- advanced knowledge of organization, technology controls, security, and risk issues including cyber control exceptions.
- Demonstrated ability to participate in complex, comprehensive or large projects and initiatives.
- Ability to serve as a lead expert resource in technology controls and information security for project teams, the business, organization and outside vendors.
- Deep understanding of multiple control domains (e.g., access control, data protection, network security).
- Ability to lead technical discussions with third-party SMEs and internal stakeholders.
- Familiarity with cyber control frameworks and assessment tools.
- Coordination with Line of Business, Vendor Management, and risk stakeholders.
- Effective communication of cyber risks and remediation strategies.
- Adherence to internal policies, procedures, and technology control standards.
- Understanding of applicable regulatory guidelines.
- Third Party Risk Management.