עדיין מחפשים עבודה במנועי חיפוש? הגיע הזמן להשתדרג!
במקום לעבור לבד על אלפי מודעות, Jobify מנתחת את קורות החיים שלך ומציגה לך רק משרות שבאמת מתאימות לך.
מעל 80,000 משרות • 4,000 חדשות ביום
חינם. בלי פרסומות. בלי אותיות קטנות.
A global successful Hitech company is looking for you for a GRC expert/manager position!
You will own the GRC domain in the company.
The Global Infosec Department is responsible for the Confidentiality, Integrity and Availability of the company's information,
systems, and processes. It's in charge of establishing controls, building trust and relationships with other departments in the company and making sure that acceptable risk levels are met.
The Global Infosec Department is working in a huge scale, cloud based environment.
Key Responsibilities:
Lead the company ISO27001 program: Gather needed evidence, Assess risks with stakeholders and maintain the company’s ISMS according to the standard specifications.
In charge of 3rd party risk management program: Conducting initial vendor risk assessment, reviewing contracts, analyzing Infosec requirements gaps and managing vendor risk management SaaS system.
Lead cross organization risk management program: Technologies, processes and people and track their mitigation status until reaching acceptable level.
Write, publish and track compliance with the company global Infosec policies and procedures.
Lead the company Infosec awareness program: Manage awareness phishing campaigns system, track awareness program usage among new and existing employees, enhance the employee’s Infosec awareness by developing top notch creative activities
Lead the company PT and assessment program: Handle 3rd party Pen Testers, analyze reports, prepare mitigation plan and track closure of validates risks.
Respond on behalf of the company to external infosec audits, data protection assessments, Privacy requirements and any other related activity.
activity.
Requirements:
At least 3 years of experience in a similar role in a technology or consulting company.
Experience leading GRC initiatives and making a significant impact on a similar company.
Extended knowledge in all cyber security domains.
knowledge in environments (SaaS, AWS/GCP, Cloud security tools).
Great understanding of the business needs, the global Infosec risks and how to close the gap between them.
במקום לעבור לבד על אלפי מודעות, Jobify מנתחת את קורות החיים שלך ומציגה לך רק משרות שבאמת מתאימות לך.
מעל 80,000 משרות • 4,000 חדשות ביום
חינם. בלי פרסומות. בלי אותיות קטנות.