DE Jobs

Search from over 2 Million Available Jobs, No Extra Steps, No Extra Forms, Just DirectEmployers

Job Information

Northwest Bank IT/INFORMATION RISK ASSESSOR in Independence, Ohio

Description The IT/Information Security Assessor ("Assessor") is responsible for the assessment, verification, review, and audit of technology controls and/or business process controls across the enterprise. The Assessor will be responsible for risk assessments which will require review and evaluation of IT and/or business systems and processes for compliance with defined regulatory standards, internal processes, and procedures. Additionally, the Assessor will be responsible for the identification of 3rd party and 4th party vendor risks, evaluation of control deficiencies, and recommendation on remediation efforts consistent with IT organizational policies, standards, procedures, and regulatory requirements. Essential Functions * Execute vulnerability assessments and compliance reviews; facilitate remediation planning, exposure tracking and communicating risk all done in accordance with industry best practices and established regulatory standards (GLBA, SOX, etc.) and report on mitigation status. * Provide security architecture knowledge and design concepts by partnering with the Enterprise Risk function to help manage technology related risk. * Provide technical expertise to support the Vendor Management Team with 3rd and 4th party supply-chain security and risk assessments, audits, tests, and verification activities, and when appropriate make recommendations to mitigate risk. * Apply or recommend adaptive security requirements and/or measurements based on investigative findings and threat monitoring including performing security risk assessments prior to going into production on new projects. * Assess systems of various scope and complexity to obtain, review, and interpret evidence provided to validate controls are performed effectively. * Conduct and lead assessment interviews and tests to identify technology control gaps that introduce risk to the organization * Execute and assist management with IT audits and regulatory compliance requirements. * Buildout the development of risk assessments, risk meditation, and performance reporting, through working within the IT function and other partners within the business * Participate as the liaison between Enterprise Risk and Information Technology/Information Security to improve the overall ability to identify operational risk , with a focus on continuous control mointoring and pivot to emerging technology and cyber security threats. * Build playbooks for key IT processes and associated process flows * Build, update, and maintain a global policy governance framework to ensure proper evaluation of controls including the identification of significant control deficiencies. Additional Essential Functions * Ensure compliance with Northwest's policies and procedures, and Federal/State regulations * Navigate Microsoft Office Software, computer applications, and software specific to the department in order to maximize technology tools and gain efficiency * Work as part of a team * Work with on-site equipment Additional Responsibilities Safety and Health for those without supervisory duties * Abide by the rules of the safety and loss prevention program * Perform work tasks in a safe manner * Report any and all injuries to supervisor * Know what to do in case of an emergency QUALIFICATIONS To perform this job successfully, an individual must be able to perform each essential duty satisfactorily. The requirements listed below are representative of the knowledge, skill, and/or ability required. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions. Education Technical Degree Information/Cyber Security or Risk Management Or Associate's Degree Information/Cyber Security or Risk Management Or Bachelor's Degree Information/Cyber Security or Risk Management Work Experience 5 - 6 years Assessing Information Securi

DirectEmployers