Cybersecurity Risk and Compliance Manager
About the role
The Cybersecurity Risk and Compliance Manager is a key role in ASSA ABLOY's strategy to accelerate the organization’s cyber resilience. This position is part of the Americas division of ASSA ABLOY Opening Solutions, headquartered in New Haven, CT. This is an onsite position.
Responsibilities
- Establish divisional cyber risk governance
- Maintain divisional cyber risk register
- Build and maintain Cyber Risk and Compliance Reporting dashboards and reports for stakeholder groups
- Define, measure, and report on Information security compliance within the operation of an ISMS, providing relevant KPIs and KRIs
- Establish and execute risk assessment and management with business functions
- Create, modify and implement divisional policies and directives based on Information security standards ISO27001 and NIST
- Create deep coalitions with business partners to anchor Information Security into Policy framework
- Collaborate with corporate counsels and HR departments to monitor enforcement of standards and regulations
- Develop and oversee control systems to prevent or deal with violations of legal guidelines and internal policies
- Evaluate the efficiency of controls and improve them continuously
Requirements
- Professional certification in Information Security CISM or CISSP
- Professional certification in CRISC or ISO27005 preferred
- Minimum 3 years of experience in a global cyber security management role
- Proven experience of implementing and operating information security risk and compliance management within an environment of similar size and global representation
- Strong knowledge of current digital service delivery concepts, technology, and its cyber protection capabilities
- Good enterprise business knowledge with the ability to articulate risks in clear business language
- Good knowledge of global regulatory compliance demands in the areas of privacy, industry or governmental segments (GDPR, CCPA, PCI-DSS, critical infrastructure, Patriot Act…)
Qualifications
- Talented and self-motivated person, who is inviting and collaborative and can guide business functions to handle organizational cyber risks and transform these into controls
- An engaged, committed, creative, hands-on and self-motivated personality
- Expert knowledge and proven success in implementing Information Security Management System (ISMS) in an enterprise organization
- Analytical and conceptual ability to identify compliance risks and develop practical solutions and adjustments
- Excellent business and IT communication skills in the English language
Skills
- Strong knowledge of current digital service delivery concepts, technology, and its cyber protection capabilities
- Good enterprise business knowledge with the ability to articulate risks in clear business language
- Good knowledge of global regulatory compliance demands in the areas of privacy, industry or governmental segments (GDPR, CCPA, PCI-DSS, critical infrastructure, Patriot Act…)
Benefits
We offer a competitive compensation and benefits package including multiple healthcare options, tuition reimbursement, and matching 401k. We also provide a generous holiday schedule and paid time off to refresh and recharge. Employee pricing on our products and discount programs for travel, entertainment, and more!
Pay
Competitive salary commensurate with experience.
Schedule
Onsite position based in New Haven, CT.
Contact
To apply, please visit our careers page or contact us at [insert contact information].