Job Title - Sr. Information Risk Consultant (Cyber risk management)
Location - Remote (1 week per quarter at Washington DC)
***Must have 10+ years of relevant work experience***
*This role is not able to offer visa transfer or sponsorship now or in the future*
Overview
Under the general supervision of an information security risk manager, the Senior Information Risk Consultant (Cyber risk management) will provide expertise with security risk management and assessment of:
- Azure cloud services (including but not limited to capabilities for IAM, Network Security, Policy Management, Key Management, etc.)
- IT Products, platforms, and services (cloud and non-cloud)
- Solutions with complex hybrid architectures
- Identity and Access Management Governance
The candidate will be required to work with project teams, service providers, and business units internal and external to the Fund's IT function. The candidate is expected to bring pragmatic cloud security and risk management experience allowing for the Fund to meet its present and emergent business needs. The candidate is expected to advise and influence technology and business personnel regarding the value and methods of safeguarding information, applications, systems, infrastructure, and activities to help ensure that technologies function optimally; work practices are optimized so that the information risks are managed.
Experience must include:
- Prior work in a technical cybersecurity risk management function at organizations with security related regulatory requirements.
- Practical use of risk management concepts and principles - including assessment, prioritization, delivery of treatment plans, tracking and reporting, and metrics (accreditation and certification). Experience with NIST-SP800-30, ISO 27001/2, ISO 27005, COBIT.
- Embedding security into processes such as SDLC, Project Lifecycle, ITIL, etc.
- Demonstrated cybersecurity expertise with infrastructure, applications, and database system technologies.
- Basic IT consultancy skills. Ability to consult and deliver on the security hardening of application and infrastructure components, including tools, and techniques to ensure the security of application, database, and infrastructure components.
- Pragmatic security expert with an inherent ability to balance security demands with business reality. Ability to quickly grasp how new technologies work and how security controls should be applied to achieve business goals.
- Knowledge of security solutions, latest threats, and countermeasures.
Specific responsibilities include:
- Senior individual contributor for information security risk management projects. Sample projects/programs could include but are not limited to:
- Control design and assessment for high-demand technical areas such as ERP, IT Service Management, Identity and Access Management, IT Resiliency, Cloud, etc.
- Compliance framework mapping and implementation,
- Risk remediation management,
- Information Security risk reporting and monitoring
- Creation of roadmaps to mature or advance Information Security Strategies/Programs/Controls
- Design and enablement of cyber controls functions and processes
- Direct experience as a power user of Cybersecurity GRC/ solutions, tools, and technologies, specifically ServiceNow and Archer
- Projects or roles requiring coordination across lines of defense working with technical, business, compliance, risk, and audit teams to deliver solutions.
- Delivery of information security risk assessments for large-scale IT implementation projects including consulting with security architecture function for threat modeling, appropriate tiering of N tier products/platforms, design of infrastructure security controls to protect system components.
- Consult and review the implementation of authentication, authorization (fine grained and coarse grained), and cryptography (PKI, SSL, Kerberos, crypto algorithms) mechanisms within applications.
- Consult with security assurance function on the delivery of technical security standards, configuration baselines and related procedures for the hardening of both cloud and non-cloud application and infrastructure components, tools, and techniques to ensure the security of application and infrastructure components such as LINUX/Windows servers, Web servers (IIS, Apache, tomcat), app servers, Databases (Oracle and MS SQL), endpoints (MAC, Windows, Apple IOS, etc.), and Web Application Firewalls.
- Collaborate with other security functions e.g. security architecture, security assurance, offensive security team (red/purple team), application security penetration testing team, to review and apply appropriate risk levels to the output of the assessments performed by the functions.
- Maintain impartiality around IT systems to produce unbiased reports on information security risk.
- Works closely with IT project teams to develop implementation plans for new security-related products and services.
- Conducts quality assurance reviews of security requirements for the implementation of identified solutions.
- Define/enhance process and procedures for using external security service providers including scoping, management of services, remediation tracking, and exception management.
- Effectively communicates requirements and trains staff and managers in IT divisions to identify and manage risks throughout the project lifecycle.
- Where applicable, manages the engagement process of external risk assessment providers and acts as a liaison with internal IT project teams and business units.
- As an advocate of information security, works closely and proactively with IT project team leaders, service providers, and business units to provide security-related technical solutions. Identifies opportunities to improve business practices or IT security-related processes.
- Other ad hoc responsibilities may include:
- Analyzes, recommends, and implements process improvements within the context of information security.
- Support governance activities for Identity and Access Management, where requested.
Required Soft Skills
- Familiarity with a broad range of security technologies supplemented by in-depth knowledge in specific areas of relevance.
- Ability to quickly grasp how new technologies work and how they might be applied to achieve business goals.
- Analytical skills that enable synthesis of inputs from many sources and allow for strategic thinking and tactical implementation.
- Pragmatic security expert with an inherent ability to balance security demands with business reality.
- Excellent relationship management skills.
- Ability to think laterally and to have input to/propose detailed, complex solutions to technical issues.
Education
- Bachelor's degree in information security, computer science, engineering, mathematics, business, or related field of study plus a minimum of 12 years of relevant experience in regulated industries working as an information risk manager or IT security architect; OR
- Advanced degree in Information Security, computer science, engineering, mathematics, business, or related field of study plus a minimum of 6 years of relevant experience in regulated industries working as an information risk manager or IT security architect.
Certifications: (Minimum plus at least 2 preferred)
- CISSP or CISM (minimum required)
- CCSP (preferred)
- Microsoft Certified: Cybersecurity Architect Expert (preferred)
- Other Microsoft cloud security related certifications at the Expert level (preferred)
- GIAC certifications (preferred)
- Offensive security related certifications (preferred)
Salary and Other Compensation: Applications will be accepted until Sept 29th 2024. The annual salary for this position is between $114,000.00 - $134000.00 depending on experience and other qualifications of the successful candidate. This position is also eligible for Cognizant's discretionary annual incentive program, based on performance and subject to the terms of Cognizant's applicable plans.
Benefits: Cognizant offers the following benefits for this position, subject to applicable eligibility requirements: Medical/Dental/Vision/Life Insurance, Paid holidays plus Paid Time Off, 401(k) plan and contributions, Long-term/Short-term Disability, Paid Parental Leave, Employee Stock Purchase Plan.
Disclaimer: The salary, other compensation, and benefits information is accurate as of the date of this posting. Cognizant reserves the right to modify this information at any time, subject to applicable law.
#J-18808-Ljbffr