Job Overview
The Information Security Risk Manager is a crucial role within IQVIA organization, responsible for helping to establish and maintain IQVIA's risk management program, which is designed to ensure that the company's IT systems and information assets are adequately protected.
The individual in this position will be responsible for identifying and evaluating information security risks in a manner that meets IQVIA's regulatory and other compliance requirements.
The individual will proactively engage various clients, business units, and other internal departments and organizations to implement practices that meet IQVIA's defined policies and standards for information risk management.
A successful candidate will demonstrate an ability to work independently and in an organized manner. They will communicate very effectively, manage their workload independently, and coach others to success. They will demonstrate strong technical ability and experience, as well as diplomacy and the ability to work calmly under pressure.
Essential Responsibilities
* Plans, executes, and conducts ongoing risk assessment, self-assessment, and reviews of various operations, including assessing risks, determining scope, executing test procedures, reporting results, and making recommendations for improvement.
* Evaluates compliance with legal, regulatory, operational, and IT policies and procedures, and partners with stakeholders to develop sustainable remediation plans for compliance issues and control gaps, and actively drives issues and risks to closure.
* Works with others to help identify advanced security risks and exposures, determine the causes of security non-compliances, design, and recommend solutions to prevent and mitigate future incidents. This will include identifying applications of functional knowledge and existing methodologies to highly complex problems.
* Follows up on deficiencies identified in monitoring reviews, self-assessments, automated assessments, and internal and external audits to ensure that appropriate remediation measures have been taken.
* Evolves the risk monitoring program to identify opportunities for enhancements and manages the risk exception process.
* Partners with the technology organization to implement and maintain IQVIA's integrated control framework, which includes requirements from NIST CSF, COBIT, HIPAA, etc.
Qualifications
* Bachelor's Degree in Computer Science, a related field, or equivalent experience.
* Equivalent work experience may substitute for degree.
* 3 years of related work experience.
* CISSP - Certified Information Systems Security Professional.
* Certified Information Security Manager.
* Certified in Risk and Information Security Controls.
#J-18808-Ljbffr