Job Overview
The Information Security Risk Manager is a crucial role within IQVIA organization, responsible for helping to establish and maintain IQVIA's risk management program, which is designed to ensure that the company's IT systems and information assets are adequately protected.
The individual in this position will be responsible for identifying and evaluating on information security risks in a manner that meets IQVIA's regulatory and other compliance requirements.
The individual will proactively engage the various clients, business units and other internal departments and organisations to implement practices that meet IQVIA's defined policies and standards for information risk management.
A successful candidate will demonstrate an ability to work independently and in an organised manner. They will communicate very effectively, manage their workload independently and coach others to success. They will demonstrate strong technical ability and experience, as well as diplomacy and the ability to work calmly under pressure.
Essential Responsibilities
1. Plans, executes and conducts ongoing risk assessment, self-assessment and reviews of various operations, including assessing risks, determining scope, executing test procedures, reporting results and making recommendations for improvement.
2. Evaluates compliance with legal, regulatory, operational and IT policies and procedures, and partners with stakeholders to develop sustainable remediation plans to compliance issues and control gaps, and actively drives issues and risks to closure.
3. Works with others to help identify advanced security risks and exposures, determine the causes of security non-compliances, designs and recommends solutions to prevent and mitigate future incidents. This will include identifying applications of functional knowledge and existing methodologies to highly complex problems.
4. Follows up on deficiencies identified in monitoring reviews, self-assessments, automated assessments, and internal and external audits to ensure that appropriate remediation measures have been taken.
5. Evolves the risk monitoring program to identify opportunities for enhancements and manages the risk exception process.
6. Partners with the technology organization to implement and maintain IQVIA's integrated control framework, which includes requirements from NIST CSF, COBIT, HIPAA, etc.
Qualifications
7. Bachelor's Degree Computer Science, a related field, or equivalent experience
8. Equivalent work experience may substitute for degree
9. 3 years of related work experience
10. CISSP - Certified Information Systems Security Professional
11. Certified Information Security Manager
12. Certified in Risk and Information Security Controls
IQVIA is a leading global provider of advanced analytics, technology solutions and clinical research services to the life sciences industry. We believe in pushing the boundaries of human science and data science to make the biggest impact possible – to help our customers create a healthier world. Learn more at