Project Support/Cobit, Iso/Nederland – Zuid-Holland
[ad_1]
Functie
Project Support
Expertise
Cobit, Iso
Werkzaamheden
For our client in Rijswijk we are looking for a Risk and Controls Analyst (Project Engagement)
Start: 1 September 2016
End date: 31 August 2017
Hours per week: 40
Location: Rijswijk (Zuid-Holland)
Position: Risk and Controls Analyst (Project Engagement)
This role requires detailed knowledge of risk assessment methodologies, industry security requirements and standards, and IT security control frameworks. Managing project stakeholders and the supplier interface are key to success. Additionally the candidate should have a strong technical background in IT infrastructure, preferably in the area of end-user computing and/or network infrastructure.
Key responsibilities:
Execute IT project reviews – guide projects towards project stage gate sign-offs to ensure projects deliver secure, reliable and compliant IT solutions;
Undertake risk assessments on IT Infrastructure projects in the area of networks and communication, hosting and storage, cloud and end user computing environments;
Engage with IT Infrastructure project managers, portfolio owners, service managers and other stakeholders to ensure IT security risk is understood, to select the appropriate IT controls, and to ensure that IT security risks are mitigated and that selected IT controls are implemented by the project;
Ensure timely, complete and accurate registration of project review records (justifications, sign-offs, risk acceptances) in the appropriate registers and systems;
Ensure the most significant security risks (technical and non-technical) are identified, and mitigated. In case of residual security risk, ensure risk is accepted and proper handover takes place to relevant stakeholders;
Ensure that identified and implemented controls are handed over to control monitoring and supplier assurance teams;
Ensure our clients Information Risk Management control framework is applied for use in infrastructure projects, including scenarios such as outsourced environments and cloud providers;
Assist with data process adherence and quality improvement initiatives; Experience & Qualifications:
Minimal Bachelor’s degree, preferably with additional recognized security qualification or equivalent to CISSP, CRISC, CISA or CISM.
Substantial experience in IT service or IT project delivery, ideally in the Information Risk Management area and with an outsourced environment.
A practical understanding of, and experience with IT infrastructure, architecture and technology solutions would be advantageous. End User Computing knowledge and network security domain is considered a plus.
IT risk assessment experience in various technologies is required.
An understanding of risk management methodologies, proven capability in analysing IT infrastructure risks and working knowledge on IT security control frameworks (e.g., ISO, COBIT, SANS 20)
Experience in stakeholder management with diverse interest groups including IT project management, IT security, compliance, architecture, service delivery would be a plus.
Must be comfortable working virtually.
Strong communication skills in English.
Self starter, pro-active attitude, collaborative team player.
Interested? Please send your CV, motivation and hourly rate before 1 August 10:00 AM.
Bijzonderheden
Regio
Nederland – Zuid-Holland
Startdatum
01-09-2016
Duur
12 maanden
Referentienr.
30160867
[ad_2]
Source link