Manager, Information Security Risk
OneTrust is the trust intelligence cloud platform organizations use to transform trust from an abstract concept into a measurable competitive advantage. Organizations globally use OneTrust to enable the responsible use of data while protecting the privacy rights of individuals, implement and report on their cyber security program, make their social impact goals a reality, and create a speak up culture of trust. Over 14,000 customers use OneTrust's technology, including half of the Global 2,000. OneTrust currently ranks #24 on the Forbes Cloud 100 list of top private cloud companies in the world and employs over 2,000 people in regions across North America, South America, Asia, Europe, and Australia.
The Challenge- We are looking for a dynamic Information Security GRC Manager to support IT and InfoSec by performing various risk activities.
- This role is critical to support OnePlan of maturing security processes and posture at OneTrust within the information security GRC domain.
- Establish and execute a broad strategic vision for the Information Security risk program
- Develop, implement and monitor vendor risk activities, including due diligence, contract provisions, vendor reviews and requirements.
- Develop, implement and monitor the exception management process
- Work independently, as well as part of a multidisciplinary team, while demonstrating organization skills to efficiently and effectively conduct reviews and assessments within established time-frames
- Identify and mitigate technical operational problems using policies, procedures and standards where applicable.
- Work in the OneTrust platform to document all systemic
- Define and establish risk management policies, SOPs and standards
- Analyze technical risks and improve risk management practices
- Collaborate with IT, InfoSec, and within the GRC team to mature the compliance process
- Become a trusted advisor to IT, InfoSec, and the business
- A Relationship builder: Ability to listen, build rapport, and credibility as a strategic partner vertically and horizontally
- An Innovator: Possess the ability to seek alternatives and recommend best solutions that gain all parties support and lead to win-win results
- Value Driven: You are detail oriented with an eye for quality
- Ability to work with minimal oversight
- Ability to execute given high level direction
- Asks good questions and always learning
- Working knowledge of NIST CSF and RMF frameworks
- Ideal candidate will be a strong leader and have a proven background in Cyber Security Risk Management with a focus on influencing change within an organization
- Extensive hands-on experience with conducting security reviews and implementing a risk register.
- Working knowledge of NIST CSF and RMF frameworks
- Ideal candidate will be a strong leader and have a proven background in Cyber Security Risk Management with a focus on influencing change within an organization
- Extensive hands-on experience with conducting security reviews and implementing a risk register.
- Previous people management experience
- CRISC certification
- Ability to communicate clearly, both verbally and in writing
- Ability to collaborate and coordinate with multiple teams and vendors
- Ability to work independently and as part of a team
- Ability to multitask and prioritize effectively
- Keen attention to details, while keeping the big picture in mind
- Ability to work with minimal supervision
- Ability to mentor, train, and educate other security personnel
- CISM or CRISC certified
- OneTrust advanced certified in ITRM and TPRM modules
- Solid understanding of current privacy and security policies including applicable state and federal regulations related to Protected Health Information such as National Institute of Standards and Technology (NIST), Health Insurance Portability and Accountability Act/Health Information Technology for Economic and Clinical Health Act (HIPAA/HITECH), Federal Information Procession Standards (FIPS), and other industry related security standards, regulations, and best practices such as ISO 27001, 27017, 27701, SOC 2, PCI-DSS, HITRUST
- Well defined understanding of risk management and risk analysis with 5- 8 years of direct relevant experience.
- Bachelor’s degree in a related field or equivalent experience required
- Advanced planning/organizational, problem-solving, analytical, consulting, time management and decision-making skills required
- Ability to effectively communicate technical security plans, strategies, and designs to all levels of the company
- Must be detail oriented and able to maintain a high degree of accuracy
- FedRamp, StateRamp experience
- PMP certification
For California, Colorado, Connecticut, Nevada, New York, Rhode Island, and Washington-based candidates: the annual base pay range for this role is listed below. Within this range, individual pay is determined by several factors, including location, job-related skills, work experience, and relevant education and/or training. This role may also be eligible for discretionary bonuses, equity, and/or commissions, as well as benefits.
Salary Range$127,500—$191,250 USDWhere we WorkOneTrust embraces a hybrid working model. Our Working@ OneTrust initiative is our way of clarifying where we hire, how we work together, and where we’re located in that hybrid model.
The underlying “why” for Working@ is that we are intentional about the culture that we want to create together. That includes bringing teams together, in-person, throughout the year to collaborate, build connections, learn from each other, and celebrate our wins toFinish Stronger.
We are committed to a flexible approach informed by a set of guiding principles. You’ll see that reflected in our worker designations: “Office-flex” and “Location-flex”.
- Office-flex: Like a traditional hybrid model, OneTrust “Office-flex” employees may be asked to work in an office periodically if they are within a commutable distance to a OneTrust office. This includes coming into the office for our Company Kickoff, Company All Hands, and other larger company events. Beyond that, we give our leaders and teams the flexibility to set additional guidelines based on the nature of your role.
- Location-flex: Similar to other companies’ remote policies, for OneTrust “Location-flex" roles, you will primarily work from your home office location. However, you may be required to travel to our OneTrust offices or customer sites periodically based on the nature of your role.
Each role may have specific requirements, so we encourage you to verify the location of the role with your recruiter during your first interview.
BenefitsAs an employee at OneTrust, you will be part of the OneTeam. That means you’ll receive support physically, mentally, and emotionally so that you can do your best work both in and out of the office. This includes comprehensive healthcare coverage, flexible PTO, equity stock options, annual performance bonus opportunities, retirement account support, 14+ weeks of paid parental leave, career development opportunities, company-paid privacy certification exam fees, and much more. Specific benefits differ by country. For more information, talk to your recruiter or visit onetrust.com/careers.
ResourcesCheck out the following to learn more about OneTrust and its people:
- OneTrust Careers on YouTube
- @LifeatOneTrust on Instagram
You have the right to have your personal data updated or removed. You also have the right to have a copy of the information OneTrust holds about you. Further details about these rights are available on the website in our Privacy Overview. You can change your mind at any time and have your personal data removed from our database. In order to do this you must contact us and let us know you wish to be removed. The request should be made on the Data Subject Request Form.
Our Commitment to YouWhen you join OneTrust you are stepping onto a launching pad — the countdown has begun. The destination? A career without boundaries working alongside a diverse and inclusive crew who is passionate about doing meaningful work. As a pioneer, your voice and expertise will help chart the direction of an entirely new industry — Trust. Our commitment to putting people first starts with you. Your growth is part of the mission. Our goal is to give you the power to embark on the next phase of your uniquely, unique career
OneTrust provides equal employment opportunities to all employees and applicants for employment and prohibits discrimination and harassment of any type without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by local laws.