Details
Posted: 23-Jul-22
Location: Los Angeles, California
Salary: Open
Internal Number: REQ20120161
The University of Southern California (USC) Department of Information Technology Services (ITS) is seeking an Information Security Risk Performance Manager with an exceptional commitment to service excellence to join its team.
As the Information Security Risk Performance Manager, you will be an integral member of the Governance, Risk Management and Compliance unit of the Office of the CISO.
The Information Security Risk Performance Manager is responsible for assessing and managing whether the university is operating within an approved security risk posture. This manager will provide key metrics tracking risk levels and manages compliance expectations. And the InfoSec Risk Performance Manager oversees third-party security audits and local/enterprise tracking of security controls.
THE WORK YOU WILL DO
The InfoSec Risk Performance Manager will:
Serves as a subject matter expert on organizational strategy for the universityâs overall information security risk posture and appetite. Develops, operates, and manages comprehensive strategies and programs prioritizing and mitigating business risk. Creates and maintains agreed-upon risk appetite and key risk indicators in line with frameworks.
Manages processes to ensure risk implications are understood, accepted appropriately, and tracked and reported throughout their lifecycle. Defines and manages KPIs to assure effectiveness and compliance across information security processes and process owners. Partners with others to ensure reporting is provided to manage risk through established governance.
Ensures performance of information security controls through assessment, remediation and escalation. Manages overall validation of adherence to policies and standards through control evaluation. Ensures alignment to regulatory, statutory, and industry requirements, as well as university policies and data classification. Independently recommends programmatic directions for cyber security risk investigations and analyses.
Engages and partners with local/enterprise entities preparing for and participating in internal/external compliance audits (e.g., FERPA, HIPAA). Defines and partners with relevant stakeholders for annual risk assessment plans. Obtains needed signoffs, and reports key performance indicators (KPIs), associated budget and resource impacts.
Maintains currency with changes in laws, regulations, and technologies which may affect operations. Ensures senior management and staff are informed of any changes and updates in a timely manner. Maintains continuity of any required or desirable certifications, if applicable.
Promotes an environment that fosters inclusive relationships and creates unbiased opportunities for contributions through ideas, words, and actions that uphold principles of the USC Code of Ethics. Establishes and maintains appropriate network of professional contacts. Participates in professional organizations (e.g., attends meetings, seminars, and conferences). Reads pertinent publications.
Performs other related duties as assigned or requested. The university reserves the right to add or change duties at any time.
MINIMUM QUALIFICATIONS
Bachelor's degree or combined experience/education as substitute for minimum education
5 yearsâ experience in information security or risk management.
Demonstrated understanding of information security across all security domains and the relationship between threats, vulnerabilities, and information value in the context of risk management.
Experience with legal and regulatory requirements and industry security frameworks. Demonstrated understanding of processes, internal control risk management, information security controls, and how they interact together. Experience performing information security risk assessments and risk analysis.
Demonstrated strong understanding of regulatory requirements (e.g., GLBA, PCI, FERPA, HIPAA).
Ability to communicate and present security risk concisely and effectively in relation to enterprise risk based on the appropriate level of management and stakeholder groups.
Demonstrated leadership and problem-solving skills.
Ability to work closely with business leaders in a high pressure, fastpaced, highly collaborative environment with multiple deadlines and competing priorities.
Ability to understand data analytics and dashboarding.
PREFERRED QUALIFICATIONS
- Bachelorâs degree in information security, information science, computer science, or related field.
- 7 or more yearsâ experience in information security or risk management.
- Extensive experience in information security, risk governance, and risk management within large enterprises or complex entities.
- Demonstrated data analytics and risk processing skills.
THE ITS TEAM
The ITS vision aligns strategy, business, and services; affirms ITS cultural values; empowers cross-functional teamwork; embraces world-class best practices; and promotes innovation, excellence, agility, and efficiency. To achieve this vision, ITS is committed to providing a modern technology infrastructure that is resilient and delivers the performance necessary to meet the demands of a growing customer base, training in the latest technologies for its highly productive and motivated workforce, outstanding customer experience, and technology services that are aligned with the universityâs mission to provide exceptional learning opportunities for students. ITS is creating a workplace where employees can develop cutting-edge skills, take pride in the services they provide, and have access to the roles and career paths that align to their abilities and potential. We are looking for top talent to join us on our journey.
ITS CULTURE
USCâs ITS organization represents a diverse and talented team, committed to supporting a collaborative culture and delivering secure and innovative IT services that are core to the mission of the university. We are also committed to creating and maintaining meaningful partnerships across the university. At ITS, we act with integrity in the pursuit of excellence; embrace diversity, equity and inclusion; promote well-being; engage in open two-way communication and are accountable for living our values. ITS strives for a supportive and inclusive culture that encourages employees to do their best work every day and where individuals are recognized and celebrated for their contributions.
ABOUT USC
USC is the leading private research university in Los Angelesâa global center for arts, technology, and international business. With more than 47,500 students, we are located primarily in Los Angeles but also in various US and global satellite locations. As the largest private employer in Los Angeles, responsible for $8 billion annually in economic activity in the region, we offer the opportunity to work in a dynamic and diverse environment, in careers that span a broad spectrum of talents and skills across a variety of academic and professional schools and administrative units. As a USC employee and member of the Trojan Familyâthe faculty, staff, students, and alumni who make USC a great place to workâyou will enjoy excellent benefits, including a variety of well-being programs designed to help individuals achieve work-life balance. USC values diversity and is committed to equal opportunity in employment.
Come join the USC ITS team and work as a trusted partner in shaping an environment of innovation and excellence. Apply today!
Minimum Education:Bachelor's degreeCombined experience/education as substitute for minimum educationMinimum Experience:5 yearsMinimum Field of Expertise:Five yearsâ experience in information security or risk management. Demonstrated understanding of information security across all security domains and the relationship between threats, vulnerabilities, and information value in the context of risk management. Experience with legal and regulatory requirements and industry security frameworks.Demonstrated understanding of processes, internal control risk management, information security controls, and how they interact together. Experience performing information security risk assessments and risk analysis. Demonstrated strong understanding of regulatory requirements (e.g., GLBA, PCI, FERPA, HIPAA). Ability to communicate and present security risk concisely and effectively in relation to enterprise risk based on the appropriate level of management and stakeholder groups. Demonstrated leadership and problem-solving skills. Ability to work closely with business leaders in a high pressure, fast-paced, highly collaborative environment with multiple deadlines and competing priorities. Ability to understand data analytics and dashboarding.