The Primary responsibility is to review the security controls in place at Milliman global office locations (aka Practices) to ensure implementation is in place and security threats are identified and remediated within established timeframes. Reviews are conducted either remotely through video calls, or in-person visits to the office being assessed. This will entail assessment preparation work, fieldwork (i.e., conducting meetings with the Practice leadership and IT resources), requesting and reviewing supporting evidence of compliance, and preparing reports and recommendations. This position is part of a team of team-oriented reviewers, located in the US and India. This position functions as a member of the Information Security team and reports to the Information Security Manager in India.
In addition to the Information Security Review Program, this role has adjunct responsibilities to assist the US Governance, Risk, and Compliance (GRC) team with the review of contract terms (and other legal agreements), respond to client information security questionnaires,
and support various ad-hoc GRC projects.
Job Requirements
1. (70%) Internal Security Reviews (ISR)
- Utilize industry knowledge and technical expertise to help management and effectively address risks associated with their business.
- Identify key risks and controls, controls optimization, including security configuration controls, and business processes across diverse environments.
- Apply understanding of the Milliman Information Security Policy and applicable security standards within the context of local business operations.
- Ability to review and understand client contracts and incorporate client requirements into assessment reviews.
- Prepare comprehensive assessment reports detailing findings and actionable recommendations for IT support and senior management.
- Ensure timely completion of tasks per project phase.
- Proactively identify and escalate project risks and/or delays to managem