
Lead, Governance, Risk & Compliance
Posted 22 hours ago

Posted 22 hours ago
This is a fully remote position, open to applicants in Maryland.
• Oversee the implementation and governance of technologies related to data classification and labeling, data loss prevention, insider risk management, data discovery and inventory, as well as records and information management.
• Collaborate with business stakeholders to identify, classify, and safeguard information.
• Establish governance procedures for data owners, custodians, and users.
• Define data protection metrics, KPIs, and prepare executive reports.
• Manage the remediation of inadequately protected data and ensure policy compliance across various technology platforms.
• Promote the adoption of data protection capabilities through training and change management initiatives.
• Enhance organizational maturity in accordance with ISO 27001, CMMC, and related NIST-based frameworks.
• Conduct cybersecurity maturity assessments and maintain relevant cybersecurity KPIs and metrics.
• Develop cybersecurity governance frameworks and operational models.
• Provide support for cyber councils, governance forums, and program steering committees.
• Align cybersecurity efforts with business objectives.
• Create and manage the cybersecurity risk register while assisting in risk quantification and prioritization.
• Assess technology, operational, third-party, and data-related risks, documenting evaluations and approvals.
• Support the development of risk dashboards for executive management and governance councils.
• Aid vulnerability management by documenting risks and action plans.
• Develop and maintain information security policies.
• Spearhead security awareness initiatives, training programs, and company-wide cybersecurity campaigns.
• Conduct internal cybersecurity audits and readiness assessments.
• Assist with internal and external audits and evaluations.
• Support manufacturing security efforts involving network segmentation, secure remote access, logging, and OT incident management.
• Create and lead cybersecurity training and awareness programs for manufacturing sites.
• Facilitate periodic business continuity planning and cybersecurity tabletop exercises.
• Collaborate with IT and business stakeholders as an individual contributor reporting to the IT Vice President and CISO.
• Bachelor’s Degree in Business or Information Systems, or equivalent experience.
• 5+ years of experience in cybersecurity, compliance, or risk management, or 7+ years of related/industry experience.
• Proven experience in leading cybersecurity projects and programs.
• Familiarity with cybersecurity tools, methodologies, and technologies.
• Experience in supporting cybersecurity programs within manufacturing settings.
• Understanding of cybersecurity risks associated with industrial operations.
• Knowledge of network and computing, vulnerability management, and IAM/PAM.
• Familiarity with SOX, SSAE 18 SOC reports, NIST CSF, ISO 27001, and CMMC standards.
• Exceptional interpersonal, collaboration, oral, written, and presentation skills.
• Strong program management and organizational abilities.
• Capability to author policy documents and conduct business risk assessments.
• Proficiency in identifying sensitive information such as PII, PHI, and clinical data.
• Demonstrated ability to resolve conflicts across organizations.
• Proven experience with organization-wide communications.
• Documented experience in managing and documenting security risks.
• Additional incentive compensation may include merit increases, annual bonuses, and/or long-term incentives in the form of stock options.
• Comprehensive benefits package.
• Reasonable accommodations for individuals with disabilities.
• Equal Opportunity/Affirmative Action workplace.
Humana
Centene Corporation
NETZSCH Group
Get handpicked remote jobs straight to your inbox weekly.