Key Performance Indicators
The purpose of the role is to ensure compliance and deliver appropriate governance to manage information risks to within risk appetite, measured through;
Compliance with enterprise standards and policies
Effectiveness of security controls to manage risk to acceptable levels
Measuring and performance risk through KPIs and KRIs
Accurate and timely analysis / reporting to facilitate decision-making
Ensuring delivery through assurance and governance
Compliance with appropriate standards, frameworks and leading practice
Quality of information controls
Key Accountabilities and Responsibilities
Support and drive key ICS Strategic and Risk Management initiatives across all business domains, as defined by objectives, and see them through to completion
Support the development of the ICS Risk Management Strategy, as well as the evolution of the overall ICS Strategy from the focus point/driver of reducing risk to within acceptable/tolerable levels
Support the definition, implement and maintenance of the Risk Management Framework in an ever evolving and changing risk landscape
Create and communicate supporting artefacts regarding strategic development and risk management i.e. Documented processes,
strategies, milestones, risk actions, KPIs
Capture, develop and present relevant ICS metrics and reports for management information as required, to articulate tangible risk reduction progress
Support the Policy Exception process from a risk perspective
Receive, manage and progress risk and strategy related tickets/business queries
Develop company wide (including 3rd party), best practices and processes for Information Security risk
Support IT and the business in documenting, sizing and planning responses to Information Security risk in adherence to documented policies, standards and procedures, providing Education & Awareness on these where relevant
Conduct risk assessments across business and IT domains and work with product/service managers to ensure effective management of these risks
Maintain and evolve risk management systems and data quality to ensure accurate reporting
Research and consider policy, standard and process enhancements across the GRC space with the view of further reducing risk
Any other activities as reasonably directed by management.