Governance, Risk and Compliance Specialist (On-site)
Concentrix · Mandaluyong, National Capital Region, Philippines
Apply & track with Apply EdgeExperience in actively contributing in establishment and Management of a Risk Management program for Internal Business and Third Parties to detect and mitigate risks which would include establishing capability to monitor, manage and audit risks and associated actions, establish training & awareness, driving reviews and supporting internal and external audits. Ability to think out-of-the-box and maintain balance of security risk vs solution within the best technical and cost opportunity limits, to meet the company standard, regulatory and the contractual obligations. Ability to work in a team and develop strong relationship bond with the Business and Cross-Platform teams while always wearing a “ready on the toes” attitude to support the organization at his best efforts. Ability to achieve positive & successful results for Information Security Risk Management activity, apprising the leadership about the specific risks from their vertical, through direct interaction and tactical influence over stakeholders.
Responsibilities
Drive Information Security Risk Management activity globally for all the business engagements and third partiesMaintain and Improve the risk management frameworks at ConcentrixWork with business teams and support teams to drive Risk Assessments for their respective spans including third partiesDeliver training to teams on Risk ManagementInterpret the business contractual requirements (Technology & Information Security) to align Risk Management programDevelop the documents as required or guiding the team responsible in development of the required documentationSupport and manage Internal and External risksHandle and respond to client audits, reviews and assessments through time-bound and committed methodologyCommunicate effectively the risks, vulnerabilities, threats and findings of the assessments and reviews to senior management and relevant stakeholders and co-ordinate and govern the closure, as required.Complete all assigned, mandatory training within the timeframe providedConduct and/or participate in regularly scheduled 1:1 meetings with direct manager and/or direct reportsAccountability:Accountable for Location level activities:Drive Information Security Risk Management activity globally for all the business engagements and third partiesMaintain and Improve the risk management frameworks at ConcentrixWork with business teams and support teams to drive Risk Assessments for their respective spans including third partiesDeliver training to teams on Risk ManagementInterpret the business contractual requirements (Technology & Information Security) to align Risk Management programDevelop the documents as required or guiding the team responsible in development of the required documentationSupport and manage Internal and External risksHandle and respond to client audits, reviews and assessments through time-bound and committed methodologyCommunicate effectively the risks, vulnerabilities, threats and findings of the assessments and reviews to senior management and relevant stakeholders and co-ordinate and govern the closure, as required
Qualifications
Educational RequirementsBachelor’s Degree (preferred)At least 3 years of experience required (Junior level)BPO experience is preferredRequired Certifications:Bonus points for Professional Security and / or Privacy credentials / certifications like CISSP, CISA, CRISC, CISM, HCISPP, CIPP/IT, etc.Fulltime onsiteShifting schedule/night shift