
Information Security, Risk Manager
Posted 2 days ago

Posted 2 days ago
This is a fully remote position, open to applicants in Texas.
• Lead the ISO 27001 certification process for Empyrean, including surveillance, internal audit preparation, and ongoing compliance with ISMS.
• Coordinate the testing of ISO 27001 controls and manage communication with control owners, business partners, and audit stakeholders.
• Assist in assessments and assurance activities related to SOC 2, NIST AI RMF, NIST CSF, NIST 800-53, HIPAA, and additional frameworks.
• Identify, evaluate, document, monitor, and communicate information security risks and control deficiencies.
• Develop, implement, track, and validate plans for corrective action and risk remediation.
• Oversee audit and assessment activities concerning information security, cybersecurity, business applications, and technology controls.
• Direct or facilitate risk assessments for technology projects, environmental changes, third parties, emerging technologies, exceptions, and risk events.
• Organize security risk and governance meetings, ensuring thorough preparation, documentation, and follow-up.
• Maintain the enterprise information security risk register along with related risk, issue, exception, and remediation documentation.
• Provide technical knowledge and apply security and compliance practices to identify control weaknesses and manage policy exceptions.
• Lead security and technology responses for client questionnaires, RFPs, due diligence requests, and internal inquiries.
• Assess the effectiveness of enterprise cybersecurity threat and vulnerability monitoring and management.
• Develop and uphold information security policies, standards, and governance documentation.
• Offer expertise in security risk and IT controls for technology initiatives, evaluating control design and implementation.
• Interpret audit results, provide actionable recommendations, and verify the implementation of remediation measures.
• Support wider information security initiatives, incident management, escalations, strategic roadmaps, and projects.
• Excellent communication, presentation, and organizational skills.
• Strong time-management abilities and capacity to juggle multiple priorities.
• Capability to collaborate effectively with diverse roles and teams.
• Previous experience in security compliance, risk management, or auditing, especially with ISO 27001.
• Familiarity with SOC 2, HIPAA, NIST, FedRAMP, or similar frameworks is advantageous.
• Experience in preparing work papers, audit reports, and presentations.
• Practical knowledge of information security, technology risk management, auditing, and control assurance practices.
• Solid understanding of ISO 27001, SOC 2/TSC, NIST CSF, NIST 800-53, NIST AI RMF, CIS, COBIT, and related frameworks.
• Experience with enterprise workflow, ticketing systems, directory services, IT infrastructure, GRC, and security technologies; familiarity with ServiceNow and Jira is beneficial.
• High standards of integrity and confidentiality.
• Over 5 years of experience in information security risk, governance, compliance, technology auditing, security engineering, or related fields.
• Knowledge of IT and security best practices and frameworks such as NIST CSF, SOC 2/TSC, CIS, ISO 27001/ISMS, COBIT, and ITIL.
• Understanding of technology risks and experience in evaluating cybersecurity, privacy, and engineering controls.
• Familiarity with vulnerability management, security governance, software development, incident response, physical security, logging and monitoring, micro-segmentation, SASE, zero trust, insider threat, vendor risk management, PKI, penetration testing, application controls, and segregation of duties.
• Advanced knowledge of internal controls and the ability to assess control design and operational effectiveness.
• Comprehensive health and wellness benefits.
• Opportunities for professional development and growth.
• Flexible work arrangements to promote work-life balance.
• Competitive salary and performance-based incentives.
• Engaging work environment with a focus on collaboration and innovation.
Sony Interactive Entertainment
Squads
Neo4j
PingWind Inc. (SDVOSB)
Get handpicked remote jobs straight to your inbox weekly.