
IT Risk Management and Compliance Specialist
22 hours ago
Position Title:
IT Risk Management and Compliance Specialist
Reports To:
Sr. Manager Information Security
Division:
IT
Direct Reports:
0
Location:
US
Date Last Revised:
05/23/2024
Role Accountability
The IT Risk Management and Compliance Specialist at Lubrizol is a key resource in the development and continuous improvement of all aspects of the company's global Information Security program, including Third Party Risk Management. This role involves actively identifying and facilitating the elimination or mitigation of risks throughout the global environment, both internally and externally. The specialist will partner with technical teams to advise on applicable control requirements and potential solutions, ensuring that third-party relationships are managed effectively and securely.
In addition to Third Party Risk Management, the specialist will also be involved in internal auditing activities. They will participate in measuring and reporting compliance with IT policies and standards, conducting audits to assess the effectiveness and efficiency of risk management processes. This includes evaluating internal controls, identifying areas for improvement, and recommending and implementing enhancements to the program.
Furthermore, the specialist will be responsible for responding to external requests related to IT risk management and compliance. They will collaborate with relevant stakeholders to address inquiries, provide necessary documentation, and ensure compliance with external regulations and standards.
Overall, the IT Risk Management and Compliance Specialist plays a critical role in ensuring the global impact and importance of Lubrizol's Information Security program by managing third-party risks, conducting internal audits, and responding to external requests.
Essential Job Functions
- Execute on the 3rd Party Risk Management program, managing and mitigating risks associated with third-party relationships.
- Execute the IT Risk Management processes to identify, assess, evaluate, and treat risks, ensuring the global impact and importance of Lubrizol's Information Security program.
- Recommend and implement Risk Management Program process improvements to enhance the effectiveness and efficiency of risk management practices.
- Facilitate and conduct technology and operational risk and compliance assessments to identify potential risks and ensure compliance with internal policies and external regulations.
- Respond to and support risk assessments or audits from external and internal customers, providing necessary documentation and addressing inquiries to ensure compliance and risk mitigation.
- Partner with technical teams, advising on applicable control requirements and proposing potential solutions to address identified risks, fostering a secure and compliant environment.
- Conduct compliance assessments of controls for in-scope systems, including remediation assessments and audit-readiness assessments, to ensure adherence to IT policies and standards.
- Identify control deficiencies and maintain records of deficiency details, including management response documentation and evidence of exposure checks, to track and address areas for improvement.
- Maintain and improve the Information Security Policy Set, ensuring that policies are up to date, aligned with industry best practices, and effectively communicated to employees.
- Provide insight and recommendations to leadership as part of a global information security team, contributing to strategic decision-making and continuous improvement efforts.
- Perform other information security activities as needed to support the overall objectives of the Information Security program at Lubrizol.
Critical Competencies
- Demonstrated effectiveness at working independently, establishing priorities, and managing task completion aligned with the needs of the organization, while actively collaborating with global stakeholders to ensure a unified approach to IT Risk Management and Compliance.
- Ability to effectively build relationships and work in a collaborative, matrix-driven, global environment, fostering strong partnerships with technical teams and stakeholders across different regions and time zones to achieve a consistent and globally impactful Information Security program.
- Sound decision-making, proactive/creative problem-solving, and strategic thinking skills, enabling the identification and mitigation of risks on a global scale, considering the diverse needs and regulatory requirements of different regions.
- Strong IT process discipline and critical thinking skills, ensuring consistent adherence to established processes and methodologies across global operations, while continuously seeking opportunities for improvement and standardization.
- Strong interpersonal skills, facilitating effective communication and collaboration with local users, global colleagues, and leadership, promoting a culture of information security awareness and compliance across the organization's global footprint.
- Must be able to drive clear accountability and expectations, ensuring that all stakeholders understand their roles and responsibilities in managing IT risks and complying with policies and standards, regardless of their geographical location.
- Strong written and verbal communication skills required to communicate complex concepts and technical information effectively, both internally and externally, across different cultures and languages, to support risk assessments, audits, and compliance reporting on a global scale.
- Ability to develop assessment plans for new technologies and processes without previous guidance or templates, demonstrating adaptability and resourcefulness in evaluating and addressing emerging risks in a global context.
- Able to learn and understand new legal or regulatory standards and apply a practical approach to implementing those standards across different regions, considering the global impact and ensuring consistent compliance throughout the organization.
Required Qualifications
Education / Certifications:
For the IT Risk Management and Compliance Specialist role, the following education and certification requirements are preferred:
- Bachelor's degree in Information Technology (IT), Information Security or a related field, providing a strong foundation in IT and Information Security principles and practices.
- Preferred certifications include CRISC (Certified in Risk and Information Systems Control), CISM (Certified Information Security Manager), or CISA (Certified Information Systems Auditor). These certifications demonstrate expertise in IT risk management, information security, and auditing, which are highly relevant to the responsibilities of the role.
Experience
For the IT Risk Management and Compliance Specialist role, the following experiences are needed:
- Minimum of 1 years of relevant industry and professional experience in areas such as risk management, audit, third-party risk, operational risk, information security, or related fields. This experience provides a solid foundation in understanding and managing risks within an organizational context.
- Knowledge of third-party risk management, including the ability to assess and manage risks associated with external vendors and partners. Experience with IT risk assessments and operational processes is also valuable, as well as familiarity with techniques for implementing regulatory requirements.
- Understanding of security domains, including identity and access management, authentication, encryption, application security, network security, vulnerability and patch management, information security metrics, policies, standards, and procedures. This knowledge enables the specialist to effectively assess and address risks across various security areas.
- Knowledge of ISO and NIST security standards, which are widely recognized frameworks for information security management. Familiarity with these standards demonstrates an understanding of best practices and compliance requirements in the field.
- Knowledge of CIS (Center for Internet Security) benchmarks and controls is preferred. Familiarity with these controls demonstrates an understanding of industry-recognized security practices and their application in risk management and compliance efforts.
- Experience working for a US headquartered global organization.
Skills & Systems
For the IT Risk Management and Compliance Specialist role, the following skills and system requirements are needed:
- Proficiency in Microsoft Windows-based operating systems and collaboration tools, enabling effective communication and collaboration within the organization.
- Demonstrated understanding of risk management processes, including the ability to identify, assess, evaluate, and treat risks in a systematic and structured manner.
- Knowledge of basic IT security principles, networking concepts, active directory, and SAP ECC/S4 concepts. This knowledge allows the specialist to assess risks and implement appropriate controls in these areas.
- Familiarity with risk management frameworks, such as ISO 31000 or COSO ERM, providing a structured approach to managing risks and ensuring compliance with industry standards.
- Experience in documenting issues and solutions to assist end users and co-workers in understanding and resolving similar problems, promoting knowledge sharing and collaboration within the organization.
- Strong analytical and problem-solving skills, enabling the ability to analyze complex information, identify patterns, and make informed decisions to mitigate risks.
- Knowledge of regulatory compliance requirements, such as GDPR, HIPAA, or SOX, depending on the industry and region of operation.
- Familiarity with data privacy and protection principles, including data classification, data retention, and data breach response.
- Understanding of incident response and business continuity planning, including the ability to develop and test incident response plans.
- Knowledge of cloud computing security principles and best practices, including familiarity with cloud service provider security frameworks (e.g., AWS, Azure, Google Cloud).
- Strong project management skills, including the ability to manage multiple projects simultaneously, prioritize tasks, and meet deadlines.
- Excellent communication and presentation skills, with the ability to effectively communicate complex technical concepts to both technical and non-technical stakeholders.
- Continuous learning mindset, staying updated with the latest trends, technologies, and regulatory changes in the field of IT risk management and compliance.
These skills and system requirements collectively contribute to the capabilities of an IT Risk Management and Compliance specialist in effectively managing risks and ensuring compliance within an organization.
Work Environment
Role Scope
- Primary: IT Risk Management and Compliance Specialist
Travel
Very Limited;
Work Hours
- M-F 2nd shift
Physical Demands
- General office-type activity
-
Regulatory Risk and Compliance Specialist
4 days ago
Pune, Maharashtra, India beBeeRegulatoryRiskSpecialist Full time ₹ 11,50,000 - ₹ 23,50,000Job Title: Regulatory Risk and Compliance SpecialistOur company is seeking a highly skilled Regulatory Risk and Compliance Specialist to join our team. As a key member of our assurance and advisory services, you will play a critical role in helping clients develop and implement effective risk management strategies.Key Responsibilities:• Lead and manage...
-
Pune, Maharashtra, India beBeeRiskManagement Full time ₹ 1,50,00,000 - ₹ 2,00,00,000Compliance Assurance SpecialistAs a senior professional in the Legal department, you will be responsible for providing assurance over the effectiveness of Compliance Risk Management across the organization.Key Accountabilities:Development and refresh of the Compliance Assurance Annual Plan to ensure it focuses on areas of highest risk and value in relation...
-
Risk Compliance Specialist
3 days ago
Pune, Maharashtra, India beBeeGovernance Full time ₹ 1,50,00,000 - ₹ 2,00,00,000Job Description:Mizuho Global Services is a subsidiary company of a major Japanese bank. It was established to manage banking and IT operations for the organization's domestic and overseas offices.The ideal candidate will be responsible for managing governance risk and compliance within our organization, ensuring that all operations meet government and...
-
Risk and Compliance Expert
4 days ago
Pune, Maharashtra, India beBeeGovernance Full time ₹ 15,00,000 - ₹ 25,00,000Strategic Risk and Compliance LeadWe are seeking a highly skilled professional to lead our Governance, Risk, and Compliance practice. The successful candidate will have experience in spearheading GRC initiatives and audits, working with senior stakeholders, and driving regulatory compliance.The role involves close collaboration with infrastructure,...
-
Risk and Compliance Specialist
1 week ago
Pune, Maharashtra, India beBeeGovernance Full time ₹ 1,50,00,000 - ₹ 2,50,00,000Governance Risk Compliance ExpertAbout the RoleAt our organization, we are seeking a highly motivated Deputy Manager to strengthen our governance and control frameworks while ensuring alignment with regulatory requirements and organizational objectives.Key ResponsibilitiesEstablish, review, and enhance governance frameworks, policies, and procedures in...
-
Risk and Compliance Manager
4 days ago
Pune, Maharashtra, India beBeeCompliance Full time ₹ 30,00,000 - ₹ 40,00,000Job OverviewThis position involves the implementation and management of a comprehensive platform for enterprise-wide risk and compliance. The ideal candidate will have hands-on experience with the platform, technical skills in configuring its modules and workflows, and ability to integrate it with various systems.Key Responsibilities:Implement a...
-
Pune, Maharashtra, India beBeeRisk Full time ₹ 9,00,000 - ₹ 12,00,000Compliance and Risk Management ExpertThe Compliance and Risk Management Expert plays a pivotal role in ensuring that our organization adheres to industry standards and regulatory requirements. This position involves analyzing, implementing, and maintaining compliance protocols, collaborating with internal teams, and providing strategic insights to enhance...
-
Pune, Maharashtra, India Deutsche Bank Full time ₹ 1,04,000 - ₹ 1,30,878 per yearAFC & Compliance – Third Party Risk Management Specialist, AssociateJob ID: R0402845Full/Part-Time: Full-timeRegular/Temporary: RegularListed: Location: PunePosition OverviewJob Title: AFC & Compliance – Third Party Risk Management Specialist, AssociateLocation: Pune, IndiaRole DescriptionAs part of DWS' AFC & Compliance function, the global Anti-Fraud,...
-
Pune, Maharashtra, India Deutsche Bank Full time ₹ 5,00,000 - ₹ 8,00,000 per yearJob Title: AFC & Compliance - Third Party Risk Management Specialist, Associate Location: Pune, India Role DescriptionAs part of DWS' AFC & Compliance function, the global Anti-Fraud, Bribery & Corruption (AFBC) team is inter alia responsible for the design and execution of the Third Party Risk Management (TPRM) framework within DWS related to Risk...
-
Risk Compliance
2 days ago
Pune, Maharashtra, India Wipro Full time ₹ 1,04,000 - ₹ 1,30,878 per yearRole PurposeThe purpose of the role is to lead and manage security requirements and recommend specific improvement measures that helps maintain the Security posture of organisationDoLead Risk and Compliance to protect sensitive informationa. Drive Risk Management, Regulatory and Contractual complianceb. Diagnose the level of preparedness of the customer for...