Principal Business Information Security Specialist

Principal Business Information Security Specialist

emagine Polska

Praca zdalna

Bengaluru
Praca stała
B2B
cybersecurity risk management
information security
Archer GRC platform
risk assessment methodologies
ISO/IEC 27005
ISO 31000
ISO 27001
documentation skills
risk registers
Cloud Security
Threat & Vulnerability Management

Hexjobs Insights

Poszukujemy Principal Business Information Security Specialist z 8-10 letnim doświadczeniem w zarządzaniu ryzykiem bezpieczeństwa. Wymagana znajomość platformy Archer GRC oraz metodologii oceny ryzyka.

Słowa kluczowe

cybersecurity risk management
information security
Archer GRC platform
risk assessment methodologies
ISO/IEC 27005
ISO 31000
ISO 27001
documentation skills
risk registers
Cloud Security
Threat & Vulnerability Management

Introduction & SummaryWe seeking a lead or Principal Business Information Security Specialist with a minimum of 8-10 years of experience. This role is essential to lead and execute the security risk management process across designated business domains, ensuring alignment with corporate standards and supporting the organization’s Information Security Management System (ISMS).Main ResponsibilitiesKey duties include:Identify and document security risk scenarios.Evaluate asset criticality for confidentiality, integrity, and availability.Assess vulnerabilities and threats using corporate risk catalogues.Analyze business impacts (financial, regulatory, reputational, operational).Determine inherent, residual, and target risk levels.Select risk response options (accept, avoid, mitigate, transfer).Maintain and update the Unit Security Risk Register and Risk Heatmap.Provide quarterly risk maps and updates to stakeholders.Communicate risk posture to internal/external stakeholders.Ensure full documentation of risk management activities.Key RequirementsThe ideal candidate should possess:Proven experience in cybersecurity risk management or information security.Hands-on experience with Archer GRC platform (mandatory).Strong knowledge of risk assessment methodologies and threat modelling.Familiarity with ISO/IEC 27005, ISO 31000, and ISO 27001.Ability to analyze technical vulnerabilities and business impacts.Excellent documentation and communication skills.Experience with risk registers and heatmaps.Knowledge of security capabilities (SDL, Cloud Security, IAM, Threat & Vulnerability Management).Nice to HavePreferred certifications include:CISSPCISMCRISCCGEITISO 27001 Lead Implementer/Auditor (or equivalent)

Wyświetlenia: 4
Opublikowanaokoło miesiąc temu
Wygasaza około miesiąc
Rodzaj umowyPraca stała, B2B
Źródło
Logo

Podobne oferty, które mogą Cię zainteresować

Na podstawie "Principal Business Information Security Specialist"

Nie znaleziono ofert, spróbuj zmienić kryteria wyszukiwania.