacturing Security
- Support the manufacturing security program workstreams around network segmentation, secure remote access, logging and OT incident management.
- Create and lead the cyber training and awareness for manufacturing sites
- Support the execution of periodic BCP and Cybersecurity table top exercises
The above statements are intended to describe the nature of work performed by those in this job and are not an exhaustive list of all duties. Nothing in this job description restricts managements right to assign or reassign duties and responsibilities to this job at any time which reflects management’s assignment of essential functions.
III. MINIMUM EDUCATION, EXPERIENCE, SKILLS
Education:
· Bachelor’s Degree in Business or Information Systems, or equivalent experience.
Experience:
- 5+ years in cybersecurity, compliance, risk management or 7+ years of related/industry experience
- Experience leading cybersecurity projects and programs
- Experience working with cybersecurity tools, methodologies and technologies
Knowledge:
- Experience supporting cybersecurity programs within manufacturing environments, including familiarity with cybersecurity risks associated with industrial operation
- Must understand network and computing, vulnerability management, IAM/PAM
- Must be familiar with Sarbanes Oxley (SOX), SSAE 18 SOC reports, NIST CSF, ISO27001 and CMMC
Skills:
- Strong interpersonal and collaboration skills to work well with all IT and business stakeholders
- Strong communication skills (oral, written, presentation) to influence across all levels of the organization
- Adequate program management and organizational skills to ensure accuracy and timeliness of job duties
- Must be able to author policy documents, provide business risk assessments, and communicate well with other teams.
- Must be able to identify sensitive information, such as PII, PHI, Clinical Data, etc.
Abilities:
- Demonstrated experience working across organizations to resolve conflicts
- Demonstrated experience with organization-wide communications.
- Demonstrated experience managing and documenting security risks.
U.S. Base Pay Ranges and Benefits Information
The estimated annual base salary as a new hire for this position ranges from [$155,500 to $188,200]. Individual base pay depends on various factors such as applicant’s education, experience, skills, and abilities, as well as internal equity and alignment with market data. The salary may also be adjusted based on applicant’s geographic location. Certain roles are eligible for additional incentive compensation, including merit increases, annual bonus, [and/or long-term incentives in the form of stock options.]
Additionally, Emergent offers a comprehensive benefits package*. Information regarding additional benefits can be found here:
(*Eligibility for benefits is governed by the applicable plan documents and policies).
If you are selected for an interview, please feel welcome to speak to a Human Resources Partner about our compensation philosophy and available benefits.
There are physical/mental demands and work environment characteristics that must be met by an individual to successfully perform the essential functions of the job. This information is available upon request from the candidate.
Reasonable accommodations may be made to enable individuals with disabilities to perform all essential functions.
Emergent BioSolutions is an Equal Opportunity/Affirmative Action Employer and values the diversity of our workforce. Emergent does not discriminate on the basis of race, color, creed, religion, sex or gender (including pregnancy, childbirth, and related medical conditions), gender identity or gender expression (including transgender status), sexual orientation, age, national origin, ancestry, citizenship status, marital status, physical or mental disability, military service or veteran status, genetic information or any other characteristics protected by applicable federal, state or local law.
Information submitted will be used by Emergent BioSolutions for activities related to your prospective employment. Emergent BioSolutions respects your privacy and any use of the information submitted will be subject to the terms of our Privacy Policy .
Emergent BioSolutions does not accept non-solicited resumes or candidate submittals from search/recruiting agencies not already on Emergent BioSolutions’ approved agency list. Unsolicited resumes or candidate information submitted to Emergent BioSolutions by search/recruiting agencies not already on Emergent BioSolutions’ approved agency list shall become the property of Emergent BioSolutions and if the candidate is subsequently hired by Emergent BioSolutions, Emergent BioSolutions shall not owe any fee to the submitting agency.
Originally posted on Himalayas