What are the responsibilities and job description for the Cyber Security Engineer position at ASM Tech Solutions?
Job Description :
Working in an agile environment, the Senior Cybersecurity Analyst (Compliance
Manager) will focus on assisting with the successful achievement of specified industry-
specific certifications for the organization. This role will report to the Senior Director of
Cybersecurity Risk Management in the Rivian Enterprise Cybersecurity organization. As
a member of the team, you will contribute to compliance activities related to multiple
frameworks including ISO 27001, TISAX, and NIST CSF. The ideal candidate brings a
strong understanding of risk assessment, understanding operating effectiveness,
recommending and coordinating security controls implementation activities, and
contributing to enhance the overall compliance and cybersecurity program. In this role,
the Senior Cybersecurity Analyst (Compliance Manager) will collaborate with Enterprise
Cybersecurity and cross-functional business leaders to obtain and maintain globally
recognized information security certifications specific to the cybersecurity domain and
automotive industry for improved security, data protection, and proving assurance to
business partners as an original automotive manufacturer.
Core Responsibilities :
- Serve as a subject matter expert for compliance initiatives with a specific focus ofISO 27001, and TISAX. Understands the practical application of NIST CSF.
- Assist in performing detailed assessments with a focus on risk information,
including self-assessments and working with external auditors covering Rivian's
information security system and cybersecurity program maturity.
undergone rigorous external verification and complies with the appropriate level
of information security standards within the TISAX framework.
reducing risk and optimizing operations facilitating meeting additional compliance
requirements.
proactively identify, escalate, and resolve impactful risks and issues.
proficiency to initiatives, problems and opportunities.
learnings for improvement.
work cross-functionally with diverse stakeholders.
objectives and industry best practices; identify gaps and ensure compliance with
standards across the enterprise.
related to cybersecurity compliance on a recurring basis by partnering with the
appropriate teams to develop Key Risk Indicators (KRIs) to drive compliance and
deliver on overall program performance.
communicate metrics which teams can use to drive continuous improvement.
consistency, and reliability of data assets; improve the quality of operational data
and metrics.
standards are met at a systematic level; follows up to keep work on track.
proactively recommend improvements to the Cybersecurity Risk Management
Program.
stakeholder buy-in.
Required Minimum Experience :
5 years in cybersecurity compliance, including hands-on experience with analytics,
tracking, and reporting.
Required Minimum Education :
required.
Desired Certification(s) :
Information Security Manager (CISM), Certified in Risk and Systems Controls
CRISC), or Microsoft Certified Systems Administrator : Security
intelligence is a plus
Qualifications
technologies, and various Standards and Guidelines (NIST CSF, TISAX, ISO
27001). PCI-DSS experience is desirable.
project / change management skills used to contribute to development of strategic
plan for aligned discipline
database / reporting / tracking tools, and project management software and tools