

Search by job, company or skills
Key Responsibilities
Governance
• Support the development, implementation, and maintenance of robust IT governance, risk, and compliance policies, frameworks, and standard operating procedures in line with industry best practices and regulatory requirements.
• Support the execution of practice's GRC initiatives and ensure alignment with business objectives. • Support GRC practice manager in the collaboration with internal stakeholders to ensure a unified approach to information security across the organization. Risk
• Implement security controls, risk assessment framework, and program that align with regulatory requirements, ensuring documented and sustainable compliance that aligns with BFG's objectives. • Conduct risk assessments and audits within the practice, identify vulnerabilities, IT security risks to the BFG's systems, networks, and data.
• Conduct cloud-based risk assessments and audits within the practice, identify vulnerabilities, IT security risks to the BFG's cloud infrastructure.
• Develop risk treatment plans and monitor their implementation to mitigate identified risks effectively and guide mitigation strategies.
• Evaluate security posture of third-party vendors through risk assessment and security reviews.
• Drive the continuous automation and management of risk management using technology and data-enabled solutions and streamline risk management activities with automation.
• Maintain accurate records of risk assessment activities. Compliance
• Identify applicable compliance baselines from legislative requirements and corporate objectives. Ensure applicable obligations are incorporated into the assurance program.
• Conduct periodic compliance assessment activities against internal policies and industry standards (e.g. ISO27001) and maintain accurate records of these activities.
• Provide support in internal and external IT security audit.
• Assist in the preparation of reports for management and regulatory bodies as required. Security Awareness & Training
• Assist the execution of security awareness program for staff on compliance standards and security best practices.
• Stay up to date on the latest developments in information security, risk management, and compliance.
Job ID: 151702923