- Establish security policies, procedures, and guidelines for information security controls
- Review, update, publish, and mature Alight’s global security policies and standards
- Identify security issues and policy, standards, and procedure gaps among employees, contractors, alliances, and third parties
- Map legal and regulatory requirements and developments onto global policies and procedures
- Perform audit attestation activities and deliver work within agreed timeframes and organizational procedures
- Interpret audit non-compliance patterns to assess risk and drive improved compliance
- Own and manage policy and audit gaps through remediation, reporting milestones, and escalating when necessary
- Lead internal subject matter experts in understanding controls and required evidence
- Partner cross-functionally and with external auditors to understand processes end-to-end and communicate effectively
- Communicate test and audit results and analysis to stakeholders and senior audit management
- Use MS Excel and proprietary insurance enrollment and administration systems to measure, monitor, and report metrics
- Design, implement, and mature the security and risk management controls library, methodology, and testing criteria
- Stay current on regulatory rules and industry changes
- Lead or participate in business-unit meetings on audit scope, testing progress, and results
- Partner with senior management to understand business risks, changes, and events affecting the audit plan
- Communicate with regulators, external auditors, and risk management committees as part of continuous monitoring and audit-plan management
Requirements
- Bachelor’s degree in Information Systems, Cybersecurity, or a related field and minimum 6 years of relevant experience; additional years of relevant experience may substitute for the degree
- Certifications in Cybersecurity and/or Project Management are a plus
- Experience with technical, procedural, or policy writing
- Experience with audit frameworks such as NIST/ISO
- Demonstrated experience working in a geographically dispersed team with global scope and responsibilities
- Experience facilitating business process design related to managing identities and access privileges
- CISA certification is beneficial
- Excellent collaboration skills
- Exceptional communication skills, including gathering relevant data, active listening, dialogue, verbalizing ideas, negotiating tense situations, and conflict resolution
- Adaptability and flexibility across functional boundaries or independently
- Willingness to work evenings, weekends, and holidays as required
- Ability to handle and maintain the integrity and confidentiality of highly sensitive material and information
- Must reside in one of the 50 United States or the District of Columbia
- Proof of US citizenship required at time of hire
- Must have work authorization that does not now or in the future require visa sponsorship in the United States
- Successful completion of a background check consistent with Alight’s employment policies
- Virtual interviews must be conducted on video
Core Competencies
Demonstrates expertise in establishing and maturing security policies and procedures, with a strong focus on compliance, audit frameworks, and risk management. Proficient in collaborating with cross-functional teams and communicating effectively with stakeholders and regulators.
Highest-signal resume keywords
- Information Security Policy Development
- Audit Frameworks (NIST/ISO)
- Risk Management
- CISA Certification
- Technical Writing
Hard Skills
- Information Security Controls
- Audit Attestation Activities
- Compliance Assessment
- Policy Writing
- Risk Assessment
- Security Standards
- Metrics Reporting
- Business Process Design
- Regulatory Compliance
- Security Controls Library
Soft Skills
- Collaboration
- Communication
- Adaptability
- Conflict Resolution
- Active Listening
Certifications & Qualifications
- Cybersecurity Certification
- Project Management Certification
- CISA Certification
Industry Keywords
- Information Systems
- Cybersecurity
- Audit Management
- Regulatory Requirements
- Global Security Standards
Tools & Technologies
- MS Excel
- Proprietary Insurance Enrollment Systems
#J-18808-Ljbffr
Security Policy and Compliance Manager Arbeitgeber: Jobtailor
Als Front Office Supervisor in unserem dynamischen Team bieten wir Ihnen die Möglichkeit, in einem unterstützenden und freundlichen Arbeitsumfeld zu wachsen. Wir legen großen Wert auf die berufliche Entwicklung unserer Mitarbeiter und bieten regelmäßige Schulungen sowie die Chance, Verantwortung zu übernehmen. Unsere Lage ermöglicht es Ihnen, Teil einer lebendigen Gemeinschaft zu sein, während Sie gleichzeitig die Standards unseres Franchise-Partners einhalten und unseren Gästen einen unvergesslichen Aufenthalt bieten.