
Governance, Risk, Compliance- Audit Security Advisor
- Madrid
- Permanente
- Tiempo completo
- Maintain an understanding and benchmark the following standards: ISO27001, ISO9001, ENS. Knowledge of other standards including: DORA, SOC, FedRamp
- Facilitate and ensure risks are identified, measured and tracked effectively.
- Identify control gaps and deficiencies and report to management.
- Conduct scheduled and ad hoc risk reviews of applicable environments required to maintain compliance and certifications.
- Support external assessment activities related to achieving required certifications and customer contractual requirements.
- Assist in the maintenance of SAS Cloud and security policy and process development and updates, while ensuring compliance with regulations and guidance.
- Effectively communicate to applicable staff SAS security requirements and procedures.
- Operate as a consultant, researching and recommending changes to enhance or streamline quality and information security policies and processes.
- Participate in security investigations and compliance reviews, as required by contract or regulation.
- Review SAS Cloud security contract terms and ensure alignment to current policies and processes.
- Coordinate responses to RFP and security questionnaires.
- Use of the IRM tool for managing risk and policy profiles, such as managing entity structures, build reporting dashboards, identifying and tracking of risk remediation.
- Perform issue remediation tasks such as analysis, documentation, follow-up and retesting in response to risk findings.
- Understanding of best practices for information security and data privacy practices and processes.
- Understanding of standards, best practices : SOC 2, DENS, CE +, BSI C5, GDPR, DORA, ISO 9001, ISO 27001, ISO 14001.
- 8+ years of experience in project or program management, management consulting, training, IT, audit/compliance or related field.
- Bachelor's degree in IT, Computer Science, Project Management or related field
- Equivalent combination of education, training and experience may be considered in place of the above qualifications.
- Knowledge and experience with best practices / standards and regualtions (ex: ENS, CE +, BSI C5, GDPR, DORA,ISO 27001, ISO 9001, ISO 14001).
- You’re curious, passionate, authentic and accountable. These are our
- Use and/or implementation of a GRC tool (ex: ServiceNow, Archer, Teammate, Thompson Reuters)
- Management consulting experience
- Experience with ServiceNow issue management ticketing system
- Auditor or security certification (ex: CISA, CISSP) and/or training
- Strong time management skills (schedules, prioritization).
- Excellent communication, analysis, and process flow skills.
- Ability to be flexible, display tact and diplomacy, and maintain confidentiality and integrity.
- Must have the ability to work with little supervision, escalating issues, as appropriate.
- Understanding of best practices for information security and data privacy practices and processes.
- Your well-being matters, and that's why we support all dimensions of your well-being by offering programs that reduce stress and distractions to help you remain healthy and productive.