Governance & Risk Management Expert (Basel, English, Hybrid, GRC systems)

D-ploy
Bubendorf, BL, CH
Quick Apply
Cette offre d'emploi n'est pas disponible dans votre pays.

D-ploy is an IT and Engineering Solutions company with operations throughout the EMEA region including Switzerland, Germany, Czech Republic, Austria, UK, as well as the USA.

We pride ourselves on delivering innovative and superior services and solutions to numerous industry-leading clients. By building relationships and trusted partnerships within the IT community, we optimize our customer s IT productivity and contribute to the organization’s success and value.

We are interested in talking to engaging, flexible, and solution-oriented individuals who are looking to become a part of a dynamically growing and international organization.

We are focused on creating value where IT counts, join us!

Tasks and Responsibilities

Support the design and improvement of the information security framework (ISF) : policies, controls, procedures using the NIST Cyber Security Framework;

including third party risk management.

  • Assess new and existing systems, data flows, business processes, and third party providers engagements and services to implement and verify compliance to the ISF reporting identified risks and issues to systems, processes and third party providers owners.
  • Perform information security risk assessments such as but not limited to : security business impact analysis (BIA) and business dependency analysis;

security controls plans; controls maturity assessments; third party provider risk profiling, risk assessments and audits.

  • Maintains the information security risks and issues registers, deliver high quality reports and run information security committees meetings with business and IT mangement to manage risks.
  • Support the design and improvement of the third party information risk management policies, controls and procedures. Assist or lead assessment of information security risks arising from engagement with third party providers and drive remediation efforts.
  • Drive the design and implementation of a GRC platform including functional requirements, reviewing process designs, rolling out the new processes to the business and IT teams.
  • Support in the administration and maintenance of the GRC tool.
  • Design, improve and periodically report security key risk indicators and metrics to IT and business management to support continuous improvements and increase security maturity in our business processes.
  • Designs, and delivers the security education training awareness program (SETA) across all business functions. Manage external resources supporting the security awareness activities.
  • Desirable : Experience in implementing controls and managing compliance risks in regards to GXP regulated systems, data protection regulations such as EU and UK GDPR, CCPA, and cyber security regulations such as the EU NIS2, and the USA SEC Disclosure Requirements.

Requirements

  • Minimun of 10 years of professional experience in information technology, at least 3 years as an information security risk manager, preferably in a pharmaceutical, biotechnology or in other manufacturing organizations.
  • Bachelor’s or Master’s degree in information security, or in Information Technology.
  • Relevant information security professional certifications e.g. CISSP, CISM, CRISC, CISA, GSEC-GIAC, ISO 27001 auditor / practitioner.
  • Desirable : Training and or certifications in GRC platforms such as ServiceNow GRC, Archer, Metricstream; and the NIST Cyber Security Framework : Standards, Guidelines and Practises.
  • You are resilient and take accountability for delivering your work.
  • You are passionate about cybersecurity and is able to coach and help others who come from different backgrounds in information technology, compliance or information security domains.
  • You have a high level of personal integrity, ability to professionally handle confidential matters and convince others using appropriate level of judgment and maturity.
  • You have strong verbal and written communication skills in English, German is a plus.
  • You are a strong communicator : presentation and training, relationship management, consultation, negotiation.
  • You can work in a matrix and geographically dispersed organization.
  • All candidates must provide a Criminal record (not older than 3 months).

Benefits

  • Broad range of activities, tasks, and projects
  • Flexible working conditions
  • Vouchers (B-day voucher, wedding, and new born surprise)
  • Fishing for Friends program our referral program
  • Refreshments in the D-ploy office
  • Further development and professional advancement
  • Friendly and international working environment
  • Company-sponsored events
  • Competitive salary and various benefits

Is IT in your DNA?

Il y a 4 heures
Emplois reliés
Offre sponsorisée
Kanton Basel-Stadt, Finanzdepartement, IT BS, IT Management
Bâle, Basel-City

Zertifikate in Projektmanagement, internationaler Rechnungslegung IPSAS oder Frameworks wie ITIL4 und COBIT erleichtern Ihnen die tägliche Arbeit. ...

D-ploy
Bubendorf, Basel-Country

Assess new and existing systems, data flows, business processes, and third party providers engagements and services to implement and verify compliance to the ISF reporting identified risks and issues to systems, processes and third party providers owners. Perform information security risk assessment...

D-ploy
Bubendorf, Basel-Country

Minimum of 5 years of experience in IT Service Management, Configuration Management, or related field. Proficiency in data standards, classifications, and relationship management within CMDB systems. Identify relevant IT and OT systems, processes, and data to be integrated into the CMDB. Strong back...

D-ploy
Bubendorf, Basel-Country

Enable projects to comply with CSV requirements when using Agile project management methodology. In-depth knowledge of Waterfall and Agile project management methodologies. ...

D-ploy
Bubendorf, Basel-Country

Translate documents from English to German. Strong written and verbal communication skills in English; fluency in German is a plus. Excellent English and German language skills (spoken and written). ...

D-ploy
Bubendorf, Basel-Country

Minimum of 5 years of experience in IT Service Management, Configuration Management, or related field. Proficiency in data standards, classifications, and relationship management within CMDB systems. Identify relevant IT and OT systems, processes, and data to be integrated into the CMDB. Strong back...

D-ploy
Bubendorf, Basel-Country

Enable projects to comply with CSV requirements when using Agile project management methodology. In-depth knowledge of Waterfall and Agile project management methodologies. ...

Deloitte
Bâle, Basel-City

As part of the Audit Quality & Risk Management (“AQRM”) team, an internal function, you will help to promote a culture of sound quality and risk management by acting as a Subject Matter Expert for the Audit & Assurance practitioners. Promote a Culture of Sound Quality & Risk Management. Deloitte’s A...

Offre sponsorisée
EDP Personalberatung GmbH
Bâle, Basel-City

Immobilien #Bewirtschaftung #temporär #TopJob #YourNewJob.Abenteuer in der Immobilienbranche!.Selbständiges Bearbeiten von telefonischen und schriftlichen Anfragen diverser Dienstleister.Allgemeine administrative Tätigkeiten, Vorbereitung von Sitzungen.Mitarbeit in verschiedenen Projektgruppen.Abges...

Offre sponsorisée
Hans Leutenegger AG - Basel
Bâle, Basel-City

Sie helfen mit, die Abteilung Sanitär / Service prozessbedingt aufrecht zu erhalten und übernehmen die fachliche Betreuung Ihrer Aufgaben.Daneben übernehmen Sie insbesondere folgende Aufgaben:.Abwechslungsreiche Kundenaufträge in der Region Basel.Ausführen von Reparaturen un...