Job Description
The Governance and Risk Officer help ensure that the organization maintains a robust security posture, complies with relevant policies and standards, and fosters a culture of security awareness among employees.
Key Responsibilities :
- Governance and Compliance :
Ensure compliance with relevant laws, regulations, and standards when required.
Develop, enforce, review, and monitor compliance and update security policies, standards, and procedures.Risk Management :Assist in Identifying and assessing risks across the organization.
Conduct risk assessments, identify potential security risks, and implement mitigation strategies.Monitor and report on risk exposure and mitigation efforts.Awareness and Training :Plan and execute security awareness campaigns and conduct phishing simulations to test employee awareness.
Define security awareness campaigns for specific profiles within the organisation.Manage the employment lifecycle and performance of personnel in accordance with security requirements (background checks, vetting, transfers, risk designations, succession planning, disciplinary action, and termination) - in alignment with Human ResourcesInformation Asset Inventories and Control ManagementMaintain information asset inventories including categorization, critical assets, risks and security controls in place.
Ownership of the cybersecurity Control Catalog and ensure controls are applied.Security Auditing :Perform security audits, internally and respond to external audit demands.
Perform 3rd Party audits and maintain an inventory of vetted suppliers and toolsQualifications
5+ years of professional experience in cybersecurity, with focus on auditing, governance, risk management.Strong understanding of regulatory requirements and industry standardsKnowledge of best practices in modern security architectures and incident responsesRelevant security certifications such as CRISC, CISA.Familiarity with security control frameworks : CIS Controls, NIST Special Publication 800-53Familiarity with cybersecurity frameworks : NIST CSF, ISO27001Additional Information
Highly responsive, energetic and enthusiasticAnalytical thinking and problem-solving skillsAbility to work independently and as part of a teamStrong ethical standards and integrityCapable of prioritising tasks and meeting critical deadlinesExcellent judgment, attention to detailsExcellent communication and interpersonal skillsExpect duty to expand beyond normal business hoursUser / business focus