information security Risk and Comp. Analyst

New york, NY 10017

Industry: Security Job Number: 4401
  • Act as point person and subject matter expert on Information Security Risk Management principles, practices, rules and procedures
  • Manage the firm’ s ISO 27001: 2013 Information Security Management System
  • Monitor and maintain the firm’ s policies and procedures, recommend changes / enhancements, ensuring compliance
  • Manage the firm’ s vendor risk management program; make recommendations for enhancements/ improvements as appropriate
  • Coordinate third party technical risk assessments and related audit activities
  • Perform internal technical risk assessments and project reviews
  • Produce and maintain information security documentation, including but not limited to policies, procedures, standards, guidelines and diagrams
  • Review and respond to client audit / assessment requests in a timely manner
  • Drive continuous improvement through trend analysis reporting and metrics management
  • Monitor legal and regulatory changes and developments; advise Director and develop appropriate strategies, corrective actions, communications
  • Provide guidance to IT group members and firm - personnel on related policies, firm procedures, regulatory rules and compliance
  • Coordinate activities within the firm’ s vulnerability management program
  • Proactively assesses potential risks and opportunities for improvement
  • Understand the role of systems and technology within the firm and promote a culture of information security risk & compliance across all business units
  • Manage the - employee annual recertification for various firm policies
  • Perform other duties as assigned
Required Skills
  • 5+ years of experience in information security related responsibilities
  • Experience with ISO 270002 control frameework, SIG-Lite Risk Assessments
  • Proficient knowledge of security implications involving a variety of technologies including but not limited to; Microsoft, Cisco, Unix/Linux, and other market leaders in technology solutions, including mobile devices.
  • Demonstrated knowledge of the global data security regulatory environment
  • Strong knowledge of technology risk management concepts and their application
  • Must be able to work collaboratively in a team environment and independentlyy
  • Ability to handle sensitive and/or confidential material with discretion
  • Excellent interpersonal skills and a professional demeanor; ability to work effectively with all levels of Firm personnel and vendors
  • Excellent written and verbal communication skills, ability to communicate clearly and concisely
  • Strategic thinker with strong analytical and problem-solving skills
  • Demonstrated project management skills, organizational and execution skills with strong attention to detail
  • Ability to manage multiple concurrent objectives or activities, and effectively make judgments in prioritizing and time allocation
  • Must be flexible in order to respond quickly and positively to shifting demands
Preferred Skills
  • Industry certifications (for example CISSP, CISM, CISA or CGEIT )
  • 5+ year experience in information security risk management or governance role
  • 5+ year experience in information technology; ie. networking, desktop engineering, programming or systems administration
  • Strong knowledge of risk management frameworks including; ISO 27002, NIST and COBIT 5
  • Experience in a law firm environment a plus

David Di Belardino
Technical Recruiter

A graduate from Catholic University where he received his degree in History. David has been with TPG since August of 2018 and got into recruiting through his passion for technology. When David is not in the office, you can find him anywhere outdoors, particularly surfing, or on a beach.

Send an email reminder to:

Share This Job:

Related Jobs:

Login to save this search and get notified of similar positions.