Manage/Contribute to the continuous improvement of the information security management framework, policies, standards, and procedures.
Coordinate information security risk assessments, risk treatment plans, and risk acceptance processes.
Maintain the security risk register and report key risks, trends, and remediation progress to management.
Support the operation and continual improvement of the Information Security Management System (ISMS).
Prepare for and support internal and external security audits, certifications, customer assessments, and regulatory reviews.
Monitor compliance with applicable legal, regulatory, contractual, and internal security requirements.
Coordinate incident preparedness, including security incident procedures, exercises, lessons learned, and follow-up actions.
Support vulnerability, threat, access, asset, and third-party security management activities.
Promote secure working practices through security awareness training, communications, and targeted guidance.
Advise project and product teams on security requirements, secure design, data protection, and risk-based controls.
Contribute to business continuity, disaster recovery, and organizational resilience planning.
Define and track meaningful security metrics and management reports.
Work with stakeholders to ensure security findings and audit actions are prioritized and closed effectively.
Keep current with relevant threats, standards, regulatory developments, and industry practices