Introduction & Summary:
We are seeking a highly skilled IT Security Assessor to evaluate the information security program and governance of our acquired companies. The ideal candidate will possess a profound understanding of security requirements ensure compliance with established frameworks like NIST, ISO 27001, and regulatory requirements such as GDPR and HIPAA.
Main Responsibilities:
This role entails assessing various aspects of information security within the acquired entities. Key responsibilities include:
- Evaluate the information security program against requirements.
- Ensure alignment with frameworks and regulatory requirements.
- Assess network topology, cloud environments, and data centers.
- Identify legacy systems and insecure configurations.
- Verify compliance with industry regulations.
- Review vendor contracts and security provisions.
- Evaluate data classification, encryption, and retention policies.
- Assess incident response plans and disaster recovery capabilities.
Key Requirements:
- Strong knowledge of information security principles.
- Experience with regulatory compliance (GDPR, HIPAA).
- Familiarity with frameworks (NIST, ISO 27001, CIS).
- Ability to assess network and cloud security environments.
- Understanding of data protection practices.
- Capable of evaluating governance structures.
Nice to Have:
- Previous experience in security assessments.
- Certifications such as CISSP, CISA, or equivalent.
- Knowledge of security awareness programs.
Other Details:
This position is remote and offers a dynamic work environment focused on improving security postures during mergers and acquisitions. Ideal candidates should be prepared for potential challenges related to integrating security processes.