Information Security Risk Manager
Job description
Job Overview
The Information Security Risk Manager is a crucial role within IQVIA organization, responsible for helping to establish and maintain IQVIA's risk management program, which is designed to ensure that the company's IT systems and information assets are adequately protected.
The individual in this position will be responsible for identifying and evaluating on information security risks in a manner that meets IQVIA's regulatory and other compliance requirements.
The individual will proactively engage the various clients, business units and other internal departments and organisations to implement practices that meet IQVIA's defined policies and standards for information risk management.
A successful candidate will demonstrate an ability to work independently and in an organised manner. They will communicate very effectively, manage their workload independently and coach others to success. They will demonstrate strong technical ability and experience, as well as diplomacy and the ability to work calmly under pressure.
Essential Responsibilities
- Plans, executes and conducts ongoing risk assessment, self-assessment and reviews of various operations, including assessing risks, determining scope, executing test procedures, reporting results and making recommendations for improvement.
- Evaluates compliance with legal, regulatory, operational and IT policies and procedures, and partners with stakeholders to develop sustainable remediation plans to compliance issues and control gaps, and actively drives issues and risks to closure.
- Works with others to help identify advanced security risks and exposures, determine the causes of security non-compliances, designs and recommends solutions to prevent and mitigate future incidents. This will include identifying applications of functional knowledge and existing methodologies to highly complex problems.
- Follows up on deficiencies identified in monitoring reviews, self-assessments, automated assessments, and internal and external audits to ensure that appropriate remediation measures have been taken.
- Evolves the risk monitoring program to identify opportunities for enhancements and manages the risk exception process.
- Partners with the technology organization to implement and maintain IQVIA's integrated control framework, which includes requirements from NIST CSF, COBIT, HIPAA, etc.
Qualifications
- Bachelor's Degree Computer Science, a related field, or equivalent experience
- Equivalent work experience may substitute for degree
- 3 years of related work experience
- CISSP - Certified Information Systems Security Professional
- Certified Information Security Manager
- Certified in Risk and Information Security Controls
IQVIA is a leading global provider of clinical research services, commercial insights and healthcare intelligence to the life sciences and healthcare industries. We create intelligent connections to accelerate the development and commercialization of innovative medical treatments to help improve patient outcomes and population health worldwide. Learn more at https://jobs.iqvia.com
At IQVIA, we believe that diversity, inclusion, and belonging empower our mission to accelerate innovation for a healthier world. We create a culture of belonging by valuing the perspectives of all talented employees worldwide and providing them with the opportunity to power smarter healthcare for everyone, everywhere. When our talented employees bring their authentic selves and their diverse experiences to work, they enable us to accomplish extraordinary things. Multifaceted thought processes spark innovation. Multi-talented collaboration harnesses innovation to deliver superior outcomes.
Junte-se à Rede de Talentos da IQVIA
Inscreva-se hoje e avisaremos quando houver vagas disponíveis que sejam compatíveis com seus interesses profissionais.
Junte-se à nossa rede