Job Summary Information Assurance Managers lead development, communication, and adoption of CSX Cyber-security policies, processes, and controls. Lead information assurance programs and pertinent efforts on behalf of the organization. They are responsible for developing effective initiatives for information assurance and management options. Supervise and manage the planning and implementation of Governance, Risk, and Compliance projects in support of multiple audits and security projects. Create and establish guidelines, policies, and procedures for keeping information secure which reflect user needs to include investigation of security incidents. Help establish S.O.X. G.C.C., SOC2, and TSA security controls, benchmarking, and stakeholder engagement. Develop Risk Management solutions for continuous vulnerability reviews for security and business units. Applicants will be required to engage in ongoing background checks through the duration of this position with continued passing results. Primary Activities and Responsibilities * Responsible for safeguarding the company's vital information and enabling the smooth transition of business functions. * Make sure that all the security policies and technology are supporting the business strategies and help in achieving the business goals and objectives that ultimately lead to making better business decisions. * Responsible for completing all the work that involves confidentiality, availability, and integrity of the network, systems, and data by executing proper plans, and ensuring complete analysis and development and enhancement of the security systems, programs, policies, procedures, etc. * Identify resources to carry out the task effectively, to work on identification of vulnerabilities, remediation, and mitigation. * Miscellaneous activities and responsibilities as assigned by manager Minimum Qualifications * Bachelor's Degree/4-year Degree * 5 or more years of experience in managing or leading in information Assurance or a related field Knowledge and Skills * Analytical ability * Administering Information Security Software and Controls * Analyzing Security System Logs, Security Tools, and Data * Perform and document risk and impact analysis for areas of audit and compliance deficiency * Communicating Up, Down, and Across All Levels of the Organization * Collaboration and coaching skills * Understanding of Risk Management Frameworks * Defining Processes for Governance, Risk, and Compliance Assurance * Knowledge of risk management and key external audits (SOX, SOC2, TSA SD) * Ability to support evidence management for SOC 1 security controls (Logical Security, Change Management, and IT Operations), SOC2 security controls, TSA security controls * Experience and knowledge over multiple database platforms and account and password management (e.g. Mainframe DB/IMS, Oracle, MongoDB, Neo4j) * Knowledge of Direct Access and integration with Saviynt in support of Logical Security * Experience with multiple Identity Management Directory Services e.g.) Active Directory, Okta, IBM LDAP * Ability to manage extraction of account population from Oracle Financials * Ability to communicate effectively across the organization * Excellent project management skills to help stay organized. Project management skills include overseeing teams who collect data and monitoring systems to identify security threats * Possess strong interpersonal skills and should be able to lead and supervise the team members to carry out the given duties efficiently * Stays abreast with the current technological developments happening in the industry * Written and oral communications skills to communicate with all levels in the organization efficiently and effectively as well as creating clear visual presentations for business and upper management * Resolve the audit and compliance issues related to security and should be able to strike a balance and prioritize work as per the workload. Advise and support the CISO in Security Governance matters. * Ensure the cost-effective provision of a professional Security Assurance response service Job Requirements * Work hours may vary in length and schedule (may include a non-standard work week)
|