SonicJobs Logo
Left arrow iconBack to search

Lead, Risk Management

ELC Beauty LLC
Posted 5 months ago, valid for 11 days
Location

New York, NY 10008, US

Salary

Competitive

Contract type

Full Time

By applying, a Sonicjobs account will be created for you. Sonicjobs's Privacy Policy and Terms & Conditions will apply.

SonicJobs' Terms & Conditions and Privacy Policy also apply.

Sonic Summary

info
  • The Cybersecurity Risk Management Lead position at ECR requires a minimum of 5 years of practical experience in technology risk and control, IT audit, or related fields.
  • The role involves identifying and evaluating technology and cyber risks, collaborating with stakeholders to mitigate risks, and managing project documentation.
  • Candidates should possess strong communication, analytical, and problem-solving skills, along with proficiency in Microsoft Office and data visualization tools.
  • An undergraduate degree in computer science or business is required, and certifications such as CISSP, CISA, or CISM are desirable.
  • The salary for this position is competitive and commensurate with experience.

Risk Management Lead

As the Cybersecurity Risk Management Lead within ECR’s Risk and Solutions team, you will work to minimize overall security risk by identifying risks, monitoring requests through approval workflows, providing risk scoring, and presenting data to give a holistic view of the risk associated with risks identified at the company.   

 

Responsibilities include:

  • Partner with ECR team members, IT stakeholders, and business owners to bring down the risk of technology to the company by identifying and evaluating technology and cyber risks as they are identified. Responsible for reviewing risks through triage and evaluative score risk level and severity with a focus on defining a potential path for remediation
  • Collaborate to define appropriate solutions to mitigate or remediate the risk by partnering with key stakeholders in ECR, IT, and the business, which will require consensus building and managing disagreements. Enable balanced risk decisions by providing recommendations to leadership, escalating based on severity and risk level to ensure appropriate cyber protection capabilities and resiliency are built into the plans. 
  • Manage risk reduction tracker and maintain basic project management documentation tracking project tasks, status, ownership, issue closure, and timelines.
  • Support monthly Risk Reduction Governance Committee meetings.
  • Coordinate and manage cross-functional project teams to track overall remediation status while coordinating with applicable team and Program Managers.
  • Prepare and provide reporting (KRI) and dashboard status(s) on a scheduled basis.

 

Qualifications

  • 5 years of practical experience in technology risk and control or IT audit (audit firm experience is a plus), including experience in project governance/management and understanding of business processes, key IT risk/controls, organizations, markets, retail, and/or manufacturing.
  • Strong communication skills, influence/negotiation skills, attention to detail, conflict management experience, analytical skills, and measurement/visualization ideas.
  • Ability to problem⁃solve, think creatively, challenge the status quo, and manage ambiguity.
  • Ability to communicate complicated or technical information to executives, including proven ability to work both independently and as part of a team, with stakeholders at all levels.
  • Proficient in Microsoft Excel, Word, and PowerPoint, including data visualization Power BI.
  • Proficient in English as a business language.
  • Experience handling, securing, and communicating highly confidential and sensitive information.
  • 3 years minimum related experience.
  • Undergraduate degree in computer science/business or equivalent professional experience CISSP/CISA/CISM/CRISC/CGEIT/ITIL or equivalent certification is desirable.



Learn more about this Employer on their Career Site

Apply now in a few quick clicks

By applying, a Sonicjobs account will be created for you. Sonicjobs's Privacy Policy and Terms & Conditions will apply.

SonicJobs' Terms & Conditions and Privacy Policy also apply.