- The purpose of the role is to ensure compliance and deliver appropriate governance to manage information risks to within risk appetite, measured through;
- Compliance with enterprise standards and policies
- Effectiveness of security controls to manage risk to acceptable levels
- Measuring and performance risk through KPIs and KRIs
- Accurate and timely analysis / reporting to facilitate decision-making
- Ensuring delivery through assurance and governance
- Compliance with appropriate standards, frameworks and leading practice
- Quality of information controls
Key Accountabilities and Responsibilities
- Support and drive key ICS Strategic and Risk Management initiatives across all business domains, as defined by objectives, and see them through to completion
- Support the development of the ICS Risk Management Strategy, as well as the evolution of the overall ICS Strategy from the focus point/driver of reducing risk to within acceptable/tolerable levels
- Support the definition, implement and maintenance of the Risk Management Framework in an ever evolving and changing risk landscape
- Create and communicate supporting artefacts regarding strategic development and risk management i.e. Documented processes,
strategies, milestones, risk actions, KPIs
- Capture, develop and present relevant ICS metrics and reports for management information as required, to articulate tangible risk reduction progress
- Support the Policy Exception process from a risk perspective
- Receive, manage and progress risk and strategy related tickets/business queries
- Develop company wide (including 3rd party), best practices and processes for Information Security risk
- Support IT and the business in documenting, sizing and planning responses to Information Security risk in adherence to documented policies, standards and procedures, providing Education & Awareness on these where relevant
- Conduct risk assessments across business and IT domains and work with product/service managers to ensure effective management of these risks
- Maintain and evolve risk management systems and data quality to ensure accurate reporting
- Research and consider policy, standard and process enhancements across the GRC space with the view of further reducing risk
- Any other activities as reasonably directed by management.