Application Governance Leader
About the Role
You will work across business units and IT domains to drive significant impact by staying informed about current events, security focus areas, and regulatory changes that affect compliance processes. This role involves conducting ongoing risk assessments, developing risk-response plans for high-risk areas, and measuring and reporting IT risks to relevant partners.
You will collaborate with IT Operations teams to ensure adherence to established controls, consult with cross-functional teams on pertinent risks, evaluate the effectiveness of IT controls, identify compliance gaps, and analyze trends in control measurements. Additionally, you will lead initiatives to enhance compliance, work with internal and external auditors on audits and remediation efforts, and promote a culture of risk awareness and continuous improvement through training and support.
Responsibilities
- Govern and steward the site’s application portfolio, working with the Site Digital Leader and Dept E&Is to ensure all MPRS (Make/Pack/Release/Ship) applications are registered with appropriate Business Impact Assessment.
- Own the site’s compliance for digital asset management.
- Identify site trends or recurring issues and develop a plan to address them by linking back to the Site Digital Master Plan.
- Ensure critical applications are identified and documented in accordance with the Site Continuity Plan.
- Partner with site CSV owner(s) to ensure computer systems are properly registered and in compliance.
- Participate as part of the Site Change Management Board.
- Build the capabilities of the Core Systems team of Key Users and Application Owners.
- Build a network within the business unit and central teams to leverage institutional knowledge for scaling and reapplying applications.
- Ensure Application Owners are qualified and trained, and provide input into Application Manager hiring and impact plans.
- Ensure all applications have capable and qualified Application Owners assigned.
- Plan, manage iRisk, and build capability for local application owners with appropriate PDCA (Plan-Do-Check-Act).
- Responsible for the Compliance Applications Management Toolkit, the site’s processes to manage, the scorecard, and meet stewardship requirements, including:
- OT software licenses
- Access Management
- QA (RAMP, CSV, etc.)
- Record Retention
- Change Management
- Develop relationships with central and 2LOD (2nd Line of Defense) teams.
- Serve as the primary escalation point for the business unit’s App SPOC and ITAM for compliance issues.
- Stay informed of upcoming policy changes and develop plans to ensure compliance across the site’s applications.
- Ensure local application managers follow application continuity best practices.
- Partner with the Digital Compliance team and policy and standard owners to ensure fit for use.
Qualifications
Required:
- BA/MA degree in Computer Science, Computer Systems Engineering, Industrial Engineering, Business Management Information Systems, Software Development, or a related field.
- Ability to influence and build relationships with business unit partners, external service providers, and architecture teams.
- Ability to communicate technical concepts to teammates and non-technical colleagues.
- English fluency (speak, write, and read).
- Ability to work onsite 5 days per week in Cape Girardeau, Missouri.
Preferred:
- Certified in ISACA CRISC, CGEIT, CISA, and/or CISSP (or willing to attain certification within the first 12 months of employment).
- Prior experience in Governance, Risk, and Compliance roles (e.g., Risk Manager, Risk Analyst, Compliance Manager, Auditor).
- Experience with IT Governance processes, including policy management and deployment, monitoring and reporting of compliance results, and identification of risks.
Pay
$85,000.00 - $122,200.00 / year
Schedule
Full time, onsite 5 days per week.