What are the responsibilities and job description for the Information Security Officer position at Ascensus Specialties?
Job Description
Job Description
Description
The Information Security Officer (ISO) is responsible for establishing and maintaining an enterprise-wide information security strategy to ensure the confidentiality, integrity, and availability of the organization's data, systems, and networks. The ISO will lead efforts to manage risks, implement best practices, enforce policies, and ensure compliance with regulatory requirements to protect the organization from cyber threats.
Key Responsibilities
- Develop, implement, and maintain the organization's information security policies, standards, and procedures.
- Establish a security framework to manage cybersecurity risks and align it with business objectives.
- Conduct regular risk assessments and develop risk mitigation strategies to address vulnerabilities.
- Ensure compliance with relevant laws, regulations, and standards (e.g., GDPR, HIPAA, ISO 27001, NIST).
- Collaborate with executive leadership to ensure security is integrated into business processes.
- Monitor and manage cybersecurity threats, incidents, and vulnerabilities.
- Oversee the management, maintenance, and optimization of existing security technologies such as firewalls, intrusion detection / prevention systems (IDS / IPS), antivirus, and endpoint protection.
- Implement access control mechanisms to safeguard sensitive information.
- Manage and coordinate incident response plans and investigations of security breaches.
- Conduct security audits, penetration tests, and vulnerability assessments.
- Develop and implement a security awareness program for employees to promote best practices and minimize human-related risks.
- Provide ongoing training and guidance to employees on cybersecurity policies and procedures.
- Ensure the organization’s compliance with industry regulations, frameworks, and standards.
- Prepare and present security reports to executive leadership and relevant stakeholders.
- Respond to client and regulatory security audits and questionnaires.
- Assess third-party vendors to ensure their security practices align with the organization’s requirements.
- Manage third-party security contracts and ensure appropriate security controls are in place.
Qualifications
Preferred
Educational Requirements
Professional certifications such as CISSP , CISM , CRISC , CEH , or ISO 27001 Lead Auditor desired.
Benefits
First 3% is matched dollar-for-dollar.