About the Job The Cybersecurity Risk Management team is part of Chief Security Office CSO and responsible for managing multiple teams that facilitate external audits internal audits analyze policy exceptions conduct risk assessments and run enforceable governance across processes They work closely with the AT T Technology Services ATS teams and Technology Risk Management TRM teams and other CSO teams to ensure the effective and productive GRC processes Below are the key responsibilities of the Specialist - Risk Management position Develop and maintain a Risk Assessment schedule to ensure all activities supporting the annual Risk Assessment process are identified assigned and completed in a timely manner to be compliant with ISO 27001 SOC and PCI risk requirements Ensure end to end risk assessment process documentation and process flows of the Risk assessment and Risk reporting processes are created reviewed updated and maintained Ensure the Risk Assessment scope objectives and deliverables are documented and managed Schedule and facilitate the annual Risk Assessment process making sure the Risk Assessment is completed in a timely manner Create and publish the monthly Risk Management report Ensure the annual Risk Assessment presentation is created to include the timeline communication protocols and expectations to help facilitate the process Ensure the kick-off presentation is finalized 2 weeks before the annual Risk Assessment kick-off meeting is scheduled to be conducted Schedule and conduct the annual Risk Assessment kickoff meeting Respond to the external auditor s risk related inquiries clarification requests and follow-ups Ensure the confidentiality and integrity of sensitive information obtained as a result of facilitating the risk assessment process Track and manage Risk Management related action items resulting from external audit findings driving timely remediation and validating all reported items have been addressed in a timely manner Help create and suppo